IM
IronMonkey Threat Research
LIVE
|
Articles 25,644
|
CVEs 338,787
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 25,612 articles — Page 246 of 854
The Register - Security ·

No reports of active exploitation … yet Cisco patched a bug in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) products that allows remote attackers with...

The Hacker News ·

The internet never stays quiet. Every week, new hacks, scams, and security problems show up somewhere. This week’s stories show how fast attackers change their tricks, how small mistakes turn into...

MuddyWater Double Dragon Bronze Atlas Energy Financial Services
Threats | CyberScoop ·

Among the 66 international organizations the administration withdrew from are a handful that work on cybersecurity topics. The post Trump pulls US out of international cyber orgs appeared first on...

Commercial Facilities Geopolitics Privacy
The Hacker News ·

Chainguard, the trusted source for open source, has a unique view into how modern organizations actually consume open source software and where they run into risk and operational burdens. Across a...

Information Technology Financial Services
The Hacker News ·

Cisco has released updates to address a medium-severity security flaw in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) with a public proof-of-concept (PoC) exploit....

Financial Services Information Technology
The Hacker News ·

Cybersecurity researchers have discovered three malicious npm packages that are designed to deliver a previously undocumented malware called NodeCordRAT. The names of the packages, all of which...

Financial Services Information Technology
CERT Polska ·

An issue allowing unauthorized access to medical records (CVE-2025-4596) was found in Asseco AMDX software.

Healthcare and Public Health CVE vulnerability
The Hacker News ·

Cybersecurity researchers have disclosed details of multiple critical-severity security flaws affecting Coolify, an open-source, self-hosting platform, that could result in authentication bypass...

Financial Services Information Technology
Wiz Blog | RSS feed ·

Learn what you can do today to prepare for Q-Day

Information Technology Government Facilities
The Register - Security ·

Cop wins hit crime infrastructure, not the people behind it If 2025 was meant to be the year ransomware started dying, nobody appears to have told the attackers.…

CERT Polska ·

CERT Polska has received a report about 2 vulnerabilities (CVE-2025-8306 and CVE-2025-8307) found in Asseco InfoMedica Plus software.

Healthcare and Public Health CVE vulnerability
The Register - Security ·

Max-severity OneView hole joins a PowerPoint bug that should've been retired years ago CISA has added a pair of security holes to its actively exploited list, warning that attackers are now...

eCrime.ch Ransomware News | RSS ·

In late 2024 and throughout 2025, a sophisticated ransomware group known as SafePay emerged, rapidly escalating its operations to become a significant global threat. Unlike the dominant...

Lazarus Group Earth Krahang Safe Financial Services Healthcare and Public Health
SECURITY.COM ·

What you don’t know can (and absolutely will) hurt you

Financial Services Government Facilities
Cyble ·

The cyber threat environment in Australia and New Zealand experienced a new escalation throughout 2025, driven by a surge in initial access sales, ransomware operations, and high-impact data...

Scattered Spider Financial Services Commercial Facilities Cyber news Cybersecurity
The Register - Security ·

Lawyers say Musk's platform may face punishment under Online Safety Act priority offenses Elon Musk's X platform is under fire as UK regulators close in on mounting reports that the platform's AI...

Communications Financial Services
The Hacker News ·

Artificial intelligence (AI) company OpenAI on Wednesday announced the launch of ChatGPT Health, a dedicated space that allows users to have conversations with the chatbot about their health. To...

Healthcare and Public Health Financial Services
Schneier on Security ·

Leaders of many organizations are urging their teams to adopt agentic AI to improve efficiency, but are finding it hard to achieve any benefit. Managers attempting to add AI agents to existing...

Lead Healthcare and Public Health Critical Manufacturing Uncategorized AI
The Register - Security ·

Unauthenticated RCE means anyone on the network can seize full control A maximum-severity bug in the popular automation platform n8n has left an estimated 100,000 servers wide open to complete...

Energy Financial Services
The Register - Security ·

Happy Groundhog Day! Security researchers at Radware say they've identified several vulnerabilities in OpenAI's ChatGPT service that allow the exfiltration of personal information.…

Healthcare and Public Health
Unit 42 ·

AI-generated code looks flawless until it isn't. Unit 42 breaks down how to expose these invisible flaws before they turn into your next breach. The post Securing Vibe Coding Tools: Scaling...

General Insights
The Register - Security ·

They also hallucinate when writing ransomware code Interview With everyone from would-be developers to six-year-old kids jumping on the vibe coding bandwagon, it shouldn't be surprising that...

Cisco Talos Blog ·

Talos assesses with high confidence that UAT-7290 is a sophisticated threat actor falling under the China-nexus of Advanced Persistent Threat actors (APTs). UAT-7290 primarily targets...

Purple Typhoon Communications Defense Industrial Base APT malware
The Hacker News ·

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added two security flaws impacting Microsoft Office and Hewlett Packard Enterprise (HPE) OneView to its Known...

Financial Services Information Technology
WeLiveSecurity ·

Reusing passwords may feel like a harmless shortcut – until a single breach opens the door to multiple accounts

Commercial Facilities Financial Services Digital Security
The Register - Security ·

Company says it dropped the ball, apologizes for wasting people's time Logitech says an expired developer certificate is to blame after swaths of customers were left infuriated when their mice...

Communications
The Register - Security ·

Suggests rotten routing, not evidence of a cyber-strike before kinetic action Cloudflare has poured cold water on a theory that the USA’s incursion into Venezuela coincided with a cyberattack on...

Information Technology Communications
Threats | CyberScoop ·

Roughly 100,000 servers running the automated workflow platform for AI and other enterprise tools are potentially exposed to exploitation. The post Researchers rush to warn defenders of...

Energy Cybersecurity Research
The Hacker News ·

A cybercrime gang known as Black Cat has been attributed to a search engine optimization (SEO) poisoning campaign that employs fraudulent sites advertising popular software to trick users into...

Financial Services Emergency Services
The Register - Security ·

Prompt injection lets risky commands slip past guardrails IBM describes its coding agent thus: "Bob is your AI software development partner that understands your intent, repo, and security...