The US government's cybersecurity agency describes UEFI as "critical attack surface" that requires urgent security attention.
Hi, what are you looking for?
The US government's cybersecurity agency describes UEFI as "critical attack surface" that requires urgent security attention.
Jericho Security raises $3 million in a pre-seed funding round to help organizations defend against emerging generative AI-powered phishing attacks.
CISA disclosed 670 ICS vulnerabilities in the first half of 2023, but roughly one-third have no patches or mitigations from the vendor.
Cisco Talos researchers warn of dozens of critical- and high-severity vulnerabilities in the Milesight UR32L industrial router leading to code execution.
Cloud security specialist Qualys has provided its view of the top five cloud security risks, drawing insights and data from its own platform and third parties.
Medical infusion pumps available via secondary market sources contain Wi-Fi configuration settings from the original organization.
Forty-two cybersecurity-related merger and acquisition (M&A) deals were announced in July 2023.
Google has paid out over $60,000 for three high-severity type confusion vulnerabilities in Chrome’s V8 engine.
Threat actors have exploited a Salesforce email service zero-day vulnerability and abused Meta features in a sophisticated phishing campaign.
Endor Labs has closed a massive $70 million Series A round of financing to fuel ambitious plans to build a dependency lifecycle management platform.
Microsoft says a Russian government-linked hacking group is using its Microsoft Teams chat app to phish for credentials at targeted organizations.
Menlo Security introduced anti-phishing solutions that analyze what users see on a landing page rather than just analyzing the content of an email.
A new macOS-targeting hVNC malware family is being advertised on a prominent cybercrime forum.
Threat intelligence firm Cyble has raised $24 million in a Series B funding round co-led by Blackbird Ventures and King River Capital.
Firefox 116 was released with patches for 14 CVEs, including nine high-severity vulnerabilities, some of which can lead to remote code execution or sandbox escapes.
Threat actors are using Google AMP URLs in phishing campaigns as a new detection evasion tactic.
The recently patched Ivanti EPMM zero-day CVE-2023-35078 has been exploited to hack the Norwegian government since at least April 2023.
Forgepoint Capital makes another investment in the cyber-insurance sector with a $15 million Series A investment in Converge Insurance.
A new power side-channel attack named Collide+Power can allow an attacker to obtain sensitive information and it works against nearly any modern CPU.
Researchers unmask an Iranian-run company providing command-and-control services to hacking groups, including state-sponsored APT actors.