IM
IronMonkey Threat Research
LIVE
|
Articles 25,834
|
CVEs 339,903
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 25,802 articles — Page 352 of 861
CERT Polska ·

SQL Injection vulnerability (CVE-2025-9339) has been found in SIMPLE.ERP software.

CVE vulnerability
DataBreaches.Net ·

Wojeski & Company suffered a ransomware attack, and then an insider breach when an employee of a firm hired to investigate the breach inappropriately accessed data. Employees were also...

Financial Services Healthcare and Public Health Business Sector Malware
The Register - Security ·

Japanese retailer halts online orders after attack cripples third-party vendor Japanese retailer Muji is suspending online orders after logistics partner Askul was knocked offline by a ransomware attack.…

Transportation Systems Critical Manufacturing
BleepingComputer ·

The Russian state-backed Star Blizzard hacker group has ramped up operations with new, constantly evolving malware families (NoRobot, MaybeRobot) deployed in complex delivery chains that start...

Star Blizzard Defense Industrial Base Information Technology Security
Schneier on Security ·

Scouting America (formerly known as Boy Scouts) has a new badge in cybersecurity. There’s an image in the article; it looks good. I want one.

Information Technology Uncategorized children
DataBreaches.Net ·

Over on Risky Biz News, Catalin Cimpanu has a great write-up about how a Romanian prisoner hacked the country’s prison management platform. He writes: The incident took place in August and...

Financial Services Healthcare and Public Health Government Sector Non-U.S.
DataBreaches.Net ·

Juan F. Luis Hospital CEO Darlene A. Baptiste says no personal data was stolen in the April cyberattack that forced the hospital offline for months, causing major billing delays, financial losses,...

Healthcare and Public Health Financial Services Health Data HIPAA
The Register - Security ·

CISA adds high-severity flaw to KEV list, urges swift updating Uncle Sam's cyber wardens have warned that a high-severity flaw in Microsoft's Windows SMB client is now being actively exploited –...

Financial Services
BleepingComputer ·

Gateways can do more than route traffic, they can also strengthen your entire security posture. Learn how NordLayer combines ZTNA, firewalls, and private gateways to secure hybrid teams and keep...

Transportation Systems Security
Cisco Talos Blog ·

Cisco Talos has observed increased activity by malicious actors leveraging Direct Send as part of phishing campaigns. Here's how to strengthen your defenses.

Financial Services On The Radar Landing Page Top Story
Securelist ·

Common email phishing tactics in 2025 include PDF attachments with QR codes, password-protected PDF documents, calendar phishing, and advanced websites that validate email addresses.

Mysterious Elephant Critical Manufacturing Information Technology Spam and phishing Spammer techniques
Vulnerabilities – The Cyber Express ·

A flaw rooted in the Server Message Block (SMB) protocol of Windows enables attackers to escalate privileges to SYSTEM level on vulnerable Windows devices, potentially granting full control over...

Healthcare and Public Health Communications Firewall Daily Cyber News
The Register - Security ·

Security pros explore whether infection-spoofing code can immunize Windows systems against attack Feature What's better, prevention or cure? For a long time the global cybersecurity industry has...

Healthcare and Public Health
BleepingComputer ·

Microsoft has fixed a major bug preventing Microsoft 365 users from launching the classic Outlook email client on Windows systems. [...]

Microsoft
Securelist ·

Kaspersky GReAT experts break down a recent PassiveNeuron campaign that targets servers worldwide with custom Neursite and NeuralExecutor APT implants and Cobalt Strike.

Mysterious Elephant Financial Services Critical Manufacturing Malware descriptions GReAT research
The Register - Security ·

Zero trust is the best kind of trust when it comes to securing your organization, says ZScaler Partner Content Many organizations across Europe have taken steps to implement Zero Trust principles,...

Critical Manufacturing Financial Services
The Register - Security ·

Calendar cock-up exposed recipients' details Anti-fraud nonprofit Cifas was left red-faced after sending out a calendar invite that exposed the email addresses of dozens of individuals working...

Government Facilities
BleepingComputer ·

Microsoft has released an emergency update to fix the Windows Recovery Environment (WinRE), which became unusable on systems with USB mice and keyboards after installing the October 2025 security...

Microsoft
The Hacker News ·

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added five security flaws to its Known Exploited Vulnerabilities (KEV) Catalog, officially confirming a recently...

Energy Information Technology
Cloud Threat Landscape ·

Attackers obtain remote code execution through abuse of SQL-server environments (exploitation, SQL injection, or credential compromise) and attempt to install web shells. When detection (e.g.,...

Vulnerabilities – The Cyber Express ·

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added five CVEs to its Known Exploited Vulnerabilities (KEV) catalog today, including Microsoft, Apple and Oracle vulnerabilities....

Communications Healthcare and Public Health Cyber News Firewall Daily
Security Latest ·

In just seven minutes, the thieves took off with crown jewels containing with thousands of diamonds along with other precious gems.

CIA Security Security / Security News
The Hacker News ·

It’s easy to think your defenses are solid — until you realize attackers have been inside them the whole time. The latest incidents show that long-term, silent breaches are becoming the norm. The...

Flax Typhoon Ethereal Panda Financial Services
The Hacker News ·

ClickFix, FileFix, fake CAPTCHA — whatever you call it, attacks where users interact with malicious scripts in their web browser are a fast-growing source of security breaches. ClickFix attacks...

Energy Information Technology
Threats | CyberScoop ·

The NSA did not confirm nor deny the allegations made by China’s Ministry of State Security. China said the origins of the attack date back to March 2022. The post China’s spy agency accuses NSA...

CIA Salt Typhoon Government Facilities Defense Industrial Base Cybersecurity Geopolitics
BleepingComputer ·

The DNS0.EU non-profit public DNS service focused on European users announced its immediate shut down due to time and resource constraints. [...]

Information Technology Communications Security Technology
The Hacker News ·

Cybersecurity researchers have uncovered a coordinated campaign that leveraged 131 rebranded clones of a WhatsApp Web automation extension for Google Chrome to spam Brazilian users at scale. The...

Energy Information Technology
DataBreaches.Net ·

Joseph Cox reports: A hacking group that recently doxed hundreds of government officials, including from the Department of Homeland Security (DHS) and Immigration and Customs Enforcement (ICE),...

Defense Industrial Base Government Facilities Hack DHS
DataBreaches.Net ·

Kim Zetter reports: The investigation into former national security advisor John Bolton’s handling of classified material stemmed in part from an admission Bolton made to the FBI in July 2021 that...

Government Facilities Commentaries and Analyses Government Sector
BleepingComputer ·

Microsoft has confirmed that this month's security updates disable USB mice and keyboards in the Windows Recovery Environment (WinRE), making it unusable. [...]

Communications Microsoft