Collected every two hours from specialised publications — each link leads to the original article.
Identity security is front, and center given all the recent breaches that include Microsoft, Okta, Cloudflare and Snowflake to name a few. Organizations are st…
An Iranian advanced persistent threat (APT) threat actor likely affiliated with the Ministry of Intelligence and Security (MOIS) is now acting as an initial ac…
The threat actors behind a recently observed Qilin ransomware attack have stolen credentials stored in Google Chrome browsers on a small set of compromised end…
As cybersecurity evolves, so too has its threats. Symantec recently identified an emerging threat aimed at Linux systems. This new type of ransomware (called d…
A North Korea-linked threat actor known for its cyber espionage operations has gradually expanded into financially-motivated attacks that involve the deploymen…
A DarkGate malware campaign observed in mid-January 2024 leveraged a recently patched security flaw in Microsoft Windows as a zero-day using bogus software ins…
A DarkGate malware campaign observed in mid-January 2024 leveraged a recently patched security flaw in Microsoft Windows as a zero-day using bogus software ins…
A CACTUS ransomware campaign has been observed exploiting recently disclosed security flaws in a cloud analytics and business intelligence platform called Qlik…
In today's digital landscape, around60%of corporate data now resides in the cloud, with Amazon S3 standing as the backbone of data storage for many major corpo…
Taiwanese networking equipment manufacturer D-Link has confirmed a data breach that led to the exposure of what it said is "low-sensitivity and semi-public inf…
Taiwanese networking equipment manufacturer D-Link has confirmed a data breach that led to the exposure of what it said is "low-sensitivity and semi-public inf…
Cloud hosting firm Leaseweb recently disclosed a security breach after its Customer Portal suffered downtime.…Leaseweb Hosting Provider Admits Security Breach …
The SmokeLoader malware is being used to deliver a new Wi-Fi scanning malware strain calledWhiffy Reconon compromised Windows machines."The new malware strain …
[BLACK HAT] Googlers have lately found not one but two more security vulnerabilities in Intel and AMD processors that can be exploited to steal sensitive data …
An updated version of the commodity malware called Legion comes with expanded features to compromise SSH servers and Amazon Web Services (AWS) credentials asso…
The supply chain attack targeting 3CX was the result of a prior supply chain compromise associated with a different company, demonstrating a new level of sophi…
Enterprise communications service provider 3CX confirmed that thesupply chain attacktargeting its desktop application for Windows and macOS was the handiwork o…
The Iranian nation-state group known asMuddyWaterhas been observed carrying out destructive attacks on hybrid environments under the guise of a ransomware oper…
As many as 55 zero-day vulnerabilities were exploited in the wild in 2022, with most of the flaws discovered in software from Microsoft, Google, and Apple.Whil…
Written by Linux security expert and LinuxSecurity.com Founder Dave Wreski.Attacks targeting Linux have surged in recent years due to the mass migration of wor…
Microsoft on Tuesday said it took steps to disable fake Microsoft Partner Network (MPN) accounts that were used for creating maliciousOAuthapplications as part…
The threat actors associated with the Gootkit malware have made "notable changes" to their toolset, adding new components and obfuscations to their infection c…
Threat actors are evolving to target a wide variety of systems and infrastructure, BlackBerry says in a new report. "In addition, attacks against Linux systems…
''Log4j has been around for 20 years; it's become embedded into nearly every meaningful Java application; and the Log4Shell event led to compromises in everyth…