Advertisement
Google Sues Outsider Enterprise Over Gemini-Powered Phishing-as-a-Service
Google takes legal action against Outsider Enterprise, a Chinese cybercrime network using Gemini AI to automate sophisticated phishing campaigns against global users.
Keyfactor's $1B+ Investment: Addressing AI & Post-Quantum Threats
Keyfactor secures over $1 billion to advance its machine identity and PKI platform, preparing enterprises for future AI-driven and post-quantum cryptographic challenges.
Building the Agentic SOC: AI's Role in Modern Security Operations
Explore how AI is transforming Security Operations Centers (SOCs) into 'Agentic SOCs', enhancing threat detection, automating investigations, and improving response.
RCS Service Discovery via DNS NAPTR Records Explained
Understanding how Rich Communication Services (RCS) relies on DNS NAPTR records for service discovery and connection establishment, and its security implications for…
France Mandates Quantum-Safe Encryption by 2027
France's ANSSI will stop certifying non-quantum-safe encryption products from 2027, compelling government and critical operators to adopt post-quantum solutions.
JadePuffer: First LLM-Driven Ransomware Leverages Langflow Flaw
Analysis of JadePuffer, the first reported LLM-driven ransomware, which exploited a Langflow vulnerability to exfiltrate database data and encrypt systems.
Business-Aligned Risk Management: Bridging Security & Enterprise Goals
Learn how organizations can transition from technical, isolated security data to a continuous, business-aligned risk management lifecycle, enhancing security outcomes.
EtherRAT Malware via Microsoft Teams IT Support Impersonation
Threat actors leverage fake IT support calls on Microsoft Teams to deploy EtherRAT malware, gaining initial access to corporate networks.
Job Interview Phishing Targets Google Accounts of Marketing Professionals
A new phishing campaign impersonates 30+ major brands to lure marketing professionals into fake job interviews, aiming to steal their Google account credentials.
Iran-Linked Hackers Deploy New Cavern C2 Against Israeli Targets
Iranian state-sponsored threat actors are using a novel modular C2 framework, Cavern (Cav3rn), to compromise Israeli IT and government entities. Learn detection and…
SkillCloak: Malicious AI Agent Skills Evade Static Code Scanners
Researchers at HKUST reveal SkillCloak, a technique using self-extracting packing to allow malicious AI agent skills to bypass static security analysis.
Flipper Zero Transitions to Community-Led Firmware Development Model
Flipper Devices shifts firmware development to a community-centric model, raising new considerations for supply chain integrity and security update lifecycles.
Kairos Group Extorts $1M from US Government in Data-Theft Campaign
A US government entity paid $1M to the Kairos group to prevent a data leak, signaling a shift from traditional ransomware to pure data-theft extortion.
Open Source Zero-Days and ATM Jackpotting: Analysis of Recent Threats
Legal actions against ATM jackpotting crews and hacktivists highlight ongoing risks in open-source security and financial infrastructure.
NetNut Residential Proxy Disrupted: 2M Android Devices Cut Off
A joint operation disrupted NetNut, a residential proxy network leveraging over 2 million compromised Android devices, including smart TVs and streaming boxes.
ARToken PhaaS Exposes EvilTokens' M365 Phishing Toolkit
ARToken PhaaS, an affiliate of EvilTokens, offers advanced Microsoft 365 phishing capabilities, including MFA bypass. Learn about its TTPs and how to defend.
Flock Safety's 'Vehicle Fingerprint' Tech: Covert Vehicle Surveillance
Flock Safety's 'Vehicle Fingerprint' technology allows law enforcement to track vehicles without license plates, raising significant privacy concerns and expanding…
Chinese LLMs Reshape Cyber Defense: Attacker Advantage
Chinese Large Language Models (LLMs) are poised to shift the cyber defense balance, potentially giving attackers an advantage. Understand the implications.
Agentic AI Automates Ransomware Attacks via Langflow Exploitation
Agentic AI agents demonstrate automated multi-stage ransomware attacks using Langflow, raising concerns for AI development security and future threat automation.
Pegasus Spyware Targets MEP Investigating Surveillance
Former European Parliament Member Stelios Kouloglou was repeatedly targeted with Pegasus spyware while investigating surveillance tools. Learn about the attack and…
Armored Likho Leverages BusySnake Stealer Against Critical Sectors
Undocumented threat actor Armored Likho targets government and electric power sectors in Russia, Brazil, and Kazakhstan with BusySnake Stealer. Learn detection and…
Peter Stokes Extradition: Impact on Scattered Spider Operations
Technical analysis of the extradition of Peter Stokes and the persistent TTPs of the Scattered Spider threat actor group targeting enterprise networks.
Google Disrupts NetNut Malicious Residential Proxy Network
Google, in coordination with the FBI and Lumen, has significantly disrupted the NetNut residential proxy network, impacting millions of compromised devices.
Cybersecurity Mission Creep: Policy Expansion & Governance Risks
Examines how policy issues like misinformation, social media safety, and antitrust are being 'cybersecuritized,' leading to urgent, exceptionalist governance responses…