A sophisticated Rust-based macOS information stealer dubbed AmnesiaStealer is being distributed through counterfeit GitHub download pages in active ClickFix social engineering camp...
Threat actors began exploiting an unpatched zero-day vulnerability in GeoServer within hours of its public disclosure, according to attack surface management firm WatchTowr. The se...
Every website visit and mobile app interaction leaves behind a trail of adtech relationships that most users never see. A newly launched service called DecryptAds ...
France's Directorate General of Public Finances (DGFiP) confirmed that an attacker breached its information systems in late June, exfiltrating data belonging to individuals and bus...
The Trump administration has authorized vetted private cybersecurity companies to conduct offensive operations against transnational cybercrime organizations under a presidential m...
Security teams across the globe are scrambling to contain active exploitation of CVE-2026-59310, a critical vulnerability in VMware vCenter Server that threat actors began weaponiz...
Security researchers at FortiGuard Labs have uncovered a new Linux-based Mirai variant dubbed Evooo1Bot that has been actively exploiting unpatched vulnerabilities in internet-faci...
Threat actors are actively weaponizing a critical Microsoft SharePoint authentication bypass vulnerability, CVE-2026-55040, following the public release of a proof-of-concept (PoC)...
Security researchers have identified a sophisticated hacking-for-hire operation dubbed Jewelbug that is striking a rare balance between nation-state cyber espio...
Cisco has confirmed that a high-severity vulnerability in Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software is being acti...
Walmart, the world's largest retailer by revenue, has overhauled its security operations center (SOC) by leaning into a culture-first model that prioritizes psychological safety, t...
Walmart has adopted a 'trusted agent' model for purple teaming, physically colocating its offensive red team and defensive blue team to break down silos and accelerate the detectio...
Threat actors are actively weaponizing a critical directory-traversal vulnerability in Broadcom VMware vCenter (CVE-2026-59310, CVSS 9.8) to establish persistent remote access on c...
Enterprise defenses are having one of their strongest years on record at the network perimeter, but collapse almost entirely once an attacker is inside. According to Picus Labs' ne...
A long-running cyber-espionage operation dubbed "City-Forum" has been systematically exfiltrating sensitive data from enterprise Salesforce and ServiceNow instances since at least ...
Colombia’s Ministry of Justice and Law was hit by a ransomware attack only days before the country’s presidential transition, according to Dark Reading. The incident disrupted the ...
Microsoft's July Patch Tuesday addressed CVE-2026-55040, a SharePoint vulnerability rooted in weak authentication that allows remote, unauthenticated attackers to bypass securit...
Security researchers from BCA LTD, NorthScan, and ANY.RUN ran a deliberate insider-threat experiment in 2026, posing as a cryptocurrency startup called Ballena Azul and recruiting ...
The DeadLock ransomware group has adopted a decentralized operational model that combines the Session messaging network with blockchain-backed services to make its extortion infras...
Three serious vulnerabilities in Zoom's annotation feature could have allowed meeting participants to hijack the computers of other attendees. The flaws, tracked as CVE-2026-53413 ...
Palo Alto Networks Unit 42 researchers Asher Davila, Chris Navarrete, and Doel Santos have uncovered Kimwolf v7, a significantly re-engineered iteration of the Kimwolf/AISURU Andro...
Long before phishing emails and OSINT frameworks, Arthur Conan Doyle's Sherlock Holmes was already mastering the art of social engineering—wearing disguises, cultivating intelligen...
Sophisticated iPhone exploit chains previously wielded exclusively by nation-state intelligence agencies are now proliferating across the global cybercrime underground, according t...
Poland's CERT Polska has disclosed a previously unknown cyberattack that disrupted a combined heat and power (CHP) plant supplying heat to roughly 50,000 residents during last wint...
For decades, vulnerability management has been driven by the Common Vulnerability Scoring System (CVSS) — a framework that assigns numeric severity ratings to CVEs based on intrins...
Cyberattacks targeting US water utilities have expanded to at least a dozen states, with cybersecurity investigators pointing to Iran-linked threat actors as the likely perpetrator...
Cybersecurity researchers at Yeeth Security have flagged two malicious Visual Studio Code extensions posing as Solidity development tools that deliver a full-fledged information st...
New Jersey and Alabama have joined the growing list of US states confirming that their water and wastewater facilities were targeted in a coordinated hacking campaign that began in...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical-severity command injection vulnerability in Progress Kemp LoadMaster to its Known Exploited Vu...
Security researchers have uncovered a sprawling npm registry campaign in which nearly 800 malicious packages distribute a cross-platform remote access trojan (RAT) and infostealer ...
A new wave of ClickFix-style social engineering attacks is delivering a Go-based macOS stealer engineered to silently siphon funds from cryptocurrency wallets while harvesting brow...
A financially motivated threat cluster tracked as UNC6671 has intensified its voice phishing (vishing) operations against enterprise employees in financial services, private equity...
The National Rural Water Association (NRWA) has launched a new partnership with DEF CON Franklin to establish the Water Watch Center (WWC), a program aimed at delivering threat ...
Arctic Wolf Labs has revealed a widespread adversary-in-the-middle (AitM) phishing campaign targeting Microsoft 365 accounts at organizations across healthcare, education, manufact...
Security researcher Malcolm Stagg has unveiled a new attack class dubbed NatJack that weaponizes network address translation (NAT) connection state to hijack active TCP sessions, s...
Law enforcement agencies worldwide continue to face a structural problem that undermines the global fight against cybercrime: their siloed operations are no match for the coordinat...
This week's threat landscape underscores how ordinary development and communication tools continue to be weaponized at scale. From nation-state-aligned telecom exposure to automate...
A new Forescout analysis has identified 4,407 internet-facing Rockwell Automation programmable logic controllers (PLCs) worldwide as of August 3, including 2,844 located in the Uni...
Huntress researchers have detailed a stealthy intrusion in which attackers exploited a SQL injection flaw in a public-facing web application to install a post-exploitation toolkit ...
A federal judge in Alexandria, Virginia sentenced Belarusian national Maksim Silnikau to 16 years in prison on August 5, 2026, for building and operating Ransom Cartel, a ransomwar...
Microsoft Threat Intelligence has tracked a macOS ClickFix operation spanning more than 250 front-end domains that fingerprints visitors before serving a malware lure, hiding the m...
Cybersecurity researchers have uncovered a sophisticated evolution of the EtherHiding technique, dubbed NullReceiver, that hides command-and-control (C2) server IP addresses inside...
A threat actor tracked as "Smoke#Screen" is leveraging ConnectWise ScreenConnect and other legitimate remote monitoring and management (RMM) tooling to establish persistent foothol...
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has evolved into a more dangerous offering, adding support for device code phishing to its existing arsenal ...
