The State Department is looking for information on hackers connected to the Iranian group Handala as well as other cyber actors in the country. A notice on Friday calling for information was sent...
Posted by Dirk Göhmann, Tony Mendez, and the Vulnerability Rewards Program Team2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th...
New data from KELA recognizes that Iranian state-sponsored threat actors have moved well beyond traditional espionage, increasingly blurring... The post Iranian hackers target US critical...
Singapore’s cyber threat landscape is being reshaped by a convergence of state-backed espionage, financially motivated cybercrime, and increasingly... The post APT groups and ransomware gangs are...
Chinese President Xi Jinping is getting the United States he always wanted. Since U.S. President Donald Trump’s return to the White House in 2025, Washington has grown less confident in its global...
Radiflow, provider of OT cybersecurity and risk management solutions, announced a partnership with DEFENDERBOX to strengthen operational technology... The post Radiflow and DEFENDERBOX join forces...
On a warm night three summers ago, Kai Raydon, a student at the University of Colorado, Boulder, opened a package of orange-white powder that he had purchased through an encrypted site on the dark...
Accenture has launched Cyber.AI, a new solution powered by Claude, Anthropic’s AI model, that enables organizations to transform... The post Accenture unveils Cyber.AI platform powered by...
Atos, a global vendor of AI-powered digital transformation, announced the official launch of its Threat Research Center (TRC)... The post Atos launches threat research center to advance AI-driven...
Healthcare technology solutions provider CareCloud (Nasdaq: CCLD) has disclosed a cybersecurity incident that may have resulted in patient information compromise. CareCloud is a New Jersey-based...
The European Commission on Monday sought to play down the impact of a cyberattack on parts of its public web infrastructure, saying there was no evidence its internal systems had been compromised....
A wave of tax-themed cyber campaigns delivering malware, remote access tools, fraud schemes and credential phishing has been detected in early 2026. Proofpoint researchers identified more than a...
U.S. policy circles reacted with a mixture of alarm and confusion when Chinese AI company DeepSeek released its open-source “R1” model in January 2025. R1 appeared to deliver reasoning...
At a time when Ukraine’s air defense expertise is being sought by Arab nations under fire from Iranian missiles and drones, Kyiv announced its new experimental concept for battling Russian drones...
As U.S. and Israeli military commanders met to map out war with Iran, they deliberated over how to divide responsibility for an array of targets, including missile batteries, military bases and...
Military artificial intelligence (AI) is moving from the margins of experimentation into the core of how NATO will fight, make critical decisions and deter competitors over the next decade. The...
The popular HTTP client known as Axios has suffered a supply chain attack after two newly published versions of the npm package introduced a malicious dependency. Versions 1.14.1 and 0.30.4 of...
Charles Bennett and Gilles Brassard have won the 2026 Turing Award for inventing quantum cryptography. I am incredibly pleased to see them get this recognition. I have always thought the...
Hijacked maintainer account let attackers slip cross-platform trojan into 100M-downloads-a-week Axios One of npm's most widely used HTTP client libraries briefly became a malware delivery vehicle...
Unit 42 uncovers a "double agent" flaw in Google Cloud's Vertex AI, demonstrating how overprivileged AI agents can compromise cloud environments. The post Double Agents: Exposing Security Blind...
AI agent risk isn't equal, it scales with access to systems and level of autonomy. Token Security explains how CISOs should categorize agents and prioritize what to secure first. [...]
A summary of the top ransomware trends from the Talos 2025 Year in Review, with a focus on identity, attacker tactics, and practical defenses.
Cota Co., Ltd., a TSE Prime Market–listed company based in Kyoto Prefecture and active in the consumer and cosmetics-related field, reported a significant disruption to its internal systems...
Hackers hijacked the npm account of the Axios package, a JavaScript HTTP client with 100M+ weekly downloads, to deliver remote access trojans to Linux, Windows, and macOS systems. [...]
I have shared my impressions of the CRA before in writing[1] and was surprised to hear that a Draft Guide for the CRA was issued for comment[2]. Taking a deep breath, I spent several days reading,...
I have shared my impressions of the CRA before in writing[1] and was surprised to hear that a Draft Guide for the CRA was issued for comment[2]. Taking a deep breath, I spent several days reading,...
Stop the noise and scale your cloud security. Our latest updates introduce custom policy automation via Explorer, AWS ABAC support for true least privilege, and research-backed protection against...
The past four weeks have seen a slew of new cybersecurity wake-up calls that showed why every organization needs a well-thought-out cyber-resilience plan
A compromised axios maintainer account led to malicious npm releases that propagated across environments. Learn how to assess impact, detect compromise, and secure your development workflows.
Microsoft has resolved a known issue that rendered the classic Outlook email client unusable for users who enabled the Microsoft Teams Meeting Add-in. [...]