Former BlackFile affiliates linked to extortion campaign targeting private equity
Researchers warned that hackers are using voice-phishing attacks to pressure company employees under the guise of providing IT help desk services. Source link
Researchers warned that hackers are using voice-phishing attacks to pressure company employees under the guise of providing IT help desk services. Source link
The National Institute for Standards and Technology is looking for input on how to overhaul its vulnerability reporting process to better meet the challenges of…
Baptist University has said it is reviewing the security of its information technology (IT) systems after a ransomware group claimed online to have illegally accessed…
After studying recent supply-chain attacks, including Shai-Hulud, Trivy, and Megalodon, the researchers found that seemingly different incidents repeatedly used the same techniques, from forged commit…
Imagine that you share a ride to work with the same colleague most mornings. As it passes by a license plate reader, the camera records…
Welcome to the 25th edition of Cloudflare’s DDoS Threat Report. This is the first half-year edition in the series: rather than publishing separate reports for…
Minerals become chips. Chips supply data centers. Data centers power the training of models, and models are acquiring arms and legs. Mines, Minds, and Machines…
Overview Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated…
Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub. However, in…
Plug and Pwn attack details that the Windows Plug and Play driver installation can lead to execution as NT AUTHORITYSYSTEM. The technique, published by researchers…
As AI models gain advanced capabilities to find vulnerabilities in software, develop ways to exploit them, and even carry out autonomous hacking sprees, researchers offered…
The March 2026 compromise of LiteLLM was more than a short-lived malicious PyPI upload. It demonstrated how an upstream breach in developer tooling can turn…