Advertisement
Police Collusion Sustains SE Asian Cybercrime and Scam Centers
Corruption and police collusion in Southeast Asia facilitate a multi-billion dollar cybercrime industry, complicating international law enforcement efforts.
Windows 10 ESU Extended to 2027: Security Implications
Microsoft extends free Windows 10 Extended Security Updates (ESU) for consumers until October 2027. Understand the security implications and planning for end-of-life.
Shopify Shop App Abused for Callback Phishing Attacks
Attackers are exploiting the Shopify Shop app's order tracking features to launch callback phishing attacks, tricking users into installing remote access tools.
ThreatsDay Bulletin: Proxyware, Legacy Flaws, and AI Crime Trends
Analysis of recent cybersecurity threats including smart TV proxyware, a 24-year curl bug, and AI-driven cybercrime trends impacting enterprise security.
Europe's Ransomware Surge: Mitigating Risks for EU Organizations and Suppliers
European organizations and their suppliers are now primary targets for ransomware gangs. Understand the escalating threat and implement critical defenses.
Cal Water Incident: No OT Impact Confirmed After Handala Claims
An investigation revealed no operational technology compromise at Cal Water despite claims by Iranian hacker group Handala to disrupt water supply. Focus on IT/OT…
AI Security Platform Runlayer Raises $30M Series A Funding
Runlayer secures $30 million in Series A funding to develop its secure control layer platform, aiming to fortify AI tools across enterprise environments.
NDR for Incident Response Teams: Richard Bejtlich on Visibility
Richard Bejtlich explains why NDR is essential for security operations to bridge visibility gaps and move beyond high-volume, low-context alert triage.
Analyzing Internet Background Radiation and Automated Scanning Trends
An analysis of automated cybercrime traffic and internet background radiation, detailing how botnets exploit vulnerabilities like CVE-2017-17215.
2026 FIFA World Cup Cyber Threats: Infrastructure & Phishing Analysis
An analysis of the cyber threat landscape for the 2026 FIFA World Cup, detailing infrastructure risks, social engineering, and mitigation strategies.
AI Agent Traps: Information as an Attack Surface for Autonomous Systems
Attackers exploit trusted data sources to deploy AI agent traps, leading to hidden content injections and cognitive state poisoning for autonomous AI systems.
Nathaniel Saavedra Sentenced for 2022 DraftKings Account Takeover
21-year-old hacker 'Snoopy' sentenced to 18 months in prison for the DraftKings cyberattack that compromised 60,000 accounts via credential stuffing in 2022.
DoJ Seizes HuiOne Cloud Account in Cyber Scam Crackdown
US authorities seized a cloud account tied to HuiOne Group and sanctioned Prince Group entities involved in global money laundering and cyber scam operations.
Autonomous Agentic AI Adversaries: Managing Machine-Speed Cyber Threats
The transition to agentic AI adversaries marks the end of human-speed threats. Learn how autonomous agents automate exploit discovery and execution at scale.
2026 World Cup Scams: Detecting SEO Hijacking and Purchase Fraud
Threat actors are using SEO hijacking and compromised domains to scale purchase scams targeting the 2026 FIFA World Cup. Learn how to identify these TTPs.
Linux Process Name Masquerading: Analyzing T1036 Obfuscation
Explore the technical methods behind Linux process name masquerading (MITRE ATT&CK T1036) used by actors like Velvet Ant to evade detection.
Scattered Spider Members Plead Guilty to Transport for London Attack
Two members of Scattered Spider pleaded guilty to the August 2024 Transport for London cyberattack, highlighting the group's social engineering efficacy.
Modern Exposure Validation: Countering the Collapsed Exploit Timeline
Examine how AI-driven exposure validation addresses the shrinking gap between vulnerability disclosure and weaponization to improve security resilience.
Windows 11 KB5095093: New Point-in-Time Restore and Bug Fixes
Microsoft releases KB5095093 for Windows 11 24H2, introducing a critical Point-in-Time restore feature and addressing multiple system-level bugs.
AI Agent Skill Security Bypass: Fake Skill Reached 26,000 Agents
A security firm demonstrated how a fake AI agent skill bypassed marketplace security scans, reaching 26,000 agents, including corporate accounts, highlighting critical…
FortiBleed: 110 Million Credentials Harvested via FortiGate Firewalls
Russian-speaking threat actors harvest 110 million credentials from 430,000 FortiGate firewalls globally. Learn to detect and mitigate FortiBleed tactics.
Scattered Spider Members Plead Guilty in TfL Infrastructure Attack
Two members of the Scattered Spider threat group plead guilty to the 2024 Transport for London hack, exposing risks of identity-based social engineering.
Anthropic Fable 5 Jailbroken: Bypassing AI Guardrails for Malicious Use
Anthropic's Fable 5, a version of Mythos Preview designed with cyberattack prevention guardrails, was jailbroken quickly. This exposes AI model security flaws.
CISO and CIO Role Convergence: Leadership Insights from Carl Froggett
Explore the strategic benefits of merging CISO and CIO roles to improve organizational security posture and operational efficiency in modern enterprises.