The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
The notorious Emotet malware, in itsreturn after a short hiatus, is now being distributed viaMicrosoft OneNote email attachmentsin an attempt to bypass macro-b…
U.S. government agencies have released a joint cybersecurity advisory detailing the indicators of compromise (IoCs) and tactics, techniques, and procedures (TT…
Google is calling attention to a set of severe security flaws in Samsung's Exynos chips, some of which could be exploited remotely to completely compromise a p…
Multiple threat actors, including a nation-state group, exploited a critical three-year-old security flaw in Progress Telerik to break into an unnamed federal …
A new Golang-based malware dubbedGoBruteforcerhas been found targeting web servers running phpMyAdmin, MySQL, FTP, and Postgres to corral the devices into a bo…
Today, the LockBit ransomware is the most active and successful cybercrime organization in the world. Attributed to a Russian Threat Actor, LockBit has stepped…
Government entities and large organizations have been targeted by an unknown threat actor by exploiting a security flaw in Fortinet FortiOS software to result …
A widespread malicious cyber operation has hijacked thousands of websites aimed at East Asian audiences to redirect visitors to adult-themed content since earl…
Previously known to target Windows systems only, a new Linux version of the IceFire ransomware that exploits an IBM Aspera Faspex file-sharing vulnerability ( …
A novel Linux version of the IceFire ransomware that exploits a vulnerability in IBM's Aspera Faspex file-sharing software has been identified by SentinelLabs,…
IceFire has changed up its OS target in recent cyberattacks, emblematic of ransomware actors increasingly targeting Linux enterprise networks, despite the extr…
Security vulnerabilities in remote desktop programs such as Sunlogin and AweSun are being exploited by threat actors to deploy the PlugX malware.AhnLab Securit…
A previously known Windows-based ransomware strain known as IceFire has expanded its focus to target Linux enterprise networks belonging to several media and e…
Threat actors linked to the IceFire ransomware operation now actively target Linux systems worldwide with a new dedicated encryptor. SentinelLabs security rese…
The North Korea-linkedLazarus Grouphas been observed weaponizing flaws in an undisclosed software to breach a financial business entity in South Korea twice wi…
The massive breach at LastPass was the result of one of its engineers failing to update Plex on their home computer, in what's a sobering reminder of the dange…
Written by Linux security expert and LinuxSecurity.com Founder Dave Wreski.Attacks targeting Linux have surged in recent years due to the mass migration of wor…
Law enforcement authorities from Germany and Ukraine have targeted suspected core members of a cybercrime group that has been behind large-scale attacks using …
Malicious actors can take advantage of "insufficient" forensic visibility into Google Cloud Platform (GCP) to exfiltrate sensitive data, a new research has fou…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) hasreleaseda new advisory aboutRoyal ransomware, which emerged in the threat landscape last ye…
Six different law firms were targeted in January and February 2023 as part of two disparate threat campaigns distributingGootLoaderandFakeUpdates(aka SocGholis…
A new post-exploitation framework called EXFILTRATOR-22 (aka EX-22) has emerged in the wild with the goal of deploying ransomware within enterprise networks wh…
Romanian cybersecurity company Bitdefender hasreleaseda free universal decryptor for a nascent file-encrypting malware known as MortalKombat.MortalKombat is a …
LastPass, which in December 2022 disclosed a severe data breach that allowed threat actors to access encrypted password vaults, said it happened as a result of…