Security leaders share how artificial intelligence is changing malware, ransomware, and identity-led intrusions, and how defenses must evolve.
Hi, what are you looking for?
Security leaders share how artificial intelligence is changing malware, ransomware, and identity-led intrusions, and how defenses must evolve.
Of 3,100 unprotected MongoDB instances, half remain compromised, most of them by a single threat actor.
The next major Windows Server and Windows releases will have the deprecated authentication protocol disabled by default.
Japan and Britain agree to accelerate cooperation on cybersecurity and the supply of critical minerals, as China’s influence grows in the region.
The likely state-sponsored threat actor had access to the hosting provider for months and targeted only certain Notepad++ customers.
Hackers compromised a MicroWorld Technologies update server and fed a malicious file to eScan customers.
Other noteworthy stories that might have slipped under the radar: Apple updates platform security guide, LastPass detects new phishing wave, CISA withdraws from RSA Conference.
Aisy has emerged from stealth mode with $2.3 million in seed funding for its AI-assisted platform.
Among them, 23,000 hosts were persistently responsible for the majority of activity observed over 293 days of scanning.
Two Biden-era memorandums have been revoked, but some of the resources they provide can still be used by government organizations.
Android users were lured to applications that served a malicious payload hosted in a Hugging Face repository.
Sandworm/Electrum hackers targeted communication and control systems at 30 sites.
The critical-severity vulnerabilities could allow unauthenticated attackers to execute arbitrary code remotely.
An LLMjacking operation has been targeting exposed LLMs and MCPs at scale, for commercial monetization.
The two bugs impacted n8n’s sandbox mechanism and could be exploited via weaknesses in the AST sanitization logic.
The four critical flaws could be exploited without authentication for remote code execution or authentication bypass.