IAM compliance works only when organizations verify access controls across applications and infrastructure, not just document ...
The threat actor known as HoneyMyte (aka Mustang Panda) has been observed deploying an updated version of the CoolClient backdoor with a signed Windows kernel-mode rootkit that can hide and protect ...
Cybersecurity researchers have detailed a post-exploitation technique that enables the Chrome DevTools Protocol (CDP) inside a running Google Chrome or Microsoft Edge process on Windows, allowing an ...
Apple alerts suspected mercenary spyware targets in 110 countries, expanding threat notifications that have reached users in ...
Trump memo directs NCC to let vetted U.S. firms conduct approved cyber surveillance and disruption operations against foreign ...
China-linked Jewelbug uses XG-Web for espionage and crypto fraud, stealing over 580,000 browser cookies and thousands of ...
A newly disclosed zero-day flaw in GeoServer is seeing active exploitation efforts, per watchTowr. The vulnerability, which has yet to be assigned a CVE identifier, is an SQL injection vulnerability ...
Some weeks have one big security story. Others bring many smaller updates that are easy to miss but still matter. This week has plenty of them, covering cloud services, AI tools, malware, data ...
APT36-linked hackers target Afghan telecom and Indian networks with new PATCHCORD and SHEETCORD backdoors using fake tools and Google Sheets for C2.
AmnesiaStealer uses a ClickFix lure to infect macOS, steal browser sessions, and give attackers live Chromium control via CDP.
WindRelay pairs with SpyNote to relay live NFC card data from infected Android phones, enabling contactless payment fraud in real time.
Researchers hired suspected DPRK developers and observed forged IDs, AI tools, remote access, VPNs, and VPS infrastructure in controlled sandboxes ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results