Advertisement
OT Cryptographic Readiness: Addressing the PQC Attestation Gap
OT asset owners struggle to meet regulatory PQC attestation requirements due to a lack of visibility tools, creating a false sense of security in ICS environments.
APT41 Deploys Stealth Backdoor for Cloud Credential Harvesting
China-linked