Documentation placeholder domain used in ClickFix attacks
The domain name third-party[.]com is being used to serve malware to users — bad news for those following a little too literally online documentation that use...
20 articles
The domain name third-party[.]com is being used to serve malware to users — bad news for those following a little too literally online documentation that use...
It was meant to make life simpler: a secret email address to which developers can send a message and create an issue in their GitLab project. But poor securi...
Flock Safety has stirred widespread debate of late. Flock builds interconnected networks of automated license-plate readers and other public safety cameras.
WordPress has patched what it described as a critical severity security vulnerability that would allow an unauthenticated attacker full remote code execution...
Microsoft 365 E5 and E7 customers can now run security information and event management (SIEM) inside Microsoft Defender at no extra license cost. Microsoft ...
A flaw in VeloCloud Orchestrator enables attackers to access the platform organizations use to manage their VeloCloud SD-WAN subscriptions and the edge devic...
An air traffic controller watching a busy scope will, sooner or later, miss the one aircraft that matters. Sustained attention decays under load, a limit avi...
In January 2018, the entire computer industry was put on alert by two new processor vulnerabilities dubbed Meltdown and Spectre that defeated the fundamental...
A firewall is supposed to be the barrier between attackers and the enterprise network, but that barrier can itself become a threat actors’ tool. Check Point ...
Technology company F5 fixed a critical remote code execution vulnerability in its BIG-IP Access Policy Manager (APM) platform on Tuesday. The flaw impacts de...
GitHub allows organizations to install GitHub Apps that automate and extend certain functionality on the platform and have access to selected repositories an...
Concerns over agentic risks are rising, and identity and access management (IAM) giant Okta believes it’s making the moves of a would-be leader in this emerg...
Attackers using AI have greatly benefited when it comes to speed and scale, and now, says Cisco Talos, the technology has evolved to execute large portions o...
Microsoft has hailed its success in disrupting EvilTokens, an AI-powered a phishing-as-a-service (PhaaS) platform linked to more than 12,000 compromised Micr...
Chinese artificial intelligence company Z.ai had to disable several features of its ZCode coding assistant this week after a default setting was caught sendi...
Websites offering fake subscriptions to AI transcription tools, image generators, and other digital assistants could be putting enterprise data at risk, acco...
In April, I wrote about what I called the Cyber AI Parity Window. This is the rare period in which defenders and adversaries gained access to the same transf...
Flare-ups between US intelligence agencies and private-sector defenders have long been a characteristic of the cybersecurity landscape, with the balance swin...
A Google Gemini AI agent broke into three companies in July, guessing the credentials for one and discovering the credentials for the second two in a public ...
Two separate reports of security flaws in OpenAI systems highlight how even a company spending billions on developing its own AI-powered cybersecurity testin...