A previously unknown APT group is targeting organizations in biomedical, IT, and manufacturing sectors in Taiwan.
Hi, what are you looking for?
A previously unknown APT group is targeting organizations in biomedical, IT, and manufacturing sectors in Taiwan.
A one-click exploit targeting the Libcue component of the GNOME desktop environment could pose a serious threat to Linux systems.
A newly identified Magecart web skimming campaign is tampering with ‘404’ error pages to hide malicious code.
UK-based cable manufacturing giant Volex has been targeted in a cyberattack that involved unauthorized access to IT systems and data.
SecurityWeek continues its Hacker Conversations series in a discussion with Natalie Silvanovich, a member of of Google's Project Zero.
Recently patched TagDiv Composer plugin vulnerability exploited to hack thousands of WordPress sites as part of the Balada Injector campaign.
Threat actors are targeting Citrix NetScaler instances unpatched against CVE-2023-3519 to steal user credentials.
A high-severity vulnerability in the data transfer project cURL will be addressed with libcurl and curl updates this week.
The District of Columbia Board of Elections says voter records were compromised in a data breach at hosting provider DataNet.
Google is hosting capture the flag (CTF) events focused on Chrome’s V8 engine and on Kernel-based Virtual Machine (KVM).
Several hacker groups have joined in on the Israel-Hamas war that started over the weekend after the militant group launched a major attack.
Taiwan authorities are investigating four Taiwan-based companies suspected of helping China’s Huawei Technologies to build semiconductor facilities.
MGM Resorts said costs from a disruptive ransomware hack has exceeded $110 million, including $10 million in one-time consulting cleanup fees.
A global cybercriminal operation called BadBox has infected the firmware of more than 70,000 Android smartphones, CTV boxes, and tablets with the Triada malware.
US, Ukraine, and Israel remain the most heavily attacked by cyberespionage and cybercrime threat actors, Microsoft says.
Noteworthy stories that might have slipped under the radar: cybersecurity funding increases, new laws, and government’s illegal use of smartphone location data.
CISA and the NSA are urging network defenders and software developers to address the top ten cybersecurity misconfigurations.
The fundraising software company Blackbaud has agreed to pay $49.5 million to settle claims brought by the attorneys general of 49 states and Washington, D.C., related to a 2020 data breach.
CISA has removed from its KEV catalog five Owl Labs video conferencing flaws that require the attacker to be in Bluetooth range.
Cisco warns that unauthenticated, remote attackers can log into devices using root account, which has default, static credentials that cannot be changed or deleted.