Elsevier platform briefly redirected to LAPSUS$ leak site
The attack involved visitors to select Elsevier platforms being temporarily redirected to a third-party page, which was later identified as belonging to the ...
The attack involved visitors to select Elsevier platforms being temporarily redirected to a third-party page, which was later identified as belonging to the ...
The TrustSink attack exploits the trust Microsoft Entra places in configured external MFA providers. An attacker with a compromised privileged Entra account ...
IoT and OT devices can create hidden security gaps. Learn how asset visibility helps organizations find forgotten devices and reduce network security risks now.
At least four internet providers serving Kyiv and other parts of Ukraine suffered partial connectivity losses following Wednesday’s drone attack, according t...
Analysis of a SectopRAT variant hidden in tampered legitimate software that steals credentials and enables remote system control
A threat actor is using three AI harnesses for vulnerability research, exploitation, and attack orchestration. The post AI-Powered Campaign Targets Hundreds ...
Cloud Range has announced the official launch of its AI Validation Range and Cloud Range AI Readiness Framework. They give organizations a structured way to ...
The logistics sector has become the target of a new malicious cyber campaign that distributes an Android spyware codenamed Corp MDM. According to Have I Been...
A Go binary called sckit was added to four malicious releases, targeting developer secrets.
AI coding agents are changing how quickly developers can build and ship software as well as how quickly credentials can become exposed. According to GitGuard...
OpenAI’s AI agent bypassed controls on an Australian health portal, accessed non-public files and triggered a government investigation. An OpenAI AI agent by...
Australian PM Anthony Albanese criticized OpenAI’s response to the incident, which occurred in June 2026
Varonis Threat Labs discovered AvisLoader, a Windows malware loader that uses the Tox peer-to-peer network for C2 and arrives through a malicious ClickFix lure.
Crypto ATM scams often follow a predictable script – here’s how to recognize it and what to do if you’ve already been caught out
Karen Vardanyan has also been ordered to pay over $1.2 million in restitution to victims.
A newly uncovered Android banking trojan dubbed RemControl is targeting customers of more than 30 financial institutions across Europe, the Middle East, and ...
Cisco Talos finds CLOSEDQUORUM, malware that lets four commercial AI models vote on its next move, with no human operator required. Cisco Talos found malware...
Disruptive attacks on public-facing services, financially motivated cybercrime and compromises of shared technology providers are increasing cybersecurity ri...
Gambit Security found AI agents breached 27 companies, stole 600,000 credit card records and installed payment skimmers across compromised retail sites.
The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name,...