IM
IronMonkey Threat Research
LIVE
|
Articles 25,621
|
CVEs 338,787
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 25,589 articles — Page 239 of 853
The Hacker News ·

Node.js has released updates to fix what it described as a critical security issue impacting "virtually every production Node.js app" that, if successfully exploited, could trigger a...

Information Technology Commercial Facilities
The Register - Security ·

U-turn leaves questions on costs, funding, and benefits unanswered The UK government has backed down from making digital ID mandatory for proof of a right to work in the country, adding to...

Government Facilities
Cyber Security Advisories - MS-ISAC ·

Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution.Adobe Bridge is a creative asset manager that lets you preview,...

Transportation Systems Healthcare and Public Health
CERT Polska ·

Missing Password Field Masking vulnerability (CVE-2025-13175) has been found in Ysoft SafeQ 6 software.

CVE vulnerability
The Hacker News ·

The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of new cyber attacks targeting its defense forces with malware known as PLUGGYAPE between October and December 2025....

Void Blizzard Laundry Bear Commercial Facilities Communications
Cisco Talos Blog ·

Terryn’s path to cybersecurity started with a fascination for criminal forensics and a knack for jailbreaking his family's tech — interests that eventually steered him toward the fast-paced world...

Humans of Talos
SECURITY.COM ·

New whitepaper reveals record number of attacks as threat landscape evolves with new players and new tactics.

Information Technology Transportation Systems
The Register - Security ·

Endesa says payment info stolen after alleged crook boasted of 1 TB-plus haul Spanish energy giant Endesa is warning customers about a data breach after a cybercrim claimed to have walked off with...

Energy Financial Services
Project Zero ·

While our previous two blog posts provided technical recommendations for increasing the effort required by attackers to develop 0-click exploit chains, our experience finding, reporting and...

Financial Services Government Facilities
WeLiveSecurity ·

Should verified identities become the standard online? Australia’s social media ban for under-16s shows why the question matters.

Communications Financial Services Social Media
Project Zero ·

With the advent of a potential Dolby Unified Decoder RCE exploit, it seemed prudent to see what kind of Linux kernel drivers might be accessible from the resulting userland context, the mediacodec...

Project Zero ·

Over the past few years, several AI-powered features have been added to mobile phones that allow users to better search and understand their messages. One effect of this change is increased...

The Register - Security ·

AI upstart also upscales its Labs to find the next frontier The Python Software Foundation (PSF) has an extra $1.5 million heading its way, after AI upstart Anthropic entered into a partnership...

Financial Services Critical Manufacturing
The Register - Security ·

First Patch Tuesday of 2026 goes big Microsoft and Uncle Sam have warned that a Windows bug disclosed today is already under attack.…

Government Facilities
Cyber Security Advisories - MS-ISAC ·

Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these...

Healthcare and Public Health Information Technology
Articles – Threat Beat ·

The scale and sophistication of foreign adversaries targeting critical infrastructure have made it imperative that offensive cyber – and the rules of the road on use – be added to our...

Salt Typhoon Energy Financial Services News
The Hacker News ·

Cybersecurity researchers have discovered a major web skimming campaign that has been active since January 2022, targeting several major payment networks like American Express, Diners Club,...

Financial Services Commercial Facilities
The Hacker News ·

Cybersecurity researchers have disclosed details of a malicious Google Chrome extension that's capable of stealing API keys associated with MEXC, a centralized cryptocurrency exchange (CEX)...

Financial Services Commercial Facilities
Threats | CyberScoop ·

Researchers said the information disclosure zero-day exposes sensitive information that attackers can use to undermine defenses and make other exploits more reliable. The post Microsoft Patch...

Research Threats
The Register - Security ·

The open-source libraries were created by Salesforce, Nvidia, and Apple with a Swiss group Vulnerabilities in popular AI and ML Python libraries used in Hugging Face models with tens of millions...

Healthcare and Public Health
maxwelldulin ·

v8 is a JavaScript engine that compiles JavaScript code into native machine code to make execution faster. The v8 Sandbox, a lightweight sandbox, is now a stable feature in Chrome. Why is this...

Maxwell Dulin's Resources ·

In JavaScript interpretters, there's a map (known as a hidden class) that represents the memory layout of a object. A map holds an array of property descriptors that contain information about each...

Unit 42 ·

Database platform MongoDB disclosed CVE-2025-14847, called MongoBleed. This is an unauthenticated memory disclosure vulnerability with a CVSS score of 8.7. The post Threat Brief: MongoDB...

High Profile Threats Vulnerabilities
SECURITY.COM ·

Reflections on how the web’s changed, how attackers exploit trust—and the visibility needed to protect it

Information Technology
Maxwell Dulin's Resources ·

When making a Cross Program Invocation (CPI) in Solana via invoke or invoke_signed, you provide a set of accounts to be used. In raw Solana, you pass in AccountInfo directly, which is a handle to...

The Hacker News ·

AI agents are no longer just writing code. They are executing it. Tools like Copilot, Claude Code, and Codex can now build, test, and deploy software end-to-end in minutes. That speed is reshaping...

Information Technology Commercial Facilities
Proofpoint News Feed ·

The one thing nearly every major tech CEO is putting at the top of their 2026 agenda? AI.

Financial Services
Cisco Talos Blog ·

Microsoft has released its monthly security update for January 2026, which includes 112 vulnerabilities affecting a range of products, including 8 that Microsoft marked as “critical”.

Information Technology Patch Tuesday
The Hacker News ·

Cybersecurity researchers have disclosed details of a previously undocumented and feature-rich malware framework codenamed VoidLink that's specifically designed for long-term, stealthy access to...

Information Technology Commercial Facilities
The Hacker News ·

Old Playbook, New Scale: While defenders are chasing trends, attackers are optimizing the basics The security industry loves talking about "new" threats. AI-powered attacks. Quantum-resistant...

Commercial Facilities Communications