Advertisement
NIST NVD Data Enrichment Cutbacks: Implications for Cyber Teams
NIST's reduction in NVD CVE data enrichment poses challenges for cyber teams' vulnerability management. Learn the implications and proposed industry solutions.
Addressing Shadow AI Risks: A Governance and Visibility Imperative
Enterprises face growing risks from unmanaged AI tool usage. This analysis details Shadow AI threats, compliance challenges, and crucial governance strategies.
White House Engages AI Labs on Emerging AI Security Concerns
The White House is engaging leading AI labs like Anthropic to address security of AI models and software, highlighting growing concerns over AI safety and supply chain…
Grinex Crypto Exchange Suffers $13.7M Hack, Blames Intelligence
Kyrgyzstan's Grinex crypto exchange suspended operations after a $13.7M hack. The exchange attributes the breach to Western intelligence agencies, highlighting sector…
Claude Mythos Preview: Anthropic Limits Access to Vulnerability AI
Anthropic restricts Claude Mythos Preview access to critical infrastructure providers due to its advanced capability to exploit zero-day vulnerabilities.
Scattered Spider Arrest and ShowDoc Vulnerability Exploitation
Analysis of the arrest of a Scattered Spider member, active exploitation of ShowDoc vulnerabilities, and the introduction of the Satellite Cybersecurity Act.
Advertisement
Android 17 Privacy Overhaul: Google Blocks 8.3B Malicious Ads
Google announces Android 17 privacy updates and Play policy changes after blocking 8.3 billion ads and 24.9 million fraudulent accounts throughout 2025.
Business Impersonation Fraud: Analyzing Identity Gaps in 2024
Analysis of how attackers exploit identity verification gaps to execute financial fraud and brand impersonation, from shell companies to AI-driven scams.
ZionSiphon Malware Targets Israeli Water Treatment ICS
Security analysis of ZionSiphon, a backdoor malware targeting Israeli desalination and water treatment facilities via ICS vulnerabilities.
Operation PowerOFF Seizes 53 DDoS Domains and 3M Criminal Accounts
Operation PowerOFF disrupts DDoS-for-hire services by seizing 53 domains and exposing 3 million user accounts, marking a major blow to booter service providers.
Public-Private Operational Collaboration for National Cyber Defense
An analysis of why government-private sector operational collaboration is essential for defending critical infrastructure against sophisticated threat actors.
Operation PowerOFF: Global Takedown of 53 DDoS-for-Hire Domains
Law enforcement agencies seized 53 booter domains and identified 75,000 users in the latest phase of Operation PowerOFF targeting the DDoS-as-a-Service market.
Sapphire Sleet's ClickFix: North Korea Targets macOS Users
North Korea-backed Sapphire Sleet is deploying ClickFix malware via fake job offers and phony Zoom updates to steal macOS user credentials and data.
OpenAI Widens GPT-5.4-Cyber Access Following Anthropic Mythos
OpenAI expands access to GPT-5.4-Cyber, a specialized model for defensive security, following Anthropic's Mythos release to aid security analysts.
PowMix Botnet Targets Czech Workers via Randomized C2 Traffic
Researchers uncover the PowMix botnet targeting the Czech workforce with evasive randomized C2 beaconing to bypass network signature detections.
Google Deploys Gemini AI to Combat Malvertising and Brand Fraud
Google expands the use of Gemini LLMs to detect sophisticated ad scams, blocking 5.5 billion ads and countering AI-generated brand impersonation tactics.
Microsoft Defender Zero-Day and 17-Year-Old Excel RCE Exploitation
Analysis of recent threats including a Microsoft Defender zero-day, SonicWall brute-force campaigns, and critical RCE in legacy Microsoft Excel components.
AI-Powered Exploitation: Scaling Enterprise Defense at Machine Speed
As AI models accelerate vulnerability discovery and exploit development, enterprises must transition to automated security operations to mitigate growing risks.
Strategic Human-LLM Interaction: Research into AI Trust and Rationality
New research shows humans attribute higher rationality and cooperation to LLMs in strategic games, impacting trust in automated cybersecurity environments.
REF6598 Exploits Obsidian Plugins to Deploy PHANTOMPULSE RAT
Attackers are targeting finance and crypto sectors by abusing Obsidian plugins to deliver the PHANTOMPULSE RAT via sophisticated social engineering.
Germany Ransomware Surge: How SafePay and Qilin Target Mittelstand
Germany sees a 92% surge in data leaks as ransomware actors like SafePay and Qilin pivot toward the Mittelstand and professional services sectors.
6-Year Ransomware Campaign Targets Turkish SMBs: An Analysis
A persistent six-year ransomware operation has targeted Turkish home users and SMBs, exploiting under-reporting to maintain operational longevity.
DPRK IT Worker Laptop Farms: U.S. Nationals Sentenced for Fraud
Two U.S. residents sentenced for operating laptop farms that enabled North Korean IT workers to defraud Fortune 500 companies using stolen identities.
UAC-0247 Targets Ukrainian Healthcare via Data-Theft Malware
UAC-0247 is targeting Ukrainian clinics and government entities using malware designed to steal data from WhatsApp and Chromium-based browsers.