Friday Squid Blogging: I Caught a Squid
On Wednesday I spent a day fishing, on a small boat out of Gloucester, MA. We caught many cod (none of which we could keep), and a bunch of hake and mackerel...
On Wednesday I spent a day fishing, on a small boat out of Gloucester, MA. We caught many cod (none of which we could keep), and a bunch of hake and mackerel...
Japan helped extradite a Russian suspect linked to Qilin ransomware to Germany, but the gang continued attacking victims after his arrest. Germany has arrest...
Japan’s National Police Agency confirmed the arrest and extradition to Germany of a Russian national accused of being involved in the Qilin ransomware gang.
Threat actors are exploiting one critical and one medium-severity vulnerability still unpatched in the AhsayCBS backup management platform to deploy webshell...
Based on information from Bleeping Computer, a Maryland man has been convicted of stealing more than $53 million from the decentralized cryptocurrency exchan...
Cybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword. "Compared with the vari...
Britain and Germany have announced a new partnership to counter cyberattacks and sabotage, particularly from Russia.
Germany has arrested a Russian national suspected of being a leading member of the Qilin ransomware group following extradition from Japan earlier this month...
For the third week running, Citrix has issued a critical security warning to customers managing their own NetScaler ADC and Netscaler Gateway instances, this...
On-demand CPU and memory profiling for Cloudflare Workers and Durable Objects is now available. Now you can generate interactive flamegraphs directly in prod...
CastleStealer, a C# information stealer first publicly identified in April 2026, has expanded its capabilities beyond credential theft. New samples analyzed ...
A Ukrainian-Russian dual citizen has pleaded guilty to running a massive money laundering operation that laundered millions for cybercriminals worldwide. [.
The flaws, CVE-2026-105133 and CVE-2026-105134, allow attackers to bypass authentication and inject OS commands. The post Unpatched AhsayCBS Vulnerabilities ...
A bug in GoBalance, a tool many dark-web sites use to stay reachable during attacks, lets anyone work out the secret key that controls a site's .onion addres...
As AI adoption accelerates, ISACA is expanding its certification portfolio with a governance-focused credential designed to help professionals manage AI secu...
Hackers targeted Hikvision surveillance devices in Ukraine during a concentrated surge of remote command execution attempts that coincided with Russian missi...
MATCHBOIL’s evolution from a basic C# downloader into a more evasive implant supporting recurring command-and-control communication. Operated by UAC-0099, th...
Microsoft Teams will support third-party detection of synthetic audio and video, allowing organizations to identify potentially AI-generated or manipulated m...
A critical authentication bypass vulnerability in Sungrow’s iSolarCloud management platform allowed researchers to access user and administrator accounts wit...