Advertisement
Abusing Google DoubleClick for DesckVB RAT Delivery — Detection Guide
A new malspam campaign leverages Google DoubleClick redirects to bypass security filters and distribute DesckVB RAT, highlighting trust-based evasion tactics.
Continuous Security Testing: Closing the 345-Day Exposure Gap
Analyze why annual penetration tests leave 345 days of risk and how continuous security validation for financial institutions improves resilience.
Detecting API Discovery Scans for swagger.json: Security Guide
Analysis of automated scans for swagger.json and OpenAPI files. Learn how to secure RESTful APIs against discovery-based attacks and reconnaissance.
AI Cryptanalysis of Historical Ciphers: Implications for Security
Researchers use machine learning to automate the decryption of medieval ciphers, signaling a shift in how legacy encryption and manual schemes are analyzed.
Finance Executive Email Compromise via Native Windows Tools
A monthslong campaign targeted a global stock exchange executive, leveraging native Windows tools for persistence and unauthorized email monitoring.
Evaluating AI Agent Security: 100 Agents Tested for Vulnerabilities
An industry-first evaluation of 100 AI agents highlights critical security gaps in defense and the high impact of potential agentic compromises.
Europol Dismantles 9 IPTV Piracy Groups in Global Crackdown
Law enforcement agencies across 11 countries dismantle 9 organized crime groups involved in illegal IPTV streaming, seizing servers and 100TB of data.
Google Android Scam Detection: Real-Time AI Defense Against Fraud
Google introduces AI-powered Scam Detection for Android, utilizing on-device Gemini Nano to identify fraud patterns and protect users from voice-based phishing.
Kali365 Phishing-as-a-Service Expands to Target AWS and Okta
The FBI-flagged Kali365 phishing kit now targets AWS and Okta via device code phishing, bypassing multi-factor authentication for cloud enterprise accounts.
AI as Security Enabler: CISO Strategies for Modern Defense
Zoom's CISO details AI's role in augmenting security teams, addressing challenges like talent gaps and alert fatigue, and strategic CISO insights.
US Executive Order on AI: Vetting Advanced Models for National Security
Executive Order mandates pre-release vetting of advanced AI models for national security risks, impacting developers and federal oversight strategies.
OpenAI GPT-3.5 Upgrades & Legacy Model Retirement: Security Impact
OpenAI is upgrading GPT-3.5 models and retiring legacy versions. Understand the impact on AI-powered security tools and data processing. Stay informed.
Microsoft Coreutils for Windows: Security and Memory Safety Analysis
Microsoft introduces native Linux Coreutils for Windows via Rust. Analyze the security impact, memory safety benefits, and potential living-off-the-land risks.
Hardening Automatic Tank Gauge Systems Against Cyber Threats
CISA and partners warn of active cyber threats targeting Automatic Tank Gauge (ATG) systems. Learn to secure critical infrastructure assets now.
China's Dual-Method Cyberattack Targets Czech, Taiwan Orgs with Azureveil
Nation-state actors linked to China employ dual-method spear-phishing with Azureveil malware to target Czech and Taiwan organizations for data theft. Understand the TTPs…
DriveSurge: Hijacking Thousands of Sites for ClickFix, FakeUpdate Malware
DriveSurge, a wide-scale IAB operation, hijacks thousands of trusted websites using a malicious TDS, redirecting users to sites distributing ClickFix and FakeUpdate…
Gamaredon Exploits WinRAR CVE-2025-8088 to Target Ukraine
Russian threat actor Gamaredon weaponizes a WinRAR path traversal flaw to deploy GammaWorm and GammaSteel malware against Ukrainian entities.
Handala Brand Evolution: Iran MOIS Shifts to Hybrid Physical Attacks
Iran’s MOIS expands the Handala brand into hybrid operations, combining cyber espionage with physical sabotage targeting U.S. and Israeli interests.
AI Automation and the Shrinking Vulnerability Exploitation Window
Analyze the impact of AI-driven automation on the vulnerability lifecycle and the debate between tooling vs. operational security failures.
AI and the Persistent Limitations of Modern Cryptography
Expert analysis on Bruce Schneier’s thesis regarding why cryptography fails to protect modern networks from AI-driven threats and architectural weaknesses.
Beyond Assume-Breach: The Rise of AI-Native Security Architecture
Explore how AI-native security architectures are replacing traditional assume-breach models with hyper-segmentation and autonomous orchestration.
AI-Driven Zero-Knowledge Threat Actors and the Erosion of Disclosure
AI enables low-skill attackers to automate malware creation and exploit development, significantly reducing the efficacy of traditional responsible disclosure.
Optimizing EDR for Operational Resilience and Threat Detection
Explore how leading organizations optimize EDR deployment to achieve operational resilience against advanced threats and move beyond legacy prevention models.
New Phishing Campaign Exploits SVG Attachments to Evade Filters
Security researchers report a wave of phishing emails using malicious SVG attachments to deliver scripts and bypass email security gateways. Learn how to defend.