The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
''Log4j has been around for 20 years; it's become embedded into nearly every meaningful Java application; and the Log4Shell event led to compromises in everyth…
Unidentified threat actors have deployed a new backdoor that borrows its features from the U.S. Central Intelligence Agency (CIA)'sHivemulti-platformmalware su…
South Korean cybersecurity firm AhnLab Security Emergency Response Center said it has observed a new Linux malware in the wild that deploys a cryptocurrency mi…
DevOps platform CircleCI on Friday disclosed that unidentified threat actors compromised an employee's laptop and leveraged malware to steal their two-factor a…
As the new year begins, it's more important than ever to protect your business from the constantly evolving cyber threats that could compromise your valuable a…
A recent IcedID malware attack enabled the threat actor to compromise the Active Directory domain of an unnamed target less than 24 hours after gaining initial…
A recently publishedSecurity Navigatorreport data shows that businesses are still taking 215 days to patch a reported vulnerability. Even for critical vulnerab…
Twitter on Wednesday said that its investigation found "no evidence" that users' data sold online was obtained by exploiting any security vulnerabilities in it…
A recent wave of Gootkit malware loader attacks has targeted the Australian healthcare sector by leveraging legitimate tools like VLC Media Player.Gootkit, als…
The Kinsing malware is now actively breaching Kubernetes clusters by leveraging known weaknesses in container images and misconfigured, exposed PostgreSQL cont…
A new malware campaign has been observed targeting Italy with phishing emails designed to deploy an information stealer on compromised Windows systems."The inf…
Ransomware attacks have become increasingly common and can have devastating consequences for businesses, and it…Strategies for Managing Security Posture and Pr…
A group of academics has demonstrated novel attacks that leverage Text-to-SQL models to produce malicious code that could enable adversaries to glean sensitive…
Earlier this year, threat actors infiltratedMailchimp, the popular SaaS email marketing platform. They viewed over 300 Mailchimp customer accounts and exported…
Microsoft has shed light on four different ransomware families –KeRanger, FileCoder, MacRansom, and EvilQuest – that are known to impact Apple macOS systems."W…
Cloud services provider Rackspace on Thursday confirmed that the ransomware gang known as Play was responsible for last month's breach.The security incident, w…
The latest breach announced by LastPass is a major cause for concern to security stakeholders. As often occurs, we are at a security limbo – on the one hand, a…
Ransomware: contemporary threats, how to prevent them and how the FBI can helpIn April 2021, Dutch supermarkets faced a food shortage. The cause wasn't a droug…
A new Linux malware developed using the shell script compiler (shc) has been observed deploying a cryptocurrency miner on compromised systems."It is presumed t…
A new malware campaign has been observed using sensitive information stolen from a bank as a lure in phishing emails to drop a remote access trojan calledBitRA…
Financial and insurance sectors in Europe have been targeted by the Raspberry Robin worm, as the malware continues to evolve its post-exploitation capabilities…
The maintainers of the PyTorch package have warned users who have installed the nightly builds of the library between December 25, 2022, and December 30, 2022,…
API-oriented cyberattacks have wreaked havoc on the corporate world, making every organization concerned about API…Why Traditional AppSec Tools are Ineffective…
WordPress sites are being targeted by a previously unknown strain of Linux malware that exploits flaws in over two dozen plugins and themes to compromise vulne…