A specter is haunting Europe — the specter of ransomware. After a global lull in 2024 and 2025, the ransomware-as-a-service (RaaS) ecosystem appears to be back to form, at least in Europe....
Microsoft says latest attack targets Leo Platform and RStreams packages, harvesting creds and going after more maintainers
A cyberattack has snarled logistics and accounting operations at a dairy producer in Russia’s republic of Bashkortostan, forcing the company to process shipments and paperwork manually, according...
The Federal Communications Commission approved new rules Thursday that boost cybersecurity regulations for the nation’s emergency alert systems and update security rules for the nation’s undersea...
The research infrastructure that underpins America’s prowess in defense technology is “deteriorating,” according to a Department of Defense report released Wednesday. One reason is that research...
CISA has been constrained by not having a Senate-confirmed director since January 2025, but is ready to rebound once the expected nominee is in place, Homeland Security Secretary Markwayne Mullin...
Apple removed VK's flagship social network VKontakte, often described as Russia's equivalent of Facebook, along with VK Music, VK Messenger, VK Video, Odnoklassniki and Mail.ru services, including...
China has been abandoning used launcher rocket stages in low Earth orbit (LEO) at an ever-increasing pace, putting both military and commercial satellites in that crowded orbital regime at greater...
Ukraine's SBU described a long-running Russian operation that used fake tech-support workers to persuade people to hand over credentials to their messaging apps.
Analysis of CVE-2024-2658 as found in Schneider Electric's Floating License Manager. Discover how this FlexNet Publisher vulnerability potentially allows attackers to escalate to NT...
Operation Endgame takes down Amadey and StealC servers, macOS.Gaslight floods AI triage with fake errors, and attackers exploit Cisco flaws for root access.
The Russian state-sponsored threat actor known as Turla has been attributed to a previously undocumented .NET backdoor called STOCKSTAY that has been deployed against government and military...
In an unprecedented move, the FCC also said it plans to mandate that owners and operators of submarine line terminal equipment (SLTE) be licensed.
By automatically loading MCP servers from workspace files, Amazon Q enabled attackers to execute code and access sensitive cloud environments.
A database of almost a million passports from around the world was leaked online. Note what happened. A high-value credential—a passport—was used in an ancillary low-value authentication system:...
Authors: Dixit Panchal & Soumen Burma Table of Contents: Introduction: Key Targets: Infection Chain: Initial Findings about Campaign: Initial Mail: Email Attachment: Lure: Official GoI, Income Tax...
Your business may be small, but its attack surface is anything but. Readiness is the first step to resilience.
One rule for the workers, another for execs
In June 2026, telecommunications tower infrastructure company American Tower was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data allegedly...
Qihoo 360, which the US has banned, says it’s needed as a deterrent to weaponized Anthropic models
Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these...
Spotted in intrusions targeting insurance, education, IT, and professional services sectors
Former employee accuses company of prioritizing pending IPO over client security
Government entities and critical infrastructure were targeted for espionage in SE Asia by attackers using a hybrid toolkit, including custom TinyRCT backdoor. The post CL-STA-1062 Targets...
An analysis of a popular Google Chrome ad block extension for YouTube has uncovered the ability to execute arbitrary JavaScript code. According to Island, the extension, named Adblock for YouTube...
In this week’s newsletter, Martin considers how AI will help threat intelligence by creating an easily queryable data source of intelligence reports.
It’s dumb out there again. This week has the usual smell of prod on fire and nobody wanting to admit who left the door open — old creds still working, trusted apps doing sketchy crap, browser...
Senior research associate Emile Dirks has been elected to serve as a member of PEN Canada's board of directors. The post Emile Dirks Elected to PEN Canada’s Board of Directors appeared first on...
Earlier this month, a German court ruled that Google is liable for its AI search summaries. Rejecting defenses like “users can check for themselves,” and that they generally know “that information...
Despite the abundance of telemetry at analysts’ disposal, many security operations teams struggle to answer a few basic questions during incident investigation: What happened? What evidence do we...