IM
IronMonkey Threat Research
LIVE
|
Articles 27,334
|
CVEs 351,965
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 27,302 articles — Page 257 of 911
BleepingComputer ·

AMOS infostealer is targeting macOS users by abusing popular AI apps and extension marketplaces to harvest credentials. Flare examines how AMOS operates, spreads through AI-driven lures, and feeds...

Financial Services Energy Security
Tenable Blog ·

“Tenable’s asset and attack surface coverage, its application of AI and its reputation for vulnerability assessment makes it the front-runner in AI-powered exposure assessment,” Gartner writes in...

Information Technology Financial Services
Tenable Blog ·

“Tenable’s asset and attack surface coverage, its application of AI and its reputation for vulnerability assessment makes it the front-runner in AI-powered exposure assessment,” Gartner writes in...

Information Technology Financial Services
BleepingComputer ·

A set of 30 malicious Chrome extensions that have been installed by more than 300,000 users are masquerading as AI assistants to steal credentials, email content, and browsing information. [...]

Security Artificial Intelligence
eCrime.ch Ransomware News | RSS ·

Two Russian nationals stand trial in Paris in a case emblematic of the wave of ransomware attacks that France has seen for more than six years. The trial opening Wednesday, February 11, before the...

Government Facilities Food and Agriculture
Proofpoint News Feed ·

Acquisition of AI security innovator positions Proofpoint as the first cybersecurity platform to comprehensively address agentic workspace protection at the intersections of humans, data, and AI

Healthcare and Public Health
The Register - Security ·

Meanwhile, IP-stealing 'distillation attacks' on the rise A Chinese government hacking group that has been sanctioned for targeting America's critical infrastructure used Google's AI chatbot,...

Judgment Panda Violet Typhoon Critical Manufacturing
The Record from Recorded Future News ·

The Dordrecht native was detained on Tuesday by police in East Brabant on accusations he distributed a bot called JokerOTP, which is used widely by cybercriminals to intercept the codes delivered...

Energy Financial Services Cybercrime News
BleepingComputer ·

Google Threat Intelligence Group (GTIG) has published a new report warning about AI model extraction/distillation attacks, in which private-sector firms and researchers use legitimate API access...

Financial Services Security Artificial Intelligence
The Register - Security ·

Businesses are embedding prompts that produce content they want you to read, not the stuff AI makes if left to its own devices Amid its ongoing promotion of AI’s wonders, Microsoft has warned...

Recorded Future ·

Download Recorded Future's 2026 State of Security report which provides comprehensive threat intelligence on geopolitical fragmentation, state-sponsored operations, ransomware evolution, and...

RedMike Defense Industrial Base Communications Research (Insikt)
Recorded Future ·

The global threat landscape didn't simplify in 2025 — it shattered. The 2026 State of Security report represents Insikt Group's most comprehensive threat intelligence analysis to date, drawing on...

Defense Industrial Base Communications Blog
Project Zero ·

Bypassing Administrator Protection by Abusing UI Access In my last blog post I introduced the new Windows feature, Administrator Protection and how it aimed to create a secure boundary for UAC...

The Hacker News ·

Cybersecurity researchers have discovered what they said is the first known malicious Microsoft Outlook add-in detected in the wild. In this unusual supply chain attack detailed by Koi Security,...

Lotus Blossom Critical Manufacturing Information Technology
Unit 42 ·

Unit 42 reveals new infrastructure associated with the Notepad++ attack. This expands understanding of threat actor operations and malware delivery. The post Nation-State Actors Exploit Notepad++...

High Profile Threats Malware
Threats | CyberScoop ·

Most signs suggest the group is running a massive hoax by claiming hundreds of initial victims, but at least some of the threat 0APT poses is grounded in truth backed by proven capabilities. The...

Salt Typhoon Energy Communications Cybercrime Ransomware
Alerts and advisories ·

Apple security advisory (AV26-122)

maxwelldulin ·

Axelar is a cross-chain protocol similar to Wormhole and Layer Zero. Normally, with finalization, the Axelar network sends a message to the core contract. Then, the calling contracts checks to see...

Energy
Alerts and advisories ·

Drupal security advisory (AV26-121)

Security Latest ·

Petitions demanding people get the chance to be released from ICE custody have overwhelmed courts throughout the US.

Financial Services Energy Security Security / National Security
The Register - Security ·

Add-ons with 37M installs leak visited URLs to 30+ recipients, researcher says They know where you've been and they're going to share it. A security researcher has identified 287 Chrome extensions...

Energy
Maxwell Dulin's Resources ·

The repository contains a set of Claude Skills for Solidity smart contract vulnerabilities. They range from authorization on tx.origin to more nuanced/contextualized things like access control...

Maxwell Dulin's Resources ·

The ERC4337 (Account Abstraction) implementation assumes that UserOperation binds the protocol to run the user's transaction only by the intended user. In particular, being sent directly to the...

Energy
Maxwell Dulin's Resources ·

Starknet is an L1 that utilizes a ZK prover. The blockifier is the creator of the blocks and proofs. I imagine that they have a centralized sequencer, but I'm not sure. Recently, they experienced...

Alerts and advisories ·

Commvault security advisory (AV26-120)

Alerts and advisories ·

[Control systems] Schneider Electric security advisory (AV26-119)

Alerts and advisories ·

HPE security advisory (AV26-117)

Alerts and advisories ·

Palo Alto Networks security advisory (AV26-118)

Information Technology
The Hacker News ·

Indian defense sector and government-aligned organizations have been targeted by multiple campaigns that are designed to compromise Windows and Linux environments with remote access trojans...

Lotus Blossom Transparent Tribe Defense Industrial Base Energy
Maxwell Dulin's Resources ·

Ticket Tricking is a technique to get OTPs or verification emails sent to a public forum so that you can "prove" you have access to a domain when you really don't. Google Groups have this risk and...

Information Technology