Fixing trivial passwords is as easy as 123456
How come it’s still possible to ‘secure’ an online account with a six-digit string? 07 May 2026 • , 4 min. read The most-used password…
How come it’s still possible to ‘secure’ an online account with a six-digit string? 07 May 2026 • , 4 min. read The most-used password…
In both cases, the highest-risk users are organizations that run untrusted JavaScript and assume vm2 is containing it. Those [application development] teams should patch immediately and add…
Researchers at Securelist by Kaspersky disclosed an ongoing supply chain attack targeting the official website of the widely used DAEMON Tools software, where trojanized installers…
Industrial cybersecurity firm Dragos revealed details of an AI-assisted intrusion targeting a municipal water and drainage utility serving the Monterrey metropolitan area in Mexico, after…
Welcome to this week’s edition of the Threat Source newsletter. Hey, you. Yeah, you! The person endlessly scrolling or typing away at their computer. Did…
You’ve likely heard that Microsoft has changed its Delegated Admin Privileges (DAP) authentication control to Granular Delegated Admin Privileges (GDAP). The transition is well underway,…
A new trojan named TCLBanker, which targets 59 banking, fintech, and cryptocurrency platforms, uses a trojanized MSI installer for Logitech AI Prompt Builder to infect…
Dirty Frag is a newly disclosed, CVE-pending Linux kernel local privilege escalation (LPE) vulnerability that chains two separate page-cache write flaws, the xfrm-ESP Page-Cache Write and…
An ongoing data extortion attack targeting the widely-used education technology platform Canvas disrupted classes and coursework at school districts and universities across the United States…
Higher education has long been a target of ransomware gangs and data extortion attacks. But never before, perhaps, has a cyberattack against a single software…
A proof-of-concept exploit for a new Linux kernel vulnerability class dubbed “Dirty Frag”. This universal local privilege escalation vulnerability allows attackers to obtain root access…
Hackers are using AI popularity to trick people into installing malware. According to new research from Sophos X-Ops, shared with Hackread.com, a fake website designed…