IM
IronMonkey Threat Research
LIVE
|
Articles 25,463
|
CVEs 337,950
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 25,432 articles — Page 28 of 848
Seqrite Labs ·

Ask a plant manager what keeps them up at night, and you’ll hear the usual answers: machine downtime, supply chain delays, quality issues, and labor gaps. But in 2026, endpoint protection for...

Critical Manufacturing Endpoint Protection CAD Data Protection
The Cloudflare Blog ·

In recent weeks, we pointed Mythos and other security-focused LLMs at live code across critical parts of our infrastructure. We share what we observed, the models’ strengths and weaknesses, and...

Information Technology Security AI
BleepingComputer ·

Microsoft has confirmed that the May 2026 Windows 11 security update (KB5089549) fails to install on some systems and triggers 0x800f0922 errors. [...]

Information Technology Microsoft Security
BleepingComputer ·

A recently patched local privilege escalation vulnerability in the Linux kernel's rxgk module now has a proof-of-concept exploit that allows attackers to gain root access on some Linux systems. [...]

Information Technology Security Linux
www.theregister.com - Articles ·

Multiple researchers using the same tools to find the same bugs are creating ‘unnecessary pain and pointless work’

Information Technology security
BleepingComputer ·

The Pwn2Own Berlin 2026 hacking contest has concluded, with security researchers collecting $1,298,250 in rewards after exploiting 47 zero-day flaws. [...]

Information Technology Security
Cloud Threat Landscape ·

Researchers identified a broad TeamPCP-linked supply chain campaign involving malicious NPM packages, compromised GitHub Actions, a trojanized VSCode extension, and malicious PyPI packages...

Information Technology
BleepingComputer ·

A cybersecurity researcher has released a proof-of-concept exploit for a Windows privilege escalation zero-day dubbed "MiniPlasma" that lets attackers gain SYSTEM privileges on fully patched...

Information Technology Microsoft Security
The Hacker News ·

A newly disclosed security flaw impacting NGINX Plus and NGINX Open has come under active exploitation in the wild, days after its public disclosure, according to VulnCheck. The vulnerability,...

Information Technology
The Hacker News ·

Grafana has disclosed that an "unauthorized party" obtained a token that granted them the ability to access the company's GitHub environment and download its codebase. "Our investigation has...

Scattered Spider ShinyHunters Information Technology
Industrial Cyber ·

Ransomware groups are increasingly being used as proxy weapons in geopolitical cyber warfare, enabling nation-states to exert pressure... The post State-backed ransomware activity raises new...

Twill Typhoon Critical Manufacturing Transportation Systems Attacks and Vulnerabilities Control device security
BleepingComputer ·

The Tycoon2FA phishing kit now supports device-code phishing attacks and abuses Trustifi click-tracking URLs to hijack Microsoft 365 accounts. [...]

Information Technology Security
The Hacker News ·

A critical security vulnerability impacting the Funnel Builder plugin for WordPress has come under active exploitation in the wild to inject malicious JavaScript code into WooCommerce checkout...

Information Technology
BleepingComputer ·

A security researcher claims Microsoft quietly fixed an Azure Backup for AKS vulnerability after rejecting his report, and without issuing a CVE. Microsoft disputes the claim, telling...

Information Technology Security
SECURITY.COM ·

New analysis confirms the targeted applications and reveals fast16 was tailored to corrupt uranium-compression simulations central to nuclear weapon design.

Energy Nuclear
Security Latest ·

Plus: Instructure’s Canvas ransomware debacle comes to a close, an alleged dark net market kingpin gets arrested, OpenAI workers fall victim to a supply chain attack, and more.

Scattered Spider Nitro Information Technology Critical Manufacturing Security Security / Cyberattacks and Hacks
BleepingComputer ·

The Russian hacker group Secret Blizzard has developed its long-running Kazuar backdoor into a modular peer-to-peer (P2P) botnet designed for long-term persistence, stealth, and data collection. [...]

Turla Venomous Bear Secret Blizzard Information Technology Government Facilities Security
Schneier on Security ·

Article about the bigfin squid. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.

Information Technology Uncategorized squid
The Hacker News ·

The Russian state-sponsored hacking group known as Turla has transformed its custom backdoor Kazuar into a modular peer-to-peer (P2P) botnet that's engineered for stealth and persistent access to...

The Record from Recorded Future News ·

THORChain officials said the investigation into the incident is ongoing but explained that one of their six vaults was compromised, leading to a loss of about $10.7 million.

Financial Services Information Technology Cybercrime News
Alerts and advisories ·

FreePBX security advisory (AV26–474)

Information Technology
The Hacker News ·

Cybersecurity researchers have disclosed a set of four security flaws in OpenClaw that could be chained to achieve data theft, privilege escalation, and persistence. The vulnerabilities,...

eCrime.ch Ransomware News | RSS ·

The Federal Bureau of Investigation (FBI) is providing this Public Service Announcement (PSA) to warn of potential future impacts related to a cyber-attack that affected an online Learning...

Government Facilities Financial Services
eCrime.ch Ransomware News | RSS ·

Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the "BlackFile" brand, that targets organizations via...

ShinyHunters Information Technology Financial Services
The Hacker News ·

In Your Biggest Security Risk Isn't Malware — It's What You Already Trust, we made a simple argument: the most dangerous activity inside most organizations no longer looks like an attack. It looks...

Information Technology
The Hacker News ·

OpenAI has disclosed that two of its employee devices in its corporate environment were impacted via the Mini Shai-Hulud supply chain attack on TanStack, but noted that no user data, production...

Information Technology Critical Manufacturing
Cyber Security Advisories - MS-ISAC ·

A vulnerability has been discovered in Microsoft Exchange Server that could allow for arbitrary code execution. Microsoft Exchange Server is an enterprise-level email and collaboration platform...

Information Technology Government Facilities
BleepingComputer ·

A critical vulnerability in the Funnel Builder plugin for WordPress is being actively exploited to inject malicious JavaScript snippets into WooCommerce checkout pages. [...]

Financial Services Information Technology Security
SECURITY.COM ·

How to protect productivity without slowing down innovation

Information Technology
Alerts and advisories ·

AL26-012 - Critical vulnerability affecting Cisco Catalyst SD-WAN - CVE-2026-20182

Information Technology Communications