Attackers are using Microsoft’s legitimate login system to camouflage phishing attacks
Attackers are moving away from fake Microsoft login pages in favor of abusing Microsoft’s own authentication system, letting phishing campaigns slip past the...
20 articles
Attackers are moving away from fake Microsoft login pages in favor of abusing Microsoft’s own authentication system, letting phishing campaigns slip past the...
Hackers were detected on Analog Devices systems in June, and an investigation found that they stole files. The post Semiconductor Firm Analog Devices Disclos...
This essay originally appeared in The Guardian. I teach public policy at the Harvard Kennedy School and the Munk School at the University of Toronto.
Hugging Face and OpenAI revealed further details on the agent’s 4.5-day attack campaign.
A covert Monero (XMR) cryptomining campaign uncovered in May 2026 is abusing Linux Pluggable Authentication Modules (PAM) to evade detection, maintain filele...
A static credentials vulnerability (CVE-2026-20316) in Cisco Secure Firewall Management Center (FMC), a platform for centrally managing multiple Cisco Secure...
Dropzone AI has announced the general availability of AI Threat Hunter, its proactive threat hunting agent. The tool enables security teams to run structured...
PortSwigger has announced the public beta of Burp AT, a new addition to Burp Suite that brings agentic AI to professional penetration testing. Burp AT enable...
South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used tho...
The Chinese cybercrime group known as Silver Fox has been observed using new drivers as part of bring your own vulnerable driver (BYOVD) attacks targeting a ...
GenieLocker is a custom ransomware family linked to the Toy Ghouls group (also known as Bearlyfy or Labubu). It can encrypt systems running Windows, Linux, a...
The FCC added foreign robots and power inverters to its Covered List, while allowing security updates for existing authorized devices until 2029. The FCC jus...
You don’t know your DDoS defenses work until you attack them yourself — safely, on purpose, with a kill switch. Simulated DDoS attack tools generate controll...
Hackers are increasingly exploiting vulnerabilities at an unprecedented speed, with nearly one in four flaws being abused before or on the same day they are ...
Unauthenticated attackers could send HTTP requests to an exposed endpoint to execute commands inside the MCP bridge container. The post Critical Ruflo Flaw L...
Home Assistant’s FFmpeg integration recently came under scrutiny after researchers demonstrated that unsafe argument handling in the Wyoming Assist satellite...
Claroty has analyzed 750,000 cyber-physical systems across some of the world’s largest data center facilities. The post 1 in 5 Data Center Assets Are Within ...
For years, North Korea's state-trained hackers have been one of the world's most prolific robbers of banks - stealing huge sums of money from foreign financi...
The new version of Chrome, 151, comes with 370 vulnerability patches, including for seven critical flaws
U.S.