Catalin Dragomir previously pleaded guilty to selling access to an Oregon state government office’s network.
Hi, what are you looking for?
Catalin Dragomir previously pleaded guilty to selling access to an Oregon state government office’s network.
The new funding, led by BDC Capital’s StrongNorth Fund, will accelerate Lastwall’s North American expansion.
As AI accelerates phishing, session hijacking, and credential abuse, security teams are racing to close the gap between attacker speed and defensive response.
Malicious repositories and disguised symlinks can trick AI coding agents into silently installing attacker-controlled MCP servers capable of stealing secrets, compromising CI pipelines, and deploying malicious code.
Security firms took down all four command-and-control (C&C) channels used by the GlassWorm malware.
The attack was claimed by a hacktivist group, but evidence showed it used infrastructure linked to Iranian government threat actors.
The FBI has issued an alert warning of Silent Ransom Group attacks targeting law firms.
Resolved last week, the vulnerability was exploited in the wild as a zero-day to execute scripts with root privileges.
The AI giant says the new plugin, which helps developers find vulnerabilities as they write code, has been used extensively internally.
Marlin AI automatically analyzes SaaS misconfigurations, investigates related activity across enterprise environments, and recommends remediation steps — while stopping short of fully autonomous corrective action.
Nimbus Manticore has continued its operations during and after the US military campaign against Iran.
The allegedly stolen information leaked by ShinyHunters contains email addresses, names, addresses, and dates of birth.
Notable integrations include CrowdStrike, Palo Alto Networks, Microsoft, Okta, Zscaler, Netskope, Cloudflare, Fortinet, and Wiz.
Hardcoded machineKey values in a configuration file enabled ViewState deserialization attacks leading to remote code execution.
Register to enjoy free access and explore the tools, strategies, and frameworks needed to build a resilient security program for a world where every minute counts.
DockSec, an OWASP incubator project, correlates findings from multiple container security scanners and uses AI to generate plain-English remediation guidance and exact Dockerfile fixes.
Lithuanian authorities are on high alert after a massive data leak involving more than 600,000 entries from national data registers.
The two own Dutch companies that allegedly provided bulletproof hosting services to Russia-aligned threat actors.
Sites belonging to major universities such as Harvard and Oxford, as well as DuckDuckGo, have been compromised in the attack.
The affected third-party vendor has not been named, but one possible candidate is TriZetto.