IM
IronMonkey Threat Research
LIVE
|
Articles 25,482
|
CVEs 338,519
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 25,451 articles — Page 55 of 849
Securelist ·

The Silver Fox group is targeting companies in Russia and India by impersonating tax authorities to distribute ValleyRAT and the new ABCDoor backdoor.

Silver Fox Government Facilities Financial Services GReAT research APT reports
Vulnerabilities – The Cyber Express ·

A newly disclosed security issue, tracked as CVE-2026-41940, has raised significant concerns across the web hosting ecosystem, particularly for systems running cPanel and WebHost Manager (WHM)....

Information Technology Firewall Daily Cyber News
The Register - Security ·

Patches land for authencesn flaw enabling local privilege escalation

Information Technology software
The Register - Security ·

Patches land for authencesn flaw enabling local privilege escalation Developers of major Linux distributions have begun shipping patches to address a local privilege escalation (LPE) vulnerability...

Information Technology
TrustedSec ·

TL;DR - If you have WriteGPLink on an Active Directory Organizational Unit (OU) and you’re on the same network segment as a computer within that OU, you can abuse that permission to link an...

Information Technology
Recorded Future ·

The United States (US) is shifting toward a more force-driven security strategy primarily relying on military operations and economic pressure to counter transnational criminal organizations and...

Government Facilities Energy Research (Insikt)
Recorded Future ·

What building with AI for three months revealed about four leadership blind spots executives can't afford to ignore: the comprehension gap, eroding competitive moats, deployment complexity, and...

Information Technology Blog
Cloud Threat Landscape ·

In the PyPI package lightning, malicious code is triggered automatically upon import. The code downloads and installs the Bun runtime and executes a large (~11 MB) obfuscated JavaScript payload....

Information Technology
The Register - Security ·

ORNL says portable detector kit can separate real GPS signals from fake ones even at equal strength

Communications Information Technology security
The Hacker News ·

Cybersecurity researchers are sounding the alarm about a new supply chain attack campaign targeting SAP-related npm Packages with credential-stealing malware. According to reports from Aikido...

Information Technology Critical Manufacturing
The Register - Security ·

Second try's a charm?

Information Technology Government Facilities security
Wiz Blog | RSS feed ·

How AI Adoption, Autonomy, and Attacker Innovation Are Reshaping Cloud Security

Information Technology
The Register - Security ·

Microsoft readies the axe once again for yesterday's security

Information Technology Communications security
Alerts and advisories ·

AL26-008 - Vulnerability affecting cPanel and WebHost Manager (WHM) - CVE-2026-41940

Information Technology
The Hacker News ·

Cybersecurity researchers have discovered malicious code in an npm package after a malicious package as a dependency to the project by Anthropic's Claude Opus large language model (LLM). The...

Lazarus Group Information Technology
The Register - Security ·

ORNL says portable detector kit can separate real GPS signals from fake ones even at equal strength GPS spoofing, which sends fake satellite-like signals, and GPS jamming, which drowns receivers...

Communications Information Technology
The Citizen Lab ·

Citizen Lab director Ron Deibert recently spoke on All Things Considered about the Lab’s new investigation of Webloc, a geolocation surveillance system. The post A New Study Shows How Ad-Based...

Information Technology Government Facilities
The Register - Security ·

Second try's a charm? Microsoft and the US Cybersecurity and Infrastructure Security Agency (CISA) warned that attackers are exploiting a zero-click Windows flaw that can expose sensitive...

Information Technology Government Facilities
The Citizen Lab ·

A group of 25 rights and privacy organizations and experts delivered an open letter to Parliament calling for the full withdrawal of Bill C-22. The post Kill Bill C-22: Says Civil Society to...

Government Facilities Information Technology
The Register - Security ·

There is no 6 Nimmt! champion, but a $12 domain registration and one Wikipedia edit convinced several bots there was

Information Technology software
BleepingComputer ·

Multiple official SAP npm packages were compromised in what is believed to be a TeamPCP supply-chain attack to steal credentials and authentication tokens from developers' systems. [...]

Information Technology Critical Manufacturing Security
The Register - Security ·

Microsoft readies the axe once again for yesterday's security Microsoft has warned users still clinging to legacy TLS versions that the end is nigh for TLS 1.0 and 1.1 on POP3 and IMAP4...

Information Technology Communications
BleepingComputer ·

The Quick Page/Post Redirect plugin, installed on more than 70,000 WordPress sites, had a backdoor added five years ago that allows injecting arbitrary code into users' sites. [...]

Information Technology Security
The Register - Security ·

GrassMarlin leaks sensitive information, provided your targeting phishing skills are sharp enough

Critical Manufacturing Energy security
Alerts and advisories ·

SonicWall security advisory (AV26-405)

Information Technology Critical Manufacturing
The Hacker News ·

In February 2026, researchers uncovered a shift that completely changed the game: threat actors are now using custom AI setups to automate attacks directly into the kill chain. We aren't just...

Alerts and advisories ·

cPanel security advisory (AV26-404)

Information Technology
The Hacker News ·

Every security team has a version of the same story. The quarter ends with hundreds of vulnerabilities closed. The dashboards are bursting with green. Then someone in a leadership meeting asks:...

Information Technology
BleepingComputer ·

Hackers are exploiting two authentication bypass vulnerabilities in the Qinglong open-source task scheduling tool to deploy cryptominers on developers' servers. [...]

Information Technology Security
The Register - Security ·

GrassMarlin leaks sensitive information, provided your targeting phishing skills are sharp enough The Cybersecurity and Infrastructure Security Agency (CISA) is warning anyone who uses...

Critical Manufacturing Energy