SC Media
20 articles
Just 13% of network segments are OT-only, says Forescout Research
Poor network segmentation leaves OT and IoT devices exposed to lateral movement.
We can take down the hackers – but it’s up to us to make OT environments safe
The recent DOJ/FBI takedown of QScan and QTRouter buys the industry time – use it well.
Microsoft and Google dismantle major cybercrime marketplace RedVDS
RedVDS operated as an online hub selling access to virtual machines (VMs) that were used by cybercriminals to launch a variety of attacks, including phishing...
How Cloud Privilege Escalation Paths Form
LDAP, Active Directory, and Entra ID: Directory Services for Security Teams
North Korean hackers target IT firm with macOS backdoors
The Jade Sleet actor, also known by aliases such as TraderTraitor, employed social engineering tactics, using job interview lures to target individuals in De...
Biometric Authentication: Methods, Risks, and Behavioral Signals
Secrets, Certificates, and Tokens: Choosing the Right Credential for Machine Identity
Authentication Fundamentals: Factors, Methods, and Trust Models
Simulation highlights OWASP LLM Top 10 risk of unbounded consumption
Forcepoint research showed how poisoned input can run up AI agent costs.
Understanding Prompt Injection In Order to Contain It - Julie Brunias - ASW #401
AI intelligence report falsely identifies weapons on Chinese ship, nearly triggers US military operation
An analyst at Special Operations Command Pacific used a chatbot to analyze intelligence regarding a Chinese ship, combining open-source and classified signal...
Google had undercover analyst inside TeamPCP hacking group
TeamPCP, known for its widespread malware distribution through open-source software and developer account hijacking, compromised hundreds of programs and bre...
CISA adds Linux kernel flaws to exploited vulnerabilities catalog
CISA has ordered federal agencies to remediate these issues by September 21, 2026, as per Binding Operational Directive 22-01.
Trump calls for AI Force, says AI Czar will be named soon
Trump's planned AI Force renews debate over guardrails and accountability for AI.
Google Gemini AI accesses 3 real companies during cybersecurity tests
In one instance, the AI repeatedly guessed passwords to gain access to a protected system.
ShinyHunters defaces Clop ransomware data leak site, claims data theft
ShinyHunters claims to have exploited an unauthenticated file upload vulnerability in Grav CMS to deface the Clop Tor site with ASCII art of its Umbreon logo.
Army and Air Force Exchange Service investigating suspicious customer messages
The suspicious messages, which included a "wishlist" link and potentially other circulating communications, were also distributed through AAFES's official app.
Texas man pleads guilty in Scattered Spider extortion scheme
Based on information from CyberScoop, a 24-year-old Texas man, Ahmed Hossam Eldin Elbadawy, has pleaded guilty to federal charges related to his involvement ...