IM
IronMonkey Threat Research
LIVE
|
Articles 25,891
|
CVEs 340,083
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 25,859 articles — Page 441 of 862
BleepingComputer ·

A novel tapjacking technique can exploit user interface animations to bypass Android's permission system and allow access to sensitive data or trick users into performing destructive actions, such...

Safe
Cyber Security Advisories - MS-ISAC ·

A vulnerability has been discovered FortiWeb, which could allow for SQL injection. FortiWeb is a web application firewall (WAF) developed by Fortinet. It's designed to protect web applications and...

Communications
infosecurity-magazine ·

Researchers from Koi Security have detected 18 malicious Chrome and Edge extensions masquerading as benign productivity and entertainment tools

Scattered Spider Information Technology Commercial Facilities
DoublePulsar - Medium ·

CitrixBleed 2 exploitation started mid-June — how to spot itCitrixBleed 2 — CVE-2025–5777 — has been under active exploitation to hijack Netscaler sessions, bypassing MFA, globally for a month.I...

ransomware cybersecurity-news
Security News | TechCrunch ·

The retail giant's chair confirmed the breach was caused by ransomware.

Commercial Facilities Financial Services
Cyber Security Advisories - MS-ISAC ·

Multiple vulnerabilities have been discovered in Microsoft products, the most severe of which could allow for remote code execution in the context of the logged on user. Depending on the...

Information Technology
The Hacker News ·

Russian organizations have been targeted as part of an ongoing campaign that delivers a previously undocumented Windows spyware called Batavia. The activity, per cybersecurity vendor Kaspersky,...

Scattered Spider Financial Services Transportation Systems
Latest stories for ZDNET in Security ·

Smarter TV operating systems bring added convenience, but they also raise fresh privacy concerns - especially when it comes to automatic content recognition (ACR).

Commercial Facilities Critical Manufacturing
Tenable Blog ·

12Critical115Important1Moderate0LowMicrosoft addresses 128 CVEs, including one zero-day vulnerability that was publicly disclosed.Microsoft addresses 128 CVEs in its July 2025 Patch Tuesday...

Information Technology Energy
BleepingComputer ·

Microsoft has released the KB5062554 cumulative update for Windows 10 22H2 and Windows 10 21H2, with thirteen new fixes or changes. [...]

Safe
The Record from Recorded Future News ·

Moscow-based cybersecurity firm Kaspersky said the campaign has already affected over 100 victims across several dozen Russian organizations, but did not disclose the specific targets.

Defense Industrial Base Critical Manufacturing
Google Online Security Blog ·

Posted by David Adrian, Javier Castro & Peter Kotwicz, Chrome Security Team Android recently announced Advanced Protection, which extends Google’s Advanced Protection Program to a device-level...

BleepingComputer ·

Microsoft has released Windows 11 KB5062553 and KB5062552 cumulative updates for versions 24H2 and 23H2 to fix security vulnerabilities and issues. [...]

Safe
BleepingComputer ·

Today is Microsoft's July 2025 Patch Tuesday, which includes security updates for 137 flaws, including one publicly disclosed zero-day vulnerability in Microsoft SQL Server. [...]

Information Technology Communications
Sharp insights on cybersecurity ·

Thousands of companies rely on Microsoft Entra ID for identity and access management (IAM), including more than half of the Fortune 500 companies. From user authentication to access control for...

Void Blizzard Information Technology Commercial Facilities
infosecurity-magazine ·

Check Point discovered around 500 suspected Scattered Spider phishing domains, suggesting the group is preparing to expand its targeting

Scattered Spider Transportation Systems Commercial Facilities
Dragos ·

On June 26, 2025, the Federal Energy Regulatory Commission (FERC or the Commission) issued Order No. 907 1 formally approving...

Energy Communications
Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto ·

Identity-based cyberattacks soar 156%, driven by cheap Phishing-as-a-Service & infostealer malware. Learn how criminals bypass MFA to steal credentials, access bank accounts, and compromise...

Transparent Tribe Financial Services
BleepingComputer ·

The Anatsa banking trojan has sneaked into Google Play once more via an app posing as a PDF viewer that counted more than 50,000 downloads. [...]

Safe Financial Services
The Hacker News ·

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in...

Scattered Spider Earth Lusca Financial Services Transportation Systems
BleepingComputer ·

Exposed RDP ports are an open door for attackers. TruGrid SecureRDP enforces Zero Trust and MFA, blocks lateral movement, and secures remote access—no open firewall ports required. Learn more and...

Information Technology Healthcare and Public Health
Unit 42 ·

An IAB campaign exploited leaked ASP.NET Machine Keys. We dissect the attacker's infrastructure, campaign and offer takeaways for blue teams. The post GoldMelody’s Hidden Chords: Initial Access...

Financial Services Information Technology
Securelist ·

We have explored the RACF security package in z/OS and developed a utility to interact with its database. Now, we are assessing RACF configuration security for penetration testing.

BleepingComputer ·

Almost a dozen malicious extensions with 1.7 million downloads in Google's Chrome Web Store could track users, steal browser activity, and redirect to potentially unsafe web addresses. [...]

Safe
infosecurity-magazine ·

Sonatype’s latest Open Source Malware Index report has identified more than 16,000 malicious open source packages, representing a 188% annual increase

Lazarus Group Scattered Spider Information Technology Critical Manufacturing
infosecurity-magazine ·

The company behind AV/EDR evasion tool Shellter has confirmed the product is being used by threat actors

Scattered Spider Information Technology Emergency Services
Industrial Cyber ·

France’s cybersecurity agency ANSSI uncovered last September a campaign exploiting multiple zero-day flaws in Ivanti Cloud Service Appliance... The post China-linked Houken attacker hit France’s...

Communications Defense Industrial Base
Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto ·

Pakistan’s APT36 Transparent Tribe uses phishing and Linux malware to target Indian defence systems running BOSS Linux says Cyfirma.

Transparent Tribe Defense Industrial Base Financial Services
infosecurity-magazine ·

China’s Hikvision vows legal battle after Canada bans its operations, citing national security concerns

Scattered Spider Government Facilities Information Technology
infosecurity-magazine ·

Trend Micro has observed the Bert ransomware group in operation since April 2025, with confirmed victims in sectors including healthcare, technology and event services

Scattered Spider Information Technology Healthcare and Public Health