IM
IronMonkey Threat Research
LIVE
|
Articles 25,516
|
CVEs 338,561
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 25,486 articles — Page 71 of 850
Industrial Cyber ·

Researchers from Darktrace detailed a malware strain dubbed ZionSiphon, highlighting a piece of OT (operational technology)-focused malware designed... The post Darktrace identifies ZionSiphon...

Water Energy Attacks and Vulnerabilities Control device security
Industrial Cyber ·

The U.S. CISA (Cybersecurity and Infrastructure Security Agency) issued an alert warning of a supply chain compromise affecting... The post CISA warns organizations of supply chain compromise in...

Information Technology Critical Manufacturing Attacks and Vulnerabilities CISA
BleepingComputer ·

Fraud prevention and user experience don't have to be a tradeoff. IPQS shows how combining identity, device, and network signals stops fraud without adding friction. [...]

Financial Services Security
Cisco Talos Blog ·

Cisco Talos documents several macOS living-off-the-land (LOTL) techniques, demonstrating that native pathways for movement and execution remain accessible to those who understand the underlying...

Information Technology
SECURITY.COM ·

And why automation may be the only way to keep up

Information Technology
Security Latest ·

There’s a lot of love all over the world for GrapheneOS, the gold standard of mobile security. There’s very little love between the two guys at the center of its history.

Information Technology Communications The Big Story Security
BleepingComputer ·

Ofcom, the United Kingdom's independent communications regulator, has launched an investigation into Telegram based on evidence suggesting it's being used to share child sexual abuse material (CSAM). [...]

Information Technology Communications Security
WeLiveSecurity ·

ESET researchers discover another iteration of NGate malware, this time possibly developed with the assistance of AI

Financial Services Information Technology ESET research
BleepingComputer ·

​CISA has given U.S. government agencies four days to secure their systems against another Catalyst SD-WAN Manager vulnerability it flagged as actively exploited in attacks. [...]

Information Technology Communications Security
The Register - Security ·

Fake emails already doing the rounds as ransomware crew boasts about what it allegedly stole UK enterprise software consultancy The Adaptavist Group is investigating a security breach after an...

Healthcare and Public Health Information Technology
The Register - Security ·

Admins are tired of taking photos, so this enables secure on-site unattended enrolment Japanese industrial giant Panasonic has created a new form of QR code it says will only work on designated...

Information Technology Critical Manufacturing
BleepingComputer ·

Nonprofit security organization Shadowserver found that over 6,400 Apache ActiveMQ servers exposed online are vulnerable to ongoing attacks exploiting a high-severity code injection vulnerability. [...]

Information Technology Security
The Register - Security ·

And China is loving it Iranian media is claiming that the US used backdoors and/or botnets to disable networking equipment during the current war, and Chinese state media is dining out on the allegations.…

Volt Typhoon Critical Manufacturing
BleepingComputer ·

41-year-old Angelo Martino, a former employee of cybersecurity incident response company DigitalMint, has pleaded guilty to targeting U.S. companies in BlackCat (ALPHV) ransomware attacks in 2023. [...]

Information Technology Security
BleepingComputer ·

A new variant of the NGate malware that steals NFC payment data is targeting Android users by hiding in a trojanized version of HandyPay, a legitimate mobile payments processing tool. [...]

Financial Services Information Technology Security Mobile
Recorded Future ·

Agentic AI adoption is accelerating rapidly as enterprise software and applications increasingly incorporate task-specific AI agents, enabling autonomous execution of complex tasks at machine speed.

Information Technology Research (Insikt)
The Register - Security ·

A lesson in how not to respond to vulnerability reports Vibe-coding platform Lovable is pooh-poohing a researcher’s finding that anyone could open a free account on the service and read other...

Information Technology
The Hacker News ·

A critical security vulnerability has been disclosed in SGLang that, if successfully exploited, could result in remote code execution on susceptible systems. The vulnerability, tracked as...

Information Technology
Threats | CyberScoop ·

Google’s highest security setting for its agents runs command operations through a sandbox and throttles network access, but is still vulnerable to prompt injection. The post Vuln in Google’s...

Information Technology AI Cybersecurity
Threats | CyberScoop ·

The attack, which originated at Context.ai, showcases the pitfalls of interconnected cloud applications and SaaS integrations with overly privileged permissions. The post Vercel’s security breach...

Information Technology Cybercrime Cybersecurity
The Register - Security ·

Installation and pre-approval without consent looks dubious under EU law One app should not modify another app without asking for and receiving your explicit consent. Yet Anthropic's Claude...

Information Technology
The Hacker News ·

Monday’s recap shows the same pattern in different places. A third-party tool becomes a way in, then leads to internal access. A trusted download path is briefly swapped to deliver malware....

MuddyWater ShinyHunters Fancy Bear Information Technology Financial Services
Cybersecurity Blog | SentinelOne ·

Machine-speed threats demand machine-speed defense—see how AI and automation cut dwell time and outpace attackers.

Information Technology Company agentic ai
BleepingComputer ·

State-sponsored North Korean hackers are likely behind the $290 million crypto-heist that impacted the KelpDAO DeFi project on Saturday. [...]

Lazarus Group Financial Services Information Technology Security
Alerts and advisories ·

Progress security advisory (AV26-371)

Information Technology Communications
Wiz Blog | RSS feed ·

Compromised Context.ai OAuth tokens enabled attackers to perform a supply chain attack via trusted SaaS integrations. Learn how to assess the risk in your environment and how to prevent the next attack.

Midnight Blizzard Information Technology
BleepingComputer ·

A set of 26 malicious apps on Apple App Store impersonate popular wallets, such as Metamask, Coinbase, Trust Wallet, and OneKey, to steal recovery or seed phrases and drain them of cryptocurrency...

Financial Services Information Technology Security Apple
The Register - Security ·

Tyler Buchanan admits role in scheme that stole at least $8 million in virtual currency A Scottish man linked to the Scattered Spider cybercrime crew has pleaded guilty in the US to a phishing and...

Scattered Spider Financial Services Information Technology
The Hacker News ·

The fastest way to fall in love with an AI tool is to watch the demo. Everything moves quickly. Prompts land cleanly. The system produces impressive outputs in seconds. It feels like the beginning...

Information Technology
The Hacker News ·

Cybersecurity researchers have discovered a critical "by design" weakness in the Model Context Protocol's (MCP) architecture that could pave the way for remote code execution and have a cascading...

Information Technology