New DRAM Scrambling Attack Unlocks AMD CPU PSP, SMM and Microcode
Security researcher Christopher Domas has released a proof-of-concept project called “skitter-creek-bath-salts,” which demonstrates a vulnerability in AMD’s ...
20 articles
Security researcher Christopher Domas has released a proof-of-concept project called “skitter-creek-bath-salts,” which demonstrates a vulnerability in AMD’s ...
Apple has issued a new set of high-confidence Apple Threat Notification alerts, warning selected iPhone users in 110 countries that they may be targets of go...
A newly uncovered espionage operation targeting Afghan telecom providers and South Asian critical infrastructure has exposed a layered attacker ecosystem bui...
A rapidly expanding financial cybercrime model called AI token jacking, where threat actors steal developer API keys for popular AI platforms, consume the vi...
Fortinet has released security updates to address high-severity vulnerabilities in FortiWeb and FortiClient for Windows. These vulnerabilities could allow un...
A newly analyzed malware operation called Aeternum is turning the public Polygon blockchain into a command-and-control (C2) channel, allowing attackers to di...
Hardware wallet manufacturer Trezor has recently disclosed a data breach at ShipMonk, a third-party shipping provider. This breach exposed the personal infor...
Beacon CRM has confirmed that a threat actor likely downloaded a complete copy of its customer database after gaining access to its Amazon Web Services (AWS)...
A newly identified macOS infostealer, named AmnesiaStealer, targets users via ClickFix social-engineering campaigns that impersonate GitHub download pages. T...
A China-linked threat group tracked as Jewelbug has turned public Google Docs into a resilient command-and-control delivery channel, embedding freshly obfusc...
Microsoft has released security updates that address six vulnerabilities in Exchange Server. These vulnerabilities include flaws that could allow remote code...
Dell has disclosed a significant security vulnerability in its Virtual Storage Integrator (VSI) for VMware vSphere Client. This vulnerability could allow una...
The Trump administration has issued a presidential memorandum that establishes a federal program allowing vetted U.S.
The LiteLLM supply-chain compromise has shifted from a short-lived malicious package incident into a sprawling enterprise exposure event. Analysis of an alle...
The U.S.
Wireshark has released version 4.6.
Armored Likho, also tracked as Eagle Werewolf, has expanded its espionage capability with a Rust-based toolkit that can hijack Telegram sessions and transfor...
Cloudflare has mitigated 23.2 million network-layer DDoS attacks and stopped 29.
A newly published internet-exposure analysis has identified more than 6,300 high-confidence industrial control system and building automation devices accessi...
Adobe has released security updates for Adobe Commerce, Adobe Commerce B2B, and Magento Open Source to address multiple critical vulnerabilities. One of the ...