DEF CON Attendees Allegedly Jam Plane Wi‑Fi, Launch ‘Evil Twin’ Phishing Attack
A Delta Air Lines flight returning travelers from Las Vegas reportedly became the site of a high-altitude Wi-Fi phishing incident when someone on board alleg...
Articles mapped to MITRE ATT&CK techniques. Select a technique to view matching articles.
169 articles found
A Delta Air Lines flight returning travelers from Las Vegas reportedly became the site of a high-altitude Wi-Fi phishing incident when someone on board alleg...
PentestGPT is an open-source penetration testing agent that points a large language model at a target and lets it work. In its default mode it runs recon, th...
Key Points Introduction Since early 2026, Check Point Research has tracked a wave of the Operation Dream Job campaign. This wave primarily targeted the defen...
AI agents can improvise beyond the intended scope of a task when they are given broad access to enterprise systems and data. Token Security explains why orga...
The March 2026 compromise of LiteLLM was more than a short-lived malicious PyPI upload. It demonstrated how an upstream breach in developer tooling can turn ...
Marcus Hutchins doesn’t personally consider himself a hacker – but he accepts the epithet because it’s a widely used term for what he once did. The post Hack...
Minerals become chips. Chips become data centers.
Ransomware campaigns are becoming more sophisticated, moving away from broad attacks to highly targeted extortion.
AI is making phishing, credential theft, and social engineering faster and more efficient, while traditional trust signals such as passwords, MFA, IP reputat...
AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize f...
This is good: Post-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding from the Sovereign Tech Agency, we implemen...
Key takeaways OAuth client ID spoofing defeats detections that key off application name or a known application ID, because the field itself is fabricated, ro...
GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.
NTIA official Adam Cassady becomes the second person confirmed to be the State Department's ambassador-at-large for cyber policy.
In today’s interconnected digital world, no organization is truly safe from cyber threats. A single unpatched vulnerability can become an open door for a dev...
Vulnerability management isn’t failing because security teams lack visibility. Most organizations already have more findings than they can reasonably address.
Meta has become the latest AI company to confirm that one of its models hacked a real organization during cybersecurity testing, as similar incidents continu...
AI did not create a new browser security problem. It exposed one that enterprises have long been able to ignore.
Most security teams don’t suffer from a lack of data. They suffer from a lack of certainty.
Meta has become the third frontier AI developer in recent weeks to disclose a security incident involving one of its advanced AI models during cyber capabili...