Recently patched PaperCut zero-days used in data theft attacks
Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity
Cronos blockchain restarts after $74 million Tectonic exploit
Microsoft warns of TerminalFix attacks deploying reverse tunnels
Is Someone Hacking DoD Refrigerators?
North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
Massive Microsoft 365 outage causes auth issues, service failures
OpenAI confirms ChatGPT outage as users report errors
Chinese Fire Ant hackers turn Cisco routers into spying platforms
File servers are here to stay. Here’s how to manage them securely
⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
Berlin confirms data theft after Rhysida ransomware attack claims
ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets
Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance
Hiding Prompt Injection in Legal Filing
Microsoft says Windows 11 KB5120998 update resets mouse settings
Nigerians extradited to US for sextortion, deaths of two teens
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
Microsoft asks users to ignore 'Antivirus is turned off' errors
DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims
FulcrumSec claims Manchester Airports hack, theft of 86 GB of data
TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network
Friday Squid Blogging: Truckload of Squid Spills in Rhode Island
Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
AI Doesn’t Mean the End of Mathematics—at Least Not Yet
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
LLM-Based Social Engineering Scams
Spyware for Babies
Black Hat State of Security Vendors
Criminal Deception in Silicon Valley
Friday Squid Blogging: Neon Flying Squid
AI Is Learning to Write Genetic Code
A Tale of Two SOCs: Insights From Two Red Team Assessments
Defending Against an Active Threat to Siemens S7 Series PLCs
Who’s Tracking You? Use This New Service to Find Out
Microsoft Plugs Nearly 400 Security Holes
Canadian Man Pleads Guilty in Snowflake Extortions
#StopRansomware: Gunra Ransomware
Read This Before You Buy That TV Streaming Stick
LG to Ban Residential Proxies from Smart TV Apps
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
Microsoft Patches a Record 570 Security Flaws
Lessons Learned from CISA’s Recent GitHub Leak
Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting
Felons, Fraudsters Flog Offensive Cybersecurity Startup
FBI Seizes NetNut Proxy Platform, Popa Botnet
Defending Against China-Nexus Covert Networks of Compromised Devices
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure
Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure
CISA Shares Lessons Learned from an Incident Response Engagement
Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System