Trump Authorizes Private Sector Participation in Offensive Cyber Operations
The White House has authorized government-directed offensive cyber operations against transnational groups, prompting warnings over escalation and attributio...
20 articles
The White House has authorized government-directed offensive cyber operations against transnational groups, prompting warnings over escalation and attributio...
Huntress documents how a ransomware affiliate sabotaged its own attack with an anti-EDR effort
The ICO has issued a formal reprimand to ACRO after patching and security monitoring failures led to a breach
New WindRelay NFC malware paired with SpyNote RAT let a fraudster clone a card mid-call
Lazarus malware used post-quantum key exchange to protect delivery of a Windows zero-day exploit
Gunra actors are using stealth to exfiltrate vast volumes of data from Microsoft services, US and Korean agencies have warned
The US National Institute for Standards and Technology wants to modernize its National Vulnerability Database to embrace AI-powered vulnerability research
The Polish CERT has released details of another 2025 attack on a combined heat and power plant in the country
Microsoft has issued another massive batch of security updates with 400 fixed in the August Patch Tuesday
Six npm packages queried an Ethereum wallet to locate C2 infrastructure
Cursor fixed a pre-trust code execution path in three days then closed the report as informative
Police and fire response has been impacted by the attack on Suisan City, while two other local authorities have been hit by cyber incidents in the past week ...
Daybreak Blue removes some OpenAI-made guardrails while Daybreak Red grants the use of cyber-focused frontier AI models
Supply chain attack and data breach at Ceva Logistics appears to have a large blast radius
OpenAI is tightening restrictions on testing of its upcoming Astra model due to security concerns
Make UK reveals major cyber resilience gaps as 30% of UK manufacturers report recent cyber incidents
Atlassian fixed a flaw letting one crafted link make its Rovo AI assistant exfiltrate company data
Poisoned JSON feed let attackers backdoor WordPress sites without changing any plugin files
Tenet reported that half of Fortune 500 companies are vulnerable to the Ghostjacking technique, which involves tricking AI agents with fake reports
A macOS malware variant has been detected stealing crypto, passwords and more