Cybersecurity researchers at Securonix Threat Research have disclosed an active, multi-wave campaign codenamed SMOKE#SCREEN that leverages social engineering lures themed around Ad...
The cybersecurity industry has long measured risk by ranking attacker sophistication—nation-state actors at the top, organized criminal groups in the middle, and inexperienced "scr...
A Russian-language loader-as-a-service (LaaS) tracked as DOUBLECUP has been weaponizing ClickFix social engineering lures since at least early June 2026 to stage steganographic PNG...
Attackers are rapidly abandoning traditional credential-stealing campaigns in favor of social engineering techniques that sidestep multi-factor authentication and leave minimal for...
New York Governor Kathy Hochul announced more than $9 million in funding on Monday to help 153 drinking water and wastewater systems harden their defenses against cyberattacks. Dis...
Researchers have released a new forensic tool designed to trace AI-generated videos back to the model and infrastructure that produced them, aiming to give defenders a faster path ...
Enterprise security teams are racing to integrate AI platforms like Anthropic's Claude, OpenAI's Codex, and Cursor into their Security Operations Centers (SOCs) for detection engin...
An attacker siphoned 1,082.65 BTC—worth roughly $70.2 million—from 1,196 addresses in a 41-minute sweep on July 30, 2026, according to Galaxy Research, which traced the drain to a ...
Advertising technology provider Adform disclosed a supply chain attack in which threat actors modified a shared JavaScript file, trackpoint-async.js, served from s2.adform[.]net, t...
A fake browser update served over hijacked hotel Wi-Fi networks has been used to deliver CornFlake, a Go-based remote access trojan (RAT) capable of capturing webcam images, microp...
A Chinese-speaking threat actor has been linked to a sustained cyber espionage campaign targeting government organizations across Central Asia, including entities in Afghanistan, K...
Cybersecurity researchers at Blackpoint Cyber have disclosed a targeted spear-phishing campaign against an unspecified law firm that weaponized a previously undocumented Go-based l...
Interpol has intensified its global fight against online financial crime by operationalizing the Global Rapid Intervention of Payments (I-GRIP), a secure communications platform th...
More than 30 water and wastewater systems across Minnesota were hit by coordinated cyberattacks on Sunday and Monday, prompting investigations by the FBI and state authorities. Min...
Device code phishing, the abuse of the OAuth 2.0 device authorization grant to hijack access tokens, has escalated from a niche red-team technique into an industrial-scale threat i...
Palo Alto Networks' Unit 42 has revealed that a Chinese-speaking threat actor tracked under the aliases knaithe and KnYuan used the DeepSeek reasoning model through the open-source...
Cheap TV streaming sticks marketed as offering unlimited content for a one-time fee are secretly powering a sophisticated ad fraud operation that spoofs mobile devices to click on ...
North Korean-linked threat actors have been tied to a sophisticated macOS malvertising campaign that abuses fake software update screens to deliver cryptocurrency-stealing malware ...
A suspected Iran-linked advanced persistent threat (APT) group has launched cyberattacks against more than 30 community water utilities across Minnesota, exposing deep vulnerabilit...
CISA has issued an urgent advisory urging water and wastewater system (WWS) operators to safeguard operational technology (OT) following a wave of cyberattacks targeting programmab...
Bank of America announced on Thursday that it will acquire MDSec Consulting Limited, a UK-based technical information security consultancy headquartered in Macclesfield, England. T...
The Chinese-linked threat actor Silver Fox has been linked to a new campaign targeting a Japanese industrial manufacturer using a three-driver bring-your-own-vulnerable-driver (BYO...
Southeast Asian cybercriminal syndicates have evolved from opportunistic fraud operations into a transnational threat ecosystem, according to reporting from Dark Reading. Once conf...
A sophisticated mobile remote access trojan (RAT) builder dubbed ‘Flying Eagle’ has emerged as a premium offering in China’s bustling malware-as-a-service (MaaS) underground, attra...
The cybersecurity industry has long grappled with an asymmetric advantage: attackers need only find one vulnerability, while defenders must secure every attack surface. With the ri...
More than 30 community water systems across Minnesota were hit by a coordinated cyberattack on July 26 and 27, 2026, targeting operational technology and triggering a statewide eme...
Russian cybersecurity vendor F6 has uncovered a sprawling fraud operation that has been cloning the websites of major Russian companies since 2017 to defraud international business...
The Federal Security Service (FSB) of Russia has formally charged Telegram founder Pavel Durov with facilitating terrorist activities under Part 1.1 of Article 205.1 of the Russian...
Two beta versions of npm packages in the @joyfill namespace—@joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4—have been compromised to deliver a rem...
Thousands of internet-exposed Baseboard Management Controllers (BMCs) and similar remote hardware management interfaces are vulnerable to offline password-cracking attacks, and thr...
Security researchers at Nozomi Networks Labs have uncovered a new Mirai-derived botnet dubbed Tengu that targets Linux-based IoT devices with an unusually resilient persistence ...
Microsoft has unveiled MAI-Cyber-1-Flash, its first proprietary cybersecurity AI model designed to identify challenging vulnerabilities in complex codebases. The model has been int...
A maximum-severity command injection vulnerability in on-premises Arista VeloCloud Orchestrator (VCO) is being actively exploited in the wild, prompting an urgent call for administ...
Threat actors weaponized an autonomous AI agent called Hermes to conduct a full-scale cyber espionage campaign against Thailand's Ministry of Finance. The open-source tool, operate...
In February 2024, the FBI and its international partners executed Operation Cronos, delivering what law enforcement officials called the most decisive blow against ransomware infra...
Dysphoria, an Internet of Things botnet tracked by China's CNCERT and Qi'anxin's XLab threat-intelligence team, has retooled its command-and-control (C2) layer with blockchain nami...
Proofpoint researchers have uncovered a sophisticated crypter-as-a-service called Cruciferra that is enabling multiple unrelated cybercrime clusters to deliver remote access trojan...
Zscaler ThreatLabz has uncovered a sophisticated cyber espionage campaign attributed to an East Asia-linked threat actor targeting government entities across the Middle East. Detec...
A long-running malvertising campaign dubbed SourTrade is bypassing traditional detection by never delivering a complete malicious file over the network. Instead, the operation, doc...
Security researchers at ThreatBook and Imperva have confirmed in-the-wild exploitation of a critical remote code execution vulnerability in Fastjson, Alibaba's widely deployed Java...
A new investigation from CTM360, published via The Hacker News, reveals that insurance-focused phishing operations have evolved beyond traditional credential harvesting into real-t...
The operators behind the DevMan ransomware-as-a-service (RaaS) scheme continue to run a dedicated web platform that lets affiliates generate payloads, track earnings, and coordinat...
Cryptocurrency holders are increasingly being targeted through physical-world coercion rather than purely digital exploits, according to a new report from blockchain security audit...
