Sophos warns of two ransomware groups abusing Microsoft 365 services and default configurations to contact internal enterprise users.
Hi, what are you looking for?
Sophos warns of two ransomware groups abusing Microsoft 365 services and default configurations to contact internal enterprise users.
PowerSchool says the personal information of students and educators was stolen in a December 2024 data breach.
Marco Raquan Honesty has pleaded guilty to his roles in several fraud schemes, including smishing, identity theft, and bank account takeover.
The FCC adopts declaratory ruling requiring telecommunications providers to secure their networks against nation-states and other threats.
CISA and the FBI have updated their guidance regarding risky software security bad practices based on feedback received from the public.
CISA and other agencies call to action for the US government to take steps to close the software understanding gap.
Law firm Wolf Haldenstein Adler Freeman & Herz LLP says more than 3.4 million people were impacted by a December 2023 data breach.
Google releases OSV-SCALIBR, an open source library for software composition analysis and file system scanning.
The US Treasury has sanctioned two individuals and four entities involved in the North Korean fake IT worker scheme.
Three vulnerabilities in SimpleHelp could allow attackers to compromise the remote access software’s server and the client machine.
Authentication solutions provider Wultra has raised €3 million (~$3.1 million) for its post-quantum technology.
Cannabis retailer Stiiizy says hackers stole the personal information of 380,000 consumers from one of its vendors.
North Korea-linked Lazarus Group is targeting freelance software developers to compromise the supply chain.
A vulnerability in Google’s OAuth implementation allows takeover of old employee accounts when domain ownership changes.
Google has released Chrome 132 with fixes for 16 vulnerabilities, including multiple high-severity security defects.
Nvidia, Zoom, and Zyxel have released patches for multiple high-severity vulnerabilities across their products.
The US, Japan, and South Korea say North Korean hackers stole roughly $660 million in cryptocurrency last year.
Ivanti has released patches for multiple vulnerabilities in Endpoint Manager (EPM), including four critical-severity flaws.
SAP has released 14 security notes on January 2025 Patch Day, including two addressing critical vulnerabilities in NetWeaver.
A ransomware group tracked as Codefinger is using compromised AWS keys to encrypt S3 bucket data using SSE-C.