Toy Ghouls’ new toy: the GenieLocker ransomware
Kaspersky experts dissect GenieLocker: new custom ransomware variants for Windows, Linux, and ESXi systems. We found this family in attacks by Toy Ghouls, a ...
20 articles
Kaspersky experts dissect GenieLocker: new custom ransomware variants for Windows, Linux, and ESXi systems. We found this family in attacks by Toy Ghouls, a ...
The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, t...
Google has released stable Chrome version 151 updates for Windows, macOS, and Linux, addressing 370 security vulnerabilities. This update includes fixes for ...
TA488 has resurfaced with a high‑end half‑click campaign against on‑premises Outlook Web Access (OWA), exploiting CVE‑2026‑42897 to deploy a persistent JavaS...
Security researcher Håkon Måløy has disclosed a cross-domain prompt injection vulnerability affecting Microsoft Copilot for Word. This vulnerability could al...
Dashlane is a password manager for individuals and families that stores passwords, passkeys, payment cards, personal information and secure notes in an encry...
The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email camp...
Learn how better questions, trusted AI, and human judgment help security leaders make confident decisions and build resilient systems. The post Better secu...
TA488 returned with OWA half-click exploit deploying OWAReaper implant that survived re-imaging
Researchers say the Russian state-linked hacking group tracked as Laundry Bear recently began exploiting a bug in Microsoft Outlook Web Access.
Microsoft has released the KB5101684 preview cumulative update for Windows 11 24H2 and 25H2, which 42 bug fixes and additional feature improvements for the...
Microsoft’s Secure Boot has had a serious vulnerability for most of its existence. An industry-wide standard Microsoft invented to protect Windows, and later...
Attackers have been observed abusing GitHub Actions workflows to distribute provenance-signed malicious npm packages, marking a significant escalation in sof...
Reported by Bleeping Computer. A proof-of-concept exploit was released for a vulnerability in Windows Active Directory Certificate Services (AD CS) known as ...
Germany’s Federal Office for Information Security (BSI) published a technical analysis of Windows Hello for Business, detailing how the system performs biome...
The Register reports that Google unveiled its own taxonomy for categorizing cybercrime groups, a move that appears to sideline a previous industry-wide effor...
SpecterOps has announced new capabilities built to give defenders a dynamic understanding of how adversaries traverse their hybrid environment and the abilit...
Microsoft has launched a new agentic security system for cyber defenders as well as its first cyber-focused AI model
The takedown of the Kratos phishing-as-a-service (PhaaS) platform in July 2026 has done little to slow the broader threat landscape. As security researchers ...
The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attri...