A threat actor deployed Nous Research's open-source Hermes assistant on a rented server, enabled its YOLO mode, and pointed it at Thailand's Ministry of Finance, where the agent au...
The operators behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families—TinyEgg, ChonkyChicken, a modularized variant of Chonk...
The Chaos ransomware group has adopted a novel technique to conceal its command-and-control communications, routing traffic through the victim's own Chrome or Edge browser using a ...
Group-IB researchers have exposed a China-nexus threat cluster tracked as JadeProx after discovering an unprotected Alibaba Cloud server in the Singapore region in mid-April 2026. ...
The U.S. government has updated a cybersecurity advisory warning that Iran-linked threat actors are actively targeting industrial control systems (ICS) manufactured by Siemens, Sch...
A deceptive application masquerading as an official Bahrain emergency alert has been discovered distributing sophisticated Android surveillance malware through fraudulent Google Pl...
For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the cat-and-mouse game continued. That dynamic has shifted. AI-equipped attackers ar...
Cybersecurity researchers at JFrog have uncovered an unusually targeted supply chain attack on the NuGet package registry: a trojanized fork of the popular Newtonsoft.Json library ...
Chicago-based cybersecurity startup Empirical has closed a $25 million Series A funding round, bringing total capital raised to $37 million. The round was led by Brightmind Part...
The ransomware landscape is undergoing a significant transformation driven by ecosystem fragmentation rather than artificial intelligence advancements, according to researchers tra...
Microsoft has confirmed that a third SharePoint Server vulnerability patched in its July 2026 Patch Tuesday cycle is now under active exploitation in the wild. Tracked as CVE-20...
Attackers are actively exploiting two critical vulnerabilities in WordPress—tracked as CVE-2026-63030 and CVE-2026-60137 and collectively codenamed "wp2shell"—to achieve unauthenti...
HollowGraph, a newly documented malware toolkit, is leveraging a compromised Microsoft 365 account's calendar as a two-way dead-drop for command-and-control (C&C) communication, ac...
Threat actors are actively chaining two newly disclosed vulnerabilities in the WP2Shell management plugin to achieve unauthenticated remote code execution on WordPress sites at sca...
A Russian-speaking threat actor tracked as "bandcampro" has been observed weaponizing Google's open-source Gemini CLI artificial intelligence tool to operate a live, small-scale bo...
Cybersecurity researchers at StepSecurity have uncovered a new software supply chain campaign dubbed SleeperGem targeting the Ruby ecosystem through three malicious RubyGems packag...
An unattributed threat actor tracked as UTA0533 exploited two previously unknown vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000-series VPN appliances as zero-days beg...
Cybersecurity researchers at Checkmarx have uncovered a software supply chain attack targeting the Vite frontend tooling ecosystem, with seven malicious npm packages collectively d...
Cybersecurity researchers at Expel have attributed the April 2026 DigiCert security incident to a threat activity cluster tracked as CylindricalCanine, a sub-group of the Chinese c...
Google Cloud is rolling out an 'agentic defense' strategy that folds key capabilities from its Wiz acquisition into a unified platform designed to automate threat detection and rem...
Coca-Cola's premium dairy subsidiary Fairlife has suspended operations at its US processing plants following a ransomware intrusion detected on Thursday. The company confirmed the ...
Armenian border officers at Yerevan's Zvartnots airport pulled Russian tourist Aleksandr Ermakov from the departure hall on June 28, 2026, detaining him on a U.S. extradition reque...
Western militaries are accelerating the deployment of autonomous systems at a pace that is outstripping the development of the trusted information infrastructure needed to support ...
Elastic Security Labs researcher Cyril François has disclosed a new modular malware family dubbed TELEPUZ that has been proliferating through ClickFix-infected websites since late ...
Cybersecurity researchers have uncovered 11 malicious NuGet packages posing as .NET command-line tools marketed as game cheats, bots, and automation panels. According to Socket, th...
A malware framework dubbed OkoBot has been active on Windows systems since April 2025, using a module called SeedHunter to hijack legitimate hardware wallet software and steal user...
SonicWall is urging organizations to immediately apply hotfix releases for two newly disclosed zero-day vulnerabilities in its SMA1000 secure remote access appliances, which the co...
ESET researcher Martin Smolár has uncovered 11 outdated, Microsoft-signed Unified Extensible Firmware Interface (UEFI) shim bootloaders that can be weaponized to bypass Secure Boot...
Cybersecurity researchers at Blackpoint Cyber have uncovered a previously undocumented Rust-based remote access trojan dubbed LabubaRAT that masquerades as legitimate NVIDIA softwa...
The UK and EU have taken a landmark step in cybersecurity diplomacy, jointly imposing sanctions on Russian individuals and entities for the first time in response to state-sponsore...
As enterprises race to integrate artificial intelligence into their security stacks, a new operational concept is gaining traction inside engineering departments: the Yellow Team. ...
Google and Microsoft have removed ModHeader, a popular HTTP header-editing browser extension with roughly 1.6 million combined installs, after security researchers identified a dor...
Cybersecurity researchers at Jamf Threat Labs have identified a sophisticated new macOS information stealer dubbed CrashStealer, distinguished by its native C++ implementation rath...
A single misconfiguration handed French security firm Lexfo an intelligence windfall. During a routine internet scan in late April 2026, researchers found an attacker-controlled ho...
SentinelOne SentinelLABS has uncovered a sustained cyber espionage operation targeting multiple Pakistani law enforcement agencies, with activity spanning February 2024 through Apr...
On July 11, 2026, the popular jscrambler npm package was compromised in a textbook software supply chain attack, with attackers publishing version 8.14.0 carrying a preinstall hook...
A cybercrime operation tracked as WP-SHELLSTORM inadvertently exposed its own infrastructure for 22 days, leaving a rented US-based server at 137.175.93[.]126 wide open with no aut...
Datadog Security Labs is sounding the alarm over a coordinated series of campaigns that systematically enumerate corporate GitHub organizations, repositories, and user accounts thr...
Microsoft has dissected a destructive Windows backdoor dubbed GigaWiper, a Go-based implant that bundles three distinct destructive payloads into a single command-driven toolkit. T...
Iranian state-sponsored hacking groups have significantly broadened their targeting scope, moving past traditional critical infrastructure attacks to compromise any organization wi...
A coordinated global anti-fraud operation, codenamed First Light 2026, led to the arrest of 5,811 individuals across 97 countries and territories, with authorities intercepting $29...
The cybersecurity world converged on a single word this summer: clearinghouse. Chainguard launched Athena, a long-rumored platform that had been quietly processing pre-disclosure v...
Microsoft has shipped a fix for a high-severity privilege escalation vulnerability in its built-in antivirus engine, roughly one month after exploit details surfaced publicly. Trac...
