The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
More details have emerged about a set of now-patched cross-site scripting (XSS) flaws in theMicrosoft Azure HDInsightopen-source analytics service that could b…
Cybersecurity researchers have called attention to a new antivirus evasion technique that involves embedding a malicious Microsoft Word file into a PDF file.Th…
New findings show that malicious actors could leverage a sneaky malware detection evasion technique and bypass endpoint security solutions by manipulating the …
A nation-state activity group originating from China has been linked to cyber attacks on dozens of organizations in Taiwan as part of a suspected espionage cam…
Microsoft on Thursday disclosed that it found a new version of theBlackCatransomware (aka ALPHV and Noberus) that embeds tools like Impacket and RemCom to faci…
Microsoft researchers discovered numerous vulnerabilities affecting Codesys PLC that risked power plants’ security with various…Multiple Codesys PLC Vulnerabil…
Users in Latin America (LATAM) are the target of a financial malware calledJanelaRATthat's capable of capturing sensitive information from compromised Microsof…
A new information malware strain calledStatc Stealerhas been found infecting devices running Microsoft Windows to siphon sensitive personal and payment informa…
A new variant ofAsyncRATmalware dubbedHotRatis being distributed via free, pirated versions of popular software and utilities such as video games, image and so…
An unnamed Federal Civilian Executive Branch (FCEB) agency in the U.S. detected anomalous email activity in mid-June 2023, leading to Microsoft's discovery of …
A developing piece of ransomware calledBig Headis being distributed as part of a malvertising campaign that takes the form of bogus Microsoft Windows updates a…
Ransomware attacks are a major problem for organizations everywhere, and the severity of this problem continues to intensify.Recently, Microsoft's Incident Res…
At least half of dozen GitHub accounts from fake researchers associated with a fraudulent cybersecurity company have been observed pushing malicious repositori…
Recently, Microsoft’s Defender Experts uncovered a sophisticated multi-stage adversary-in-the-middle (AiTM) phishing and business email compromise…Unmasking th…
Details have emerged about a now-patched actively exploited security flaw in Microsoft Windows that could be abused by a threat actor to gain elevated privileg…
Details have emerged about a now-patched actively exploited security flaw in Microsoft Windows that could be abused by a threat actor to gain elevated privileg…
An unnamed government entity associated with the United Arab Emirates (U.A.E.) was targeted by a likely Iranian threat actor to breach the victim's Microsoft E…
The Iranian threat actor known asAgriusis leveraging a new ransomware strain called Moneybird in its attacks targeting Israeli organizations.Agrius, also known…
The notorious cybercrime group known as FIN7 has been observed deployingCl0p(aka Clop) ransomware, marking the threat actor's first ransomware campaign since l…
The notorious cybercrime group known as FIN7 has been observed deployingCl0p(aka Clop) ransomware, marking the threat actor's first ransomware campaign since l…
Poorly managed Microsoft SQL (MS SQL) servers are the target of a new campaign that's designed to propagate a category of malware calledCLR SqlShellthat ultima…
Cybersecurity researchers have shared details about a now-patched security flaw in Windows MSHTML platform that could be abused to bypass integrity protections…
Update to 1.21.1 (resolve rhbz#2182365)
The North Korean threat actor known asScarCruftstarted experimenting with oversized LNK files as a delivery route for RokRAT malware as early as July 2022, the…