IM
IronMonkey Threat Research
LIVE
|
Articles 28,724
|
CVEs 366,928
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 28,692 articles — Page 1 of 957
The Hacker News ·

The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a privilege escalation flaw impacting...

Information Technology
The Hacker News ·

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers'...

Information Technology Financial Services
www.theregister.com - Articles ·

They had more access than the average Joe, and IT didn't track what needed to be cut off

Information Technology Commercial Facilities security
www.theregister.com - Articles ·

Sandboxes, permissions, and VMs aren't enough to keep frontier models at bay. "Data diodes" might do the job

Information Technology Government Facilities ai and ml
Wiz Blog | RSS feed ·

Fixing security vulnerabilities in code takes seconds, while patching in production creates high operational costs and risk. Discover how empowering developers as your first line of defense...

Information Technology
The Hacker News ·

Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative...

www.theregister.com - Articles ·

Cyber Weapon Index finds AI attacks 'imminent'

Information Technology Government Facilities security
The Hacker News ·

An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. "The campaign has targeted users looking to download...

Silver Fox Critical Manufacturing Information Technology
Threats | CyberScoop ·

Researcher tracking 764 said the first-of-its-kind case has a wider impact that will cause ripples across the landscape of violent extremist crime. The post Jail time for Maine child in 764 marks...

Scattered Spider Cybercrime Cybersecurity
www.theregister.com - Articles ·

Adding insult to injury

Information Technology security
The Hacker News ·

Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's...

Information Technology
The Hacker News ·

A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational...

Earth Berberoka Information Technology
The Hacker News ·

Virtualizor said hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic. The hackers then used the diverted update traffic to deliver a malicious Virtualizor package to...

Information Technology
Schneier on Security ·

I received the two emails below earlier in the month. They’re vaguely coherent. I suppose I shouldn’t be surprised that the corpus that AIs are training on contain data suggesting that I am...

Financial Services Information Technology Uncategorized AI
www.theregister.com - Articles ·

Miscreants use chained zero days to pwn boxen as third-party SOCs say further attacks 'almost certain'

Information Technology Healthcare and Public Health security
The Hacker News ·

Cybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a fake television-streaming campaign on Meta...

Threats | CyberScoop ·

Sality’s peer-to-peer infrastructure allowed it to evade system-wide disruption efforts for an exceptionally long period. Authorities and cybersecurity experts finally brought it down. The post...

Scattered Spider Information Technology Communications Cybercrime Cybersecurity
Cyber Security Advisories - MS-ISAC ·

Multiple Vulnerabilities have been discovered in SonicWall SMA1000 Series Appliances, which when chained together could allow for remote code execution, potentially leading to full system...

Information Technology Government Facilities
BleepingComputer ·

Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. [...]

Information Technology Communications Security
The Hacker News ·

The debate about whether AI delivers business value is over. The challenge now is implementing it at scale and securely across every function while meeting board-level pressure to move fast....

Information Technology
Cyber Security Advisories - MS-ISAC ·

Multiple vulnerabilities have been discovered in PaperCut products, the most severe of which could allow for remote code execution. PaperCut products are software tools used to track, control,...

Government Facilities Information Technology
www.theregister.com - Articles ·

Cloud storage biz severs old integration and urges victims to reset credentials

Information Technology security
The Hacker News ·

SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks. The...

Information Technology
Alerts and advisories ·

Progress Software security advisory (AV26-875)

Information Technology
BleepingComputer ·

An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites. [...]

Information Technology Security
Threats | CyberScoop ·

It’s the first Pegasus infection of 2026 that Citizen Lab is forensically confirming, and the SHARE Foundation said it’s the biggest wave of spyware surveillance in Serbia yet. The post Pegasus,...

Information Technology Communications Privacy Technology
Threats | CyberScoop ·

it’s the latest in a sequence of letters to feds from Sen. Ron Wyden, D-Ore., on commercial VPNs. The post Wyden seeks upgraded NSA security guidance on commercial VPN use appeared first on CyberScoop.

Mabna Institute Information Technology Government Facilities Policy Technology
The Hacker News ·

Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency...

Government Facilities Information Technology
The Hacker News ·

The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malware-laced Excel...

Lazarus Group Information Technology Government Facilities
Alerts and advisories ·

Google security advisory (AV26-874)

Information Technology