Symantec's Threat Hunter Team has identified a new ransomware family, dubbed GodDamn, that leverages a Microsoft-signed kernel driver called PoisonX to neutralize endpoint secur...
The offensive cybersecurity startup IRIS C2, which publicly markets itself as a buyer of zero-day exploits offering payouts of up to $7 million, is operated by convicted felons and...
Mexico's national cybersecurity strategy is heading into a high-stakes stress test it was never designed for: hosting matches during the 2026 FIFA World Cup, the largest sporting e...
Sophos researchers examining a week of endpoint telemetry from June 2026 have found that AI coding agents such as Claude Code, Cursor, and OpenAI Codex are routinely tripping detec...
Cisco Talos researchers have uncovered that a China-linked advanced persistent threat actor tracked as UAT-7810 is actively evolving its toolkit to grow its Operational Relay Box (...
A sophisticated phishing campaign is weaponizing the names of well-known consumer brands to lure marketing professionals into surrendering their Google Workspace credentials. Resea...
A new Microsoft 365 device-code phishing campaign observed between late June and early July 2026 is leveraging a reusable attack framework dubbed DEBULL to hijack enterprise accoun...
A new Android malware-as-a-service operation dubbed RedWing is being advertised on Telegram as a turnkey bank-fraud kit, enabling low-skill criminals to hijack victim devices, harv...
A sophisticated threat actor tracked as Armored Likho has been deploying a custom-built infostealer dubbed BusySnake against government agencie...
An Iranian threat cluster linked to the Ministry of Intelligence and Security (MOIS) is using a previously undocumented modular command-and-control framework dubbed Cavern (aka Cav...
The AI security operations center (SOC) market has matured into a crowded landscape where SIEM, SOAR, and pureplay AI SOC vendors all claim to offer autonomous detection and respon...
Google, the FBI, Lumen, and other partners moved this week to dismantle the NetNut residential proxy network—also tracked as Popa—disabling Google accounts and services used for ma...
Researchers at Shandong University have unveiled TrojPix, a covert channel technique that exfiltrates data from air-gapped systems by modulating imperceptible pixels on the screen ...
Flipper Devices has confirmed that development of the Flipper Zero firmware will continue, but with a leaner internal team and a heavier reliance on community contributions. The...
A U.S. government entity—almost certainly Union County, Ohio—paid roughly $1 million in bitcoin to a group calling itself Kairos to suppress the leak of stolen files, according to ...
A coordinated law enforcement and industry operation has dismantled NetNut, one of the world's largest residential proxy networks, cutting off access to an estimated two million co...
Cisco Talos researchers have uncovered a phishing-as-a-service (PhaaS) platform named “ARToken” that operates as an affiliate of the EvilTokens ecosystem, exposing a sophisticated ...
A new macOS information stealer dubbed PamStealer has been identified by Jamf Threat Labs, employing a multi-stage infection chain designed to harvest login credentials, browser da...
Google has significantly disrupted NetNut, one of the largest residential proxy networks in operation, in a coordinated takedown with the FBI, Lumen's Black Lotus Labs, and acad...
The FBI and IRS Criminal Investigation have seized hundreds of domains associated with NetNut, a sprawling residential proxy service operated by publicly-traded Israeli company Ala...
When a security operations team ingests every firewall log, DNS query, and authentication event into their SIEM, they quickly discover that more data does not always mean better de...
Threat actors are weaponizing search engine optimization (SEO) poisoning to push fraudulent software download pages that deploy AsyncRAT through the legitimate ScreenConnect remote...
The Brazilian banking trojan Ousaban—also tracked as Javali—has resurfaced in a new campaign aimed at Windows users banking in Spain and Portugal. Researchers at Fortinet's FortiGu...
Cybersecurity researchers at Huntress have uncovered a massive, ongoing automated password spray campaign targeting Microsoft's Azure command-line interface (CLI), generating more ...
Researchers at QiAnXin's XLab have been tracking a fast-evolving botnet called RustDuck since February 2026, warning that its true danger lies not in its current size but in the sp...
McAfee Labs has uncovered an active browser extension campaign dubbed Silent Swap that stealthily replaces cryptocurrency wallet addresses during transactions, red...
More than 236,000 second-level domains powering investment scam infrastructure have been built using Uni-App, a Chinese open-source cross-platform development framework maintained ...
The FBI and CISA have updated their March advisory (PSA I-062626-PSA) warning that Russian intelligence services are now actively phishing Signal users into surrendering their Back...
A Chinese-speaking advanced persistent threat (APT) actor tracked as CL-STA-1062 has been linked to a newly discovered custom backdoor called TinyRCT, deployed in a sustained cyber...
Cybersecurity researchers at Socket have uncovered a new wave of the Mini Shai-Hulud, Miasma, and Hades malware campaign, this time targeting npm packages associated with LeoPlatfo...
Microsoft has disclosed an active phishing campaign targeting hotel and hospitality organizations across Europe and Asia since April 2026, using photo-themed ZIP archives to delive...
Despite the growing abundance of security telemetry, most SOC teams still struggle with fundamental questions during incident investigation: What actually happened? What evidence s...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent warning on Tuesday that a critical security flaw in Lantronix EDS5000 Series serial-to-IP converte...
The U.S. Department of Justice announced on Tuesday the seizure of a cloud computing account operated by subsidiaries of Cambodia-based conglomerate HuiOne Group, a network accused...
Symantec researchers have uncovered a new stealthy backdoor dubbed "Mistic" being deployed by KongTuke (also tracked as Woodgnat), a financially motivated initial access broker act...
A critical vulnerability in Cisco's Unified Communications Manager (Unified CM) is being actively exploited in the wild, according to exploit intelligence firm Defused. The flaw, t...
A Russian-speaking initial access broker (IAB) has been linked to a massive credential-harvesting campaign called FortiBleed, which has compromised over 430,000 FortiGate firewalls...
Cybersecurity researchers at JFrog have uncovered three malicious npm packages designed to deliver a Windows-based remote access trojan (RAT) to developers who install them. Publis...
Security researchers at Kaspersky have uncovered an active social engineering campaign abusing WhatsApp Direct Messages to distribute heavily obfuscated VBScript files disguised as...
Elastic Security Labs has uncovered a new campaign, tracked as REF8372, that delivers the CastleStealer information-stealing malware through a previously undocumented loader called...
Threat actors are actively exploiting a recently patched information disclosure vulnerability in the Gravity SMTP WordPress plugin, installed on roughly 100,000 websites. Tracked a...
Threat actors are actively exploiting an unauthenticated information disclosure vulnerability in the Gravity SMTP WordPress plugin, which is installed on over 100,000 websites. Tra...
In a significant blow against one of the web's most persistent malware distribution networks, Dutch law enforcement, working alongside the FBI, the Royal Canadian Mounted Police, a...
