IM
IronMonkey Threat Research
LIVE
|
Articles 27,345
|
CVEs 351,973
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 27,319 articles — Page 295 of 911
Wiz Blog | RSS feed ·

Building the future of cloud security, together.

Information Technology Financial Services
FortiGuard Labs Threat Research ·

FortiGuard Labs analyzes a phishing campaign delivering a fileless Remcos RAT via malicious Word templates, CVE-2017-11882 exploitation, and in-memory execution.

Transportation Systems Critical Manufacturing
The Record from Recorded Future News ·

CISA is giving civilian agencies until February 3 to fix a Windows vulnerability that can reveal where code resides in memory.

Government Facilities Healthcare and Public Health News Technology
CERT Polska ·

Exposure of Private Personal Information (CVE-2025-14317) has been identified in Crazy Bubble Tea mobile application.

CVE vulnerability
The Register - Security ·

Attack enters second day with major disruption to healthcare provision Two hospitals in Belgium have cancelled surgeries and transferred critical patients to other facilities after shutting down...

Healthcare and Public Health Emergency Services
The Register - Security ·

Travel biz tells customers to change passwords beyond its own services Eurail has confirmed customer information was stolen in a data breach, according to notification emails sent out this week.…

Financial Services Healthcare and Public Health
The Hacker News ·

Node.js has released updates to fix what it described as a critical security issue impacting "virtually every production Node.js app" that, if successfully exploited, could trigger a...

Information Technology Commercial Facilities
The Register - Security ·

U-turn leaves questions on costs, funding, and benefits unanswered The UK government has backed down from making digital ID mandatory for proof of a right to work in the country, adding to...

Government Facilities
Cyber Security Advisories - MS-ISAC ·

Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution.Adobe Bridge is a creative asset manager that lets you preview,...

Transportation Systems Healthcare and Public Health
CERT Polska ·

Missing Password Field Masking vulnerability (CVE-2025-13175) has been found in Ysoft SafeQ 6 software.

CVE vulnerability
The Hacker News ·

The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of new cyber attacks targeting its defense forces with malware known as PLUGGYAPE between October and December 2025....

Void Blizzard Laundry Bear Commercial Facilities Communications
Cisco Talos Blog ·

Terryn’s path to cybersecurity started with a fascination for criminal forensics and a knack for jailbreaking his family's tech — interests that eventually steered him toward the fast-paced world...

Humans of Talos
SECURITY.COM ·

New whitepaper reveals record number of attacks as threat landscape evolves with new players and new tactics.

Information Technology Transportation Systems
The Register - Security ·

Endesa says payment info stolen after alleged crook boasted of 1 TB-plus haul Spanish energy giant Endesa is warning customers about a data breach after a cybercrim claimed to have walked off with...

Energy Financial Services
Project Zero ·

While our previous two blog posts provided technical recommendations for increasing the effort required by attackers to develop 0-click exploit chains, our experience finding, reporting and...

Financial Services Government Facilities
WeLiveSecurity ·

Should verified identities become the standard online? Australia’s social media ban for under-16s shows why the question matters.

Communications Financial Services Social Media
Project Zero ·

With the advent of a potential Dolby Unified Decoder RCE exploit, it seemed prudent to see what kind of Linux kernel drivers might be accessible from the resulting userland context, the mediacodec...

Project Zero ·

Over the past few years, several AI-powered features have been added to mobile phones that allow users to better search and understand their messages. One effect of this change is increased...

The Register - Security ·

AI upstart also upscales its Labs to find the next frontier The Python Software Foundation (PSF) has an extra $1.5 million heading its way, after AI upstart Anthropic entered into a partnership...

Financial Services Critical Manufacturing
The Register - Security ·

First Patch Tuesday of 2026 goes big Microsoft and Uncle Sam have warned that a Windows bug disclosed today is already under attack.…

Government Facilities
Cyber Security Advisories - MS-ISAC ·

Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these...

Healthcare and Public Health Information Technology
Articles – Threat Beat ·

The scale and sophistication of foreign adversaries targeting critical infrastructure have made it imperative that offensive cyber – and the rules of the road on use – be added to our...

Salt Typhoon Energy Financial Services News
The Hacker News ·

Cybersecurity researchers have discovered a major web skimming campaign that has been active since January 2022, targeting several major payment networks like American Express, Diners Club,...

Financial Services Commercial Facilities
The Hacker News ·

Cybersecurity researchers have disclosed details of a malicious Google Chrome extension that's capable of stealing API keys associated with MEXC, a centralized cryptocurrency exchange (CEX)...

Financial Services Commercial Facilities
Threats | CyberScoop ·

Researchers said the information disclosure zero-day exposes sensitive information that attackers can use to undermine defenses and make other exploits more reliable. The post Microsoft Patch...

Research Threats
The Register - Security ·

The open-source libraries were created by Salesforce, Nvidia, and Apple with a Swiss group Vulnerabilities in popular AI and ML Python libraries used in Hugging Face models with tens of millions...

Healthcare and Public Health
maxwelldulin ·

v8 is a JavaScript engine that compiles JavaScript code into native machine code to make execution faster. The v8 Sandbox, a lightweight sandbox, is now a stable feature in Chrome. Why is this...

Maxwell Dulin's Resources ·

In JavaScript interpretters, there's a map (known as a hidden class) that represents the memory layout of a object. A map holds an array of property descriptors that contain information about each...

Unit 42 ·

Database platform MongoDB disclosed CVE-2025-14847, called MongoBleed. This is an unauthenticated memory disclosure vulnerability with a CVSS score of 8.7. The post Threat Brief: MongoDB...

High Profile Threats Vulnerabilities
SECURITY.COM ·

Reflections on how the web’s changed, how attackers exploit trust—and the visibility needed to protect it

Information Technology