Russia-linked hacking group Gamaredon is infecting USB drives for lateral movement within compromised Ukrainian networks.
Hi, what are you looking for?
Russia-linked hacking group Gamaredon is infecting USB drives for lateral movement within compromised Ukrainian networks.
The Cl0p ransomware gang has listed more than two dozen victims of the MOVEit zero-day attack on its leak website.
CISA and the NSA have published new guidance to help organizations harden baseboard management controllers (BMCs).
Investors pour $15 million into Silicon Valley startup building AI-powered technology to detect and monitor harmful content on the internet.
Shift5 has now raised $108 million in funding to bring cybersecurity to OT within fleet vehicles: planes and boats and trains – and military vehicles and weapon systems.
Microsoft addressed two cross-site scripting (XSS) vulnerabilities in Azure Bastion and Azure Container Registry (ACR) leading to unauthorized access to user sessions.
Attacks exploiting the Barracuda zero-day CVE-2023-2868 have been linked to a Chinese cyberespionage group that has targeted government and other organizations.
Cybersecurity startup SquareX launches a temporary bug bounty program for its cloud-based browser security solution.
Fake security researcher accounts seen distributing malware disguised as Chrome, Signal, WhatsApp, Discord and Exchange zero-day exploits.
If you want to begin, or improve, sharing customized intelligence with key users, consider these four aspects as you develop your process.
LockBit ransomware operators launched 1,700 attacks in the US and received roughly $91 million in ransom payments.
Authorities worldwide are racing to rein in artificial intelligence, including in the European Union, where groundbreaking legislation is set to pass a key hurdle.
Microsoft is publicly exposing a Russian hacking group that worked on destructive wiper malware attacks that hit organizations in Ukraine.
CISA’s Binding Operational Directive 23-02 requires federal agencies to secure the network management interfaces of certain classes of devices.
Hundreds of thousands of ecommerce sites are impacted by a critical vulnerability in the WooCommerce Stripe Payment Gateway plugin.
Detection-focused threat intelligence firm Silent Push, which maps out the entire internet every day, has launched with $10 million in seed funding.
Google has released a Chrome 114 security update to address five vulnerabilities, including a critical-severity bug in Autofill payments.
SAP has released eight new security notes on June 2023 Security Patch Day, including two that address high-severity vulnerabilities.
ICS Patch Tuesday: Siemens and Schneider Electric have published more than a dozen advisories addressing over 200 vulnerabilities.
Music streaming giant Spotify was fined 58 million kronor ($5.4 million) for not properly informing users on how data it collected on them was being used, Swedish authorities said.