IM
IronMonkey Threat Research
LIVE
|
Articles 25,652
|
CVEs 338,940
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 25,620 articles — Page 262 of 854
The Hacker News ·

A new campaign named GhostPoster has leveraged logo files associated with 17 Mozilla Firefox browser add-ons to embed malicious JavaScript code designed to hijack affiliate links, inject tracking...

Information Technology
Cyble ·

The Australian Cyber Security Centre (ACSC) has published a new guide, Quantum Technology Primer: Overview, aimed at helping organizations understand the field of quantum technologies for...

Information Technology Critical Manufacturing Cyber news Cybersecurity
Schneier on Security ·

For two days in September, Afghanistan had no internet. No satellite failed; no cable was cut. This was a deliberate outage, mandated by the Taliban government. It followed a more localized...

Communications Energy Uncategorized denial of service
Cisco Talos Blog ·

Lexi DiScola shares how her unconventional path led her to global cyber threat analysis and highlights the power of diverse backgrounds on an international team

Humans of Talos
Security Latest ·

The weak RC4 for administrative authentication has been a hacker holy grail for decades.

Defense Industrial Base Healthcare and Public Health Security Security / Cyberattacks and Hacks
The Register - Security ·

Regulator proposes strict limits on screen-based testing, cites infrastructure concerns and lack of evidence for benefits Most students taking school and college GCSE, A-level, and AS-level exams...

Securelist ·

Kaspersky's GReAT experts have uncovered a new wave of cyberattacks by the ForumTroll APT group, targeting Russian political scientists and delivering the Tuoni framework to their devices.

Mysterious Elephant ToddyCat Hacking Team Critical Manufacturing Financial Services APT reports GReAT research
Tenable Blog ·

The Monetary Authority of Singapore’s cloud advisory, part of its 2021 Technology Risk Management Guidelines, advises financial institutions to move beyond siloed monitoring to adopt a continuous,...

Financial Services Information Technology
eCrime.ch Ransomware News | RSS ·

[11/20/2025] – Fieldtex Products, Inc. (“Fieldtex”) has become aware of a data security incident that may have impacted certain protected health information. Fieldtex is a medical supply...

Healthcare and Public Health Financial Services
Recorded Future ·

Discover how Russia’s BlueDelta targets UKR.NET users with advanced credential-harvesting campaigns, evolving tradecraft, and multi-stage phishing techniques.

Fancy Bear Forest Blizzard BlueDelta Information Technology Defense Industrial Base Research (Insikt)
Recorded Future ·

A $0 card test signaled a Chinese state-linked cyberattack on Anthropic’s AI platform. Learn how card-testing fraud intelligence spots nation-state ops early.

Financial Services Blog
Cloud Threat Landscape ·

On December 17, 2025 Cisco announced that they had detected a campaign exploiting a zero day in their email security devices. The vulnerability affects the physical and virtual versions of Cisco...

Recorded Future ·

Discover how PurpleBravo, a North Korean threat group, exploits fake job offers to target software supply chains, using RATs and infostealers like BeaverTail.

Safe Tenacious Pungsan PurpleBravo Financial Services Information Technology Research (Insikt)
Recorded Future ·

China is consolidating cyber power through zero-days. Explore how state control of vulnerabilities enables long-term strategic advantage.

Volt Typhoon Energy Defense Industrial Base Research (Insikt)
Recorded Future ·

Offensive cyber operations are spreading beyond the Big Four. Discover how regional conflicts are driving new state-linked cyber threats.

Marbled Dust Stealth Falcon Defense Industrial Base Energy Research (Insikt)
The Register - Security ·

Misconfigured servers are in, 0-days out Chinese espionage crew Ink Dragon has expanded its snooping activities into European government networks, using compromised servers to create illicit relay...

Government Facilities Energy
Maxwell Dulin's Resources ·

In both EVM and Solana programs, a common security issue is not validating external calls properly. This can led to DOS issues, reentrancy or loss of funds bugs. This article has a list of 7...

Energy
Maxwell Dulin's Resources ·

Ethereum storage is very simple: a 32-byte slot with 32-byte values. Mapping these slots back to meaningful variable names and use cases is difficult to do though. This post is about going from...

Energy
Maxwell Dulin's Resources ·

While reviewing the application, the author of the post found a self-XSS vulnerability. Normally, this doesn't have any impact on other users but they wanted to create it. Thus starts the chain!...

The Hacker News ·

An ongoing campaign has been observed targeting Amazon Web Services (AWS) customers using compromised Identity and Access Management (IAM) credentials to enable cryptocurrency mining. The...

Information Technology Financial Services
The Register - Security ·

An employee of the adult site could be responsible. Analytics vendor Mixpanel says it is not the source of data stolen from Pornhub and says the info was last accessed by an employee of the adult site.…

ShinyHunters
Maxwell Dulin's Resources ·

HttpWebClientProtocol has several variants of it - the main focus in this post is SoapHttpClientProtocol. Since this has HTTP in it, it's completely understandable that it would only support HTTP....

The Hacker News ·

Cybersecurity researchers have discovered a new malicious NuGet package that typosquats and impersonates the popular .NET tracing library and its author to sneak in a cryptocurrency wallet...

Financial Services Information Technology
Maxwell Dulin's Resources ·

XSS is cool and all but there's more to it. This wiki goes into other frontend security issues like CSRF, prototype pollution, CSS injection and many other things. Just a good reference overall.

Critical Manufacturing
The Register - Security ·

More than 8 million people have installed extensions that eavesdrop on chatbot interactions Ad blockers and VPNs are supposed to protect your privacy, but four popular browser extensions have been...

Maxwell Dulin's Resources ·

The author of this post created a long-tail MEV strategy around the hourly Bean emissions on the Beanstalk protocol. By coordinating with several other MEV's, they were able to collectively earn...

Energy Food and Agriculture
Maxwell Dulin's Resources ·

AI tools are being integrated deeper and deeper into our workflow. As this happens, this opens up the attack surface to trick the bot into doing malicious things with attacker controlled input....

Energy
Articles – Threat Beat ·

WASHINGTON – House Homeland Security Chairman Andrew Garbarino (R-N.Y.) said that he wants to see proactive offensive cyber capabilities take a prime role in the White House’s forthcoming national...

Defense Industrial Base Government Facilities News
Maxwell Dulin's Resources ·

Gemini's Markdown renderer fails to sanitize HTML-like content within code blocks when there are premature code fence terminations (```). An example payload: ``` test ``` ``` ```` ... The payload...

The Register - Security ·

All I want for Christmas … is all of your data A new, modular infostealer called SantaStealer, advertised on Telegram with a basic tier priced at $175 per month, promises to make criminals'...

Financial Services