CISA has issued an urgent advisory urging Fortinet customers to secure their FortiGate appliances against an ongoing malicious campaign dubbed FortiBleed, which has already comprom...
The average enterprise security team juggles 40 or more security tools, generating massive amounts of internal telemetry and asset data. Yet these tools operate in silos, producing...
Security researchers from Qurium, HUMAN Security, and XLAB have concluded that the massive Popa botnet is operated by NetNut, a residential proxy service run by publicly-traded Isr...
The Gentlemen ransomware-as-a-service (RaaS) operation is actively maintaining a sophisticated suite of endpoint detection and response (EDR) killers to help its affiliates evade d...
A cluster of 23 deceptive Chrome browser extensions has been uncovered routing user searches through monetization middleware before delivering results, exposing roughly 758,000 aff...
Microsoft's Defender Security Research Team has disclosed details of a sophisticated Windows-based cryptocurrency clipper campaign that has been active since February 2026. The mal...
INC Ransomware has cemented its position as one of the most prolific ransomware-as-a-service (RaaS) operations in 2026, claiming more than 830 victims since its emergence in August...
INC Ransomware has emerged as one of the most operationally disciplined ransomware groups active in 2024-2025, achieving consistent success not through novel exploit chains or zero...
A French-speaking threat actor tracked as "Poisson" compromised a small French automotive business and demonstrated a persistence technique that survived the loss of his command-an...
Security teams today are drowning in findings but starving for context. Vulnerability scanners, CSPM tools, endpoint detection platforms, attack surface monitors, SAST scanners, an...
A newly discovered data leak dubbed "FortiBleed" has exposed a massive trove of Fortinet and FortiGate VPN credentials spanning 73,932 firewall URLs across 194 countries. Security ...
Organizations now manage thousands of human and non-human identities spread across cloud services, SaaS applications, endpoints, and remote environments. As hybrid work, BYOD polic...
A new analysis of 3,000 organizational attack surfaces reveals that unnecessary internet-facing services remain the weakest link in enterprise defense. Intruder's 2026 Attack Surfa...
Cybersecurity researchers from Morphisec, BlueVoyant, and Huntress have independently identified a wave of ClickFix social engineering campaigns distributing three new malware load...
Security researchers at Zimperium's zLabs have uncovered a new Android banking trojan dubbed Rokarolla, named after its command-and-control infrastructure. The malware targets 217 ...
A newly disclosed technique dubbed GhostTree exploits a little-known feature of the Windows NTFS file system to conceal malware from security scanners. By creating recursive direct...
Security teams are drowning in IP data but starving for context, according to a new industry study from Spur Intelligence. The survey of more than 200 security practitioners found ...
Threat intelligence firm Defused Cyber has reported active in-the-wild exploitation of three critical vulnerabilities in Fortinet FortiSandbox appliances over the past 24 hours. Th...
Cybersecurity researchers at ESET have uncovered two previously undocumented Windows variants of SprySOCKS, a backdoor long believed to operate exclusively on Linux systems. Intern...
A China-linked espionage group tracked as UNC6508 maintained undetected access to North American medical, academic, and military research networks for over a year, quietly siphonin...
Cybersecurity researchers at Socket have uncovered a sprawling network of 152 Google Chrome extensions posing as live wallpaper and new tab add-ons that covertly distribute a poten...
Cybersecurity researchers at Group-IB have exposed a sprawling social engineering campaign operated through Sniper Dz, a turnkey phishing-as-a-service (PhaaS) platform dismantled l...
Palo Alto Networks has confirmed active exploitation of CVE-2026-0257, a high-severity authentication bypass vulnerability (CVSS 7.8) affecting the GlobalProtect VPN portal and gat...
The Chinese state-linked espionage group "Velvet Ant" maintained undetected access to a large organization's critical infrastructure for an extraordinary 10 years, according to res...
More than 400 packages in the Arch User Repository (AUR) have been compromised to distribute a Linux rootkit and infostealer malware designed to harvest developer credentials, acce...
Supply-chain attacks rarely appear under their real name in underground forums. Long before a malicious package, compromised update, or breached vendor makes headlines, the precurs...
Section 702 of the Foreign Intelligence Surveillance Act (FISA) expired at midnight Friday after Congress and the White House failed to reach a deal to renew the controversial spy ...
For the past decade, Managed Detection and Response (MDR) filled a critical gap in enterprise security by providing outsourced 24/7 alert triage for teams that couldn't staff round...
An INTERPOL-coordinated operation codenamed "Operation Ramz" has successfully disrupted Sniper Dz, a decade-old phishing-as-a-service (PhaaS) platform responsible for harvesting ov...
Europol has announced the takedown of AudiA6, an industrial-scale cryptocurrency laundering service that processed more than €336 million (~$389 million) in illicit funds since lau...
Phishing attack volume has declined by approximately 20% over the past reporting period, according to new data highlighted by Dark Reading, but the decline tells a misl...
A new deep-dive into The Gentlemen ransomware operation reveals that the financially motivated threat group has claimed 478 victims since emerging in March 2025, and now operates a...
The latest threat intelligence roundup reveals a staggering expansion of the identity-based attack economy, with Flashpoint reporting that infostealer infections on more than 11.1 ...
Law enforcement agencies across 11 countries have jointly dismantled "AudiA6," a cryptocurrency laundering service that processed more than $380 million in illicit proceeds for ran...
Vietnam-aligned threat actor OceanLotus has been linked to two parallel cyber-espionage campaigns targeting domestic entities, leveraging its signature SPECTRALVIPER backdoor in a ...
For three decades, vulnerability management depended on a buffer: the months between disclosure and weaponization. Triage by severity, schedule remediation, validate, and move on. ...
State-sponsored threat actors from China and North Korea are scaling up cyber operations across the Asia-Pacific region, leveraging tactical gains to pursue higher-value targets in...
Cybersecurity researchers at Lumen's Black Lotus Labs have identified a significant resurgence of JDY, a covert China-linked botnet that has expanded to over 1,500 compromised smal...
A clean penetration test report may look reassuring, but security leaders should read it as a warning sign, not a victory lap. According to Autumn Stambaugh and Can Yüceel of Picus...
Two Russia-aligned cyber-espionage campaigns have continued weaponizing CVE-2025-8088, a path-traversal vulnerability in WinRAR patched in July 2025, to compromise Ukrainian organi...
Despite record investment in SIEM platforms, firewalls, IAM systems, and AI-driven detection, enterprise network security teams are still struggling with the same fundamental probl...
A new supply chain offensive dubbed Hades has compromised 19 packages in the Python Package Index (PyPI), deploying 37 malicious wheel artifacts that silently install a Bun-based c...
New variants of the NFCShare Android malware are spreading through a phishing campaign that impersonates legitimate banking apps, with malicious APKs hosted on public GitHub reposi...
