ASOS links data breach to social engineering attack, credential theft
ASOS is sending updates to affected customers about the cybersecurity incident it suffered earlier this week, confirming that hackers accessed some personal ...
Articles mapped to MITRE ATT&CK techniques. Select a technique to view matching articles.
97 articles found
ASOS is sending updates to affected customers about the cybersecurity incident it suffered earlier this week, confirming that hackers accessed some personal ...
FBI warns FortiBleed attackers remain active, turning stolen credentials into persistent access.
Tanium has relaunched Tanium Security Operations to address AI-assisted attacks in which adversaries use legitimate administrative tools to blend into normal...
Ontinue has announced the launch of ION for Dark Web Monitoring (DWM), a new managed add-on service that extends ION MXDR to continuously identify exposed cr...
AWS released security updates for three vulnerabilities in its open-source Loom platform, used for AI agent orchestration. These vulnerabilities could allow ...
A credential-collection toolkit dubbed TIKTOUK that combines WordPress reconnaissance, exposed-file harvesting, plugin credential decryption, and JavaScript ...
The phishing campaigns that weaponize legitimate remote monitoring and management software to establish persistent access and support credential theft on Win...
Microsoft has detailed a cloud-focused intrusion attributed to Storm-3068, in which attackers turned a compromised user account into a launch point for Azure...
Security researchers have disclosed a high-severity vulnerability in Anthropic’s Model Context Protocol (MCP) Python SDK. This flaw could allow a malicious M...
A newly identified Windows botnet dubbed x47.c is marketing a blend of conventional DDoS tooling, credential theft, SOCKS5 proxying, fast-flux command-and-co...
An internet-exposed cybercrime server linked to the BlackHatSect0r and DXQRTXX personas, revealing an operational environment that allegedly combined AI-assi...
Infostealer malware is increasingly becoming the bridge between a compromised developer workstation and an enterprise cloud environment, with Lumma, RedLine,...
“Operation Master,” an end-to-end cybercrime operation that combined GlobalProtect VPN exploitation, web-application attacks, credential theft, data monetiza...
Earlier this month, Anthropic published a long report detailing all of the Claude misuses it detected. Daniel Meissler usefully summarized the report into 11...
The botnet, sold by WraithTools, includes capabilities for credential theft, SOCKS5 proxying, and an AI module for malware persistence, Qrator Research Labs ...
LevelBlue found Microsoft’s password reset portal can reveal valid accounts, recovery methods and likely administrator accounts without user authentication.
The Australian Signals Directorate (ASD) has this month issued a clear call to action through its Multi-factor authentication: Switch it on campaign, urging ...
Qrator found a Windows botnet advertised with AI API draining, credential theft and SOCKS5 proxying
Network Solutions has launched Dark Web Monitoring, a new security capability that alerts small businesses when information associated with their domain appe...
A newly analyzed WordPress malware implant combines must-use plugin persistence, hidden administrator accounts, credential theft, cross-site propagation, and...