Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware
Attackers are buying expired domains to exploit their reputation, traffic and DNS history, using them for malware delivery, scams and C2 infrastructure. Ever...
20 articles
Attackers are buying expired domains to exploit their reputation, traffic and DNS history, using them for malware delivery, scams and C2 infrastructure. Ever...
Attackers are actively exploiting a maximum severity SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231, just days after SAP released a patch. A cri...
A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay no...
A maximum-severity security vulnerability impacting SAP Commerce Cloud is witnessing active exploitation efforts. The vulnerability, tracked as CVE-2026-5823...
Hackers are exploiting a macOS Screen Sharing flaw to gain root access and install Monero miners on Macs with port 5900 exposed online. The Dutch National Cy...
Microsoft will make passkeys the default authentication experience in Entra ID beginning September 1, 2026, and will fully retire its native SMS and voice mu...
A newly disclosed universal deserialization gadget chain shows how a single unsafe Marshal.load operation can reportedly produce remote command execution in ...
A newly disclosed Windows attack technique, dubbed “Download More RAM,” can undermine Virtualization-Based Security (VBS), bypass Hypervisor-Protected Code I...
A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner, the Netherlands National Cyb...
Microsoft is reshaping its consumer and productivity AI strategy with a major update to its Copilot application, merging personal chat histories and generate...
GeoServer faces an unpatched zero-day enabling SQL injection and potentially RCE, with attackers already probing exposed systems. A newly disclosed GeoServer...
A fake GitHub download page hosts the malicious ClickFix command.
It could soon become easier to identify AI-generated content, even if it's not the usual "It's Not X, it's Y" type of post you'd come across on LinkedIn and ...
How proactive prioritization will save time and effort when your team faces a wave of AI-discovered vulnerabilities.
While the breach was initially believed to affect only recent orders, new information suggests older orders may also be compromised.
Starting with the 2028 Wiretap Report, which will be published in 2029, the judiciary will include data on network investigating techniques.
The initiative mandates the creation of an AI cybersecurity officer role within every state agency and establishes an AI cyber defense program housed in the ...
These "dropcatch" domains are attractive to threat actors because they retain trust, backlinks, and web traffic from their previous legitimate use, making th...
The vulnerability, identified as CVE-2026-65400, has a severity rating of 7.1 out of 10 and stems from a flaw in macOS' screen sharing capability.
ExfilSquad, which emerged on July 26, initially claimed to have exfiltrated data from 15 organizations.