Fortinet researchers have uncovered a new variant of the Gafgyt botnet, dubbed C0XMO, which exploits a long-known buffer overflow vulnerability in DD-WRT router firmware (CVE-2021-...
The Silent Ransom Group, tracked by Mandiant as UNC3753 (also known as Luna Moth and Chatty Spider), is actively targeting U.S. law firms and professional services organizations wi...
Hackers are actively exploiting a critical unauthenticated remote code execution (RCE) vulnerability in the Everest Forms Pro WordPress plugin to seize full control of vulnerable w...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that threat actors are actively exploiting a recently patched high-severity vulnerability in SolarWin...
ESET researchers have uncovered a new Android spyware strain dubbed "Asin" that has been actively targeting Arabic-speaking users through a series of malicious apps disguised as le...
Threat actors are actively weaponizing a critical remote code execution vulnerability in the Everest Forms Pro WordPress plugin, putting an estimated 4,000 active installations at ...
Cybersecurity researchers and the FBI are sounding the alarm on a massive wave of FIFA-themed fraud targeting World Cup 2026 fans, just days before the June 11 opening match. With ...
The threat actor tracked as PCPJack has compromised at least 230 cloud servers across Amazon Web Services (AWS), Google Cloud Platform, and Microsoft Azure, converting them into a ...
Cisco has released a patch for a server-side request forgery (SSRF) vulnerability in Unified Communications Manager (Unified CM) and its Session Management Edition that allows an u...
Cybersecurity researchers at Check Point have uncovered a large-scale SEO poisoning operation that impersonates popular open-source and freeware projects to distribute malware thro...
Unknown attackers maintained undetected access to the Outlook mailbox of a senior executive at a major global stock exchange for at least five months, systematically exfiltrating c...
A state-sponsored cyber-espionage campaign attributed to Pakistan-linked threat actors has been uncovered targeting Afghanistan's Ministry of Finance, leveraging the open-source Xe...
Cybersecurity researchers at Huntress have uncovered a sophisticated malspam campaign that exploits Google's DoubleClick domain to bypass security filters and deliver a remote acce...
Assume the breach. Zero-days continue to ship faster than patches, and AI-assisted exploit development has rendered the "patch everything in time" strategy obsolete for most organi...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two high-severity vulnerabilities—one in the Android Framework and another in the Linux kernel—to its Kno...
Cybersecurity researchers at Huntress have disclosed an unpatched vulnerability in the Windows "search:" URI handler that can be weaponized to leak a user's NTLMv2 hash to a remote...
Cybersecurity researchers at McAfee Labs have uncovered a malware-as-a-service (MaaS) campaign dubbed Weedhack that has been actively targeting Minecraft players since January 2026...
A large-scale malware-as-a-service operation dubbed WeedHack has infected more than 116,464 systems since January 2026 by targeting Minecraft players with trojanized mods, clients,...
Google has rolled out its June 2026 Android security bulletin, addressing 124 vulnerabilities across the mobile operating system, including a high-severity privilege escalation fla...
Russian state-sponsored hacking group Gamaredon, officially linked to the Federal Security Service (FSB), has been exploiting a WinRAR path traversal vulnerability (CVE-2025-8088) ...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity Oracle WebLogic Server flaw, tracked as CVE-2024-21182, to its Known Exploited Vulnerabil...
Endpoint detection and response (EDR) has become a default investment for mid-sized organizations, yet owning an advanced platform does not automatically translate into operational...
A new supply chain attack campaign dubbed "Miasma" has compromised multiple @redhat-cloud-services npm packages to steal credentials and secrets from developer machines, ultimately...
Seqrite Labs has uncovered a sophisticated cyber espionage operation dubbed Operation Dragon Weave, targeting government officials, research institutions, and financial services in...
Security researchers at GoDaddy have uncovered a sophisticated WordPress malware campaign that leverages Steam Community profile comments to conceal command-and-control (C2) commun...
Dutch authorities have successfully dismantled a massive botnet infrastructure responsible for enslaving approximately 17 million compromised devices, including computers, tablets,...
The Iranian threat actor MuddyWater has been linked to a sophisticated cyber espionage campaign that compromised at least nine organizations across nine countries on four continent...
Multi-factor authentication (MFA) was designed to close a critical gap in identity security by requiring a second factor beyond passwords. However, attackers have developed a techn...
A critical high-severity vulnerability (CVE-2026-5426, CVSS 7.5) in Digital Knowledge KnowledgeDeliver, a Learning Management System (LMS) widely used in Japan, was actively exploi...
Threat actors are actively exploiting a critical SQL injection vulnerability in Ghost CMS (CVE-2026-26980, CVSS 9.4) to compromise over 700 websites across multiple sectors includi...
Network Detection and Response (NDR) has long carried a reputation for being noisy and overwhelming security operations center (SOC) teams with alert fatigue. However, the emergenc...
The Cybersecurity and Infrastructure Security Agency (CISA) has unveiled a new nomination form enabling security researchers, vendors, and industry partners to submit vulnerabiliti...
Authorities in Europe and North America have successfully dismantled First VPN, a criminal VPN service specifically designed to anonymize ransomware operations and other cyberattac...
Jacob Butler, known in cybercrime circles as "Dort," has been arrested in Canada and faces criminal charges in both the United States and Canada for allegedly operating the Kimw...
Cybersecurity researchers from Lumen Technologies Black Lotus Labs have uncovered a sophisticated Linux malware campaign targeting a telecommunications provider in the Middle East ...
Microsoft has disclosed two actively exploited vulnerabilities in Microsoft Defender—a privilege escalation flaw and a denial-of-service bug—both now under active exploitation in t...
Ukrainian cyberpolice, working in coordination with U.S. law enforcement, have identified an 18-year-old male from Odesa suspected of orchestrating an infostealer malware operation...
INTERPOL's Operation Ramz has concluded with a significant blow to cybercriminal operations across the Middle East and North Africa (MENA) region. The coordinated crackdown, spanni...
Phishing attacks continue to evolve beyond simple credential harvesting, creating multi-stage risks that can compromise email systems, SaaS applications, cloud platforms, and inter...
In a concentrated 48-hour window, threat actors launched coordinated attacks against npm, PyPI, and Docker Hub, marking a significant escalation in software supply chain aggression...
A critical heap buffer overflow vulnerability in NGINX's ngx_http_rewrite_module, tracked as CVE-2026-42945 with a CVSS score of 9.2, is now under active exploitation mere days aft...
Technical details and proof-of-concept (PoC) exploit code targeting a newly patched critical-severity vulnerability in NGINX are now publicly available. Tracked as CVE-2026-42945 w...
Bitdefender's analysis of 700,000 high-severity incidents reveals that legitimate-tool abuse now accounts for 84% of attacks, fundamentally reshaping how organizations must approac...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-20182, a critical authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Controller...
