Zero Day Initiative
CVE
Apr 6
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Labcenter Electronics Proteus. User interaction is required...
Zero Day Initiative →
Zero Day Initiative
CVE
Apr 6
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Labcenter Electronics Proteus. User interaction is required...
Zero Day Initiative →
Read our blog post to learn how SentinelOne’s AI EDR autonomously stopped a global LiteLLM supply chain attack before execution.
SentinelOne Blog →
Elastic Security Labs
Supply Chain
Apple
Apr 2
Joe Desimone shares the story of how he caught the Axios supply chain attack with a proof of concept tool built in an afternoon.
Elastic Security Labs →
Trail of Bits
Vulnerability Disclosure
Apr 1
Code coverage is one of the most dangerous quality metrics in software testing. Many developers fail to realize that code coverage lies by omission: it measu...
Trail of Bits →
Recorded Future
General
Apr 1
The expanding conflict around Iran signals a deeper shift.
Recorded Future →
Elastic Security Labs
Supply Chain
Apple
Apr 1
Elastic Security Labs analyzes a supply chain compromise of the axios npm package delivering a unified cross-platform RAT
Elastic Security Labs →
Elastic Security Labs
Supply Chain
Apple
Apr 1
Hunting and detection rules for the Elastic-discovered Axios supply chain compromise.
Elastic Security Labs →
Read our blog post to learn how SentinelOne’s AI EDR autonomously stopped a global LiteLLM supply chain attack before execution.
SentinelOne Blog →
Infosecurity Magazine
Ransomware
Mar 31
TeamPCP is exploring ways to monetize the secrets harvested during supply chain attacks, with identified ties to the Lapsus$ and Vect ransomware gangs
Infosecurity Magazine →
Infosecurity Magazine
Vulnerability Disclosure
Mar 30
Tax-season phishing floods deliver RMM malware, credential theft, BEC and tax-form scams
Infosecurity Magazine →
Infosecurity Magazine
Campaigns
Mar 27
Socket and Endor Labs discovered a new TeamPCP campaign leading to the delivery of credential-stealing malware
Infosecurity Magazine →
Infosecurity Magazine
Vulnerability Disclosure
Mar 26
PwC Annual Threat Dynamics report says AI-threats are the biggest concern of clients
Infosecurity Magazine →
Infosecurity Magazine
Vulnerability Disclosure
SentinelOne
Mar 25
Cybersecurity company’s annual report issues warning over a “mass-marketed impersonation crisis” over attackers abusing legitimate credentials
Infosecurity Magazine →
Infosecurity Magazine
Campaigns
Mar 25
Python package LiteLLM compromised with credential-stealing malware linked to TeamPCP threat group
Infosecurity Magazine →
Infosecurity Magazine
General
Mar 24
Geopolitics and cyber warfare take center stage at Infosecurity Europe as Dmytro Kuleba discusses Ukraine’s hybrid war experience
Infosecurity Magazine →
Infosecurity Magazine
Malware
Docker
Mar 23
New Trivy Docker images 0.69.
Infosecurity Magazine →
Infosecurity Magazine
Ransomware
Fortinet
Mar 19
Hastalamuerte leaks The Gentlemen RaaS ops: FortiGate exploits, BYOVD evasion, Qilin split tactics
Infosecurity Magazine →
Zero Day Initiative
CVE
Mar 16
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics ASDA-Soft. User interaction is required t...
Zero Day Initiative →
Infosecurity Magazine
Data Breach
Mar 10
Ericsson data breach affects 15k employees/customers after third-party service provider compromise
Infosecurity Magazine →