The cybersecurity industry’s beloved “purple team” concept is broken by design. According to data from CISA KEV, VulnCheck KEV, and ExploitDB, the mean time from ...
German law‑enforcement agencies, led by the Federal Criminal Police Office (BKA) and the Hessian State Criminal Police Office (LKA Hessen) in close coordination with Europol’s Euro...
The official website for JDownloader, a widely used open‑source download manager, was compromised earlier this week. Attackers altered the download links for both Windows and Linux...
U.S. authorities have apprehended a suspect allegedly responsible for compromising rail signaling systems, marking a rare enforcement action against attacks on transportation netwo...
Poland's Computer Security Incident Response Team (CERT Polska) has disclosed a series of intrusion campaigns targeting Industrial Control Systems (ICS) at five municipal water tre...
RansomHouse, a known ransomware operation, has claimed responsibility for a breach at Trellix, a prominent cybersecurity vendor. The group posted several screenshots on a dark‑web ...
A Slovakian national, Alan Bill, 33, was sentenced on Thursday to 16 years (192 months) in federal prison after pleading guilty to conspiracy to distribute controlled substances. B...
Kaspersky researchers have uncovered a convergence between the pro‑Ukraine hacktivist group BO Team and the advanced threat actor Head Mare, revealing that the two have begun shari...
The Hacker News recently highlighted an emerging cybersecurity threat model dubbed "Patient Zero" that organizations increasingly struggle to detect. A specialized webinar hosted b...
A recent analysis of more than 25 million security alerts collected from a dozen global security operations centers (SOCs) over a six‑month period reveals that low‑severity events ...
Cybersecurity researchers have disclosed a previously unknown Linux backdoor called PamDOORa that is being actively advertised on the Russian cybercrime forum Rehub for $1,600 by a...
Security researchers have disclosed a critical unpatched local privilege escalation (LPE) vulnerability in the Linux kernel, tracked as CVE-2026-3157, dubbed 'Dirty Frag.' The flaw...
Modern threat actors launch campaigns that generate thousands of alerts per hour, leaving security operations centers (SOCs) drowning in data. Even with a larger team of analysts, ...
Ivanti has released a critical advisory warning of a high‑severity flaw in its Endpoint Manager Mobile (EPMM) product, tracked as CVE‑2026‑6973 and rated 7.2 on the CVSS scale. The...
Organizations often believe that securing a retainer with a reputable incident response (IR) firm or pre‑approving an external provider is sufficient to survive a cyber crisis. Whi...
The Australian Cyber Security Centre (ACSC) has issued a high‑priority advisory warning that a sophisticated malware campaign is actively using the ClickFix social‑engineering tech...
Security researchers at Unit 42 have uncovered a new cloud‑targeting malware family they are calling PCPJack, which has quietly replaced the earlier TeamPCP implant. PCPJack distin...
Ethan J. Rivera, a 20‑year‑old from Los Angeles, California, was sentenced on Friday to 78 months (6.5 years) in federal prison for his role in a sophisticated criminal operation t...
Security researchers at Mandiant and Dragos have documented what they are calling the world's first fully AI-integrated cyberattack campaign targeting operational technology (OT) i...
Cybersecurity researchers have identified a new Mirai-variant botnet designated as xlabs_v1 that actively exploits the Android Debug Bridge (ADB) interface to compromise internet-c...
The Hacker News (THN) has officially opened the call for entries for the Cybersecurity Stars Awards 2026, an initiative designed to shine a spotlight on the behind‑the‑scenes work ...
A sophisticated phishing campaign is leveraging Google’s sponsored search ads to mimic the login page of ManageWP, GoDaddy’s platform for centrally managing large fleets of WordPre...
Acronis researchers have documented a systematic shift in ransomware operations: before triggering encryption, threat actors now deliberately cripple backup infrastructure. Their 2...
hackmyip.com will host a live webinar titled "Why Network Incidents Escalate and How to Fix Response Gaps" on March 15, 2025 at 2:00 PM EST. The session will feature Alex Rivera, s...
Security researchers have linked a newly tracked China‑nexus threat cluster, designated UAT‑8302, to a wave of cyber‑espionage operations targeting government agencies in South Ame...
Microsoft’s Threat Intelligence Center (MSTIC) has released details of a large‑scale credential‑harvesting operation that successfully targeted roughly 35,000 users in 26 countries...
Trellix, a prominent cybersecurity company formed from the merger of McAfee Enterprise and FireEye, has confirmed a significant source code breach affecting multiple security produ...
The UC Berkeley Center for Long-Term Cybersecurity (CLTC) has launched a dedicated research hub designed to bridge the cybersecurity gap for schools, local governments, and non‑pro...
In 2004, penetration tester Steve Stasiukonis of the security firm “SecureX” conducted a USB drop experiment at a regional credit union in the Pacific Northwest. Armed with a batch...
Education technology provider Instructure has disclosed a significant data breach after a threat actor operating under the alias 'CSAMKing' claimed to have stolen approximately 280...
On April 8, 2026, Disc Soft Ltd. confirmed that the official DAEMON Tools Pro installer (version 8.0.0.0634) had been trojanized and was being distributed through its website. The ...
On 12 March 2026, Taiwanese authorities arrested a 23‑year‑old university student for allegedly compromising the TETRA (Terrestrial Trunked Radio) communication network that underp...
A Latvian national was sentenced on Friday to 8.5 years in a U.S. federal prison after being extradited to face charges related to his work as a "cold case" negotiator for the Russ...
An international law enforcement coalition dubbed 'Operation Crypto Shield,' led by the FBI, Europol, and China's Ministry of Public Security, has achieved a landmark victory again...
Physical cargo theft is no longer the domain of opportunistic street gangs; it has morphed into a high‑tech enterprise orchestrated by transnational cybercriminal syndicates. Accor...
Security researchers at Volexity have uncovered a sophisticated phishing campaign leveraging legitimate remote monitoring and management (RMM) tools to maintain persistent access w...
Twenty years ago, Dark Reading entered the cybersecurity media landscape without the traditional safety net of a print edition, proving that compelling content and editorial expert...
Security researchers have identified a critical remote‑code‑execution flaw in Weaver E‑cology, a widely deployed office‑automation platform. The vulnerability, tracked as CVE‑2026‑...
Kaspersky researchers identified a surge in phishing campaigns leveraging Amazon Simple Email Service (SES). Attackers abuse the trusted infrastructure by sending emails via verifi...
Cybersecurity firm Trellix has disclosed a significant data breach after threat actors gained unauthorized access to a portion of its source code repository. The incident, discover...
Amazon Simple Email Service (SES), the cloud‑based email sending platform offered by Amazon Web Services, is increasingly being weaponized by threat actors to distribute phishing e...
Fraudsters are not breaking into credit unions with zero‑days or ransomware; they are exploiting the normal loan origination workflow. Flare’s threat‑intelligence team uncovered a ...
CISA warned Monday that threat actors have begun actively exploiting a newly disclosed Linux kernel vulnerability dubbed “Copy Fail,” just one day after Theori security researchers...
Instructure, the educational technology company behind the popular Canvas learning‑management system, confirmed on March 5 2026 that unauthorized actors had accessed its internal n...
Security researchers have flagged a new iteration of the consent‑phishing tool known as ConsentFix, now labeled v3, which dramatically expands the scale and automation of attacks a...
Cybersecurity researchers have identified two distinct cybercrime groups orchestrating rapid, high‑impact extortion campaigns that operate almost entirely within Software‑as‑a‑Serv...
Cybersecurity researchers have uncovered a sophisticated espionage operation linked to Chinese state actors, targeting a broad spectrum of victims across Asia and a NATO member sta...
Managed security services are on a steep ascent, with the market expected to swell from $38.31 billion in 2025 to $69.16 billion by 2030, making cybersecurity the fastest‑growing s...
North Korean advanced persistent threat (APT) groups have consolidated their dominance over the cryptocurrency threat landscape in 2026, accounting for an estimated 76 % of all dig...
Dark Reading marks its 20th anniversary this month, reflecting on two decades of delivering timely cybersecurity news, analysis, and insights to professionals worldwide. Launched o...
Criminal IP, a provider of exposure‑based threat intelligence, announced a partnership with Securonix to embed its rich contextual data directly into the Securonix ThreatQ platform...
A federal court has sentenced two former cybersecurity incident response professionals to four years in prison each for their roles in conducting BlackCat (ALPHV) ransomware attack...
Security researchers at SentinelOne and WithSecure have uncovered a sophisticated Python-based backdoor named DEEP#DOOR that leverages legitimate tunneling services to establish co...
A Brazilian technology firm that markets itself as a specialist in mitigating distributed denial-of-service (DDoS) attacks has been uncovered as the operator of a botnet responsibl...
Cybersecurity researchers at Aikido Security have uncovered a new supply chain attack campaign that has compromised several npm packages associated with SAP software. The malicious...
In February 2026, a joint research team from SentinelLabs and the University of Calgary published a report revealing a paradigm shift in cyber‑attack tradecraft. The analysts, led ...
Security teams across industries are increasingly discovering that traditional vulnerability management approaches fail to accurately represent organizational risk. Despite closing...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical security flaws—one affecting ConnectWise ScreenConnect and the other targeting Microsoft Win...
Chris Inglis, who served as NSA Deputy Director from 2011 to 2014 under Director Keith Alexander, has broken his silence on the agency's missteps during the Edward Snowden affair, ...
The ransomware ecosystem was rocked in early 2026 when two prominent ransomware‑as‑a‑service (RaaS) operations, 0APT and KryBit, turned on each other, spilling a treasure trove of ...
Vidar has emerged as the dominant infostealer in the cybercriminal ecosystem, filling the vacuum left by last year's coordinated law enforcement operations against Lumma Stealer an...
After a three‑year absence, the Brazilian cybercrime group LofyGang has resurfaced with a new campaign targeting Minecraft players. The outfit is deploying a freshly coded stealer ...
A Chinese national linked to the Silk Typhoon advanced persistent threat (APT) group has been handed over to U.S. authorities after being arrested in Italy in July 2025. Xu Zewei, ...
Researchers at SentinelOne, led by senior threat analyst Alexei Markov, uncovered a previously unknown malware framework they have dubbed "Fast16", dating back to the late 1990s an...
Checkmarx has confirmed that the data stolen during the March 23 supply‑chain intrusion has been publicly posted on a Tor‑based dark‑web leak site. The company’s incident response ...
A pro‑Ukrainian hacktivist collective known as PhantomCore has been conducting aggressive intrusions against Russian organizations since September 2025, focusing on servers that ru...
Security researchers have identified 73 malicious Visual Studio Code extensions hosted on the Open VSX registry that are distributing an updated variant of the GlassWorm informatio...
Security researchers at Group-IB have uncovered a large-scale smishing operation that combines fake CAPTCHA verification pages with International Revenue Share Fraud (IRSF) and cry...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, signaling a...
The US Department of Justice has announced the indictment of 29 individuals linked to a cyber fraud syndicate operating from Myanmar, charging them with conspiracy to commit wire f...
In the past six months, a surge of AI‑powered phishing campaigns has reshaped the threat landscape, according to an analysis published by Dark Reading. Threat actors are moving awa...
Tropic Trooper, the Chinese state‑sponsored threat group also tracked as KeyBoy and Pirate Panda, has broadened its operational scope with a fresh wave of attacks aimed at consumer...
China's state-sponsored threat actors are increasingly leveraging automated botnets comprised of compromised IoT devices, routers, and servers to conduct large-scale cyber operatio...
According to the latest Dark Reading analysis, the weekly number of cyberattacks directed at African organizations dropped by 22 % over the past year, falling from roughly 5,400 in...
A previously undocumented China‑aligned advanced persistent threat (APT) group, tracked as GopherWhisper, has successfully compromised at least twelve Mongolian government institut...
Security researchers at multiple threat intelligence firms have observed a significant acceleration in The Gentlemen ransomware group's operational tempo and technical capabilities...
A newly identified Chinese advanced persistent threat (APT) group has launched a coordinated cyber‑espionage campaign against major Indian financial institutions and South Korean p...
NIST's National Vulnerability Database (NVD) has historically been the primary source of enriched CVE data, attaching CVSS v3.1 vector strings, severity ratings, affected product C...
Tycoon, a well‑known phishing collective that has long abused two‑factor authentication (2FA) bypass tricks, has quietly shifted to a new attack vector: OAuth 2.0 device‑code phish...
The UK Cabinet Office’s Emerging Technology Cybersecurity Division (ETCD), in close collaboration with the National Cyber Security Centre (NCSC), has publicly released results from...
German authorities have publicly exposed the identity of the notorious hacker known as "UNKN", linking the alias to 31‑year‑old Russian national Daniil Maksimov. Maksimov is allege...
Security researchers at SecureSphere Labs have uncovered a new file‑wiping worm they have named CanisterWorm, attributed to a financially motivated threat actor tracked under the a...
The U.S. Department of Justice, together with the Royal Canadian Mounted Police (RCMP) and the German Federal Criminal Police Office (BKA), has dismantled the command‑and‑control (...
Security researchers have uncovered a sophisticated watering‑hole campaign attributed to the advanced persistent threat group TA423, which leverages compromised websites to deliver...
A coordinated phishing operation attributed to the threat group 0ktapus has ensnared more than 130 organizations across multiple industries, according to researchers at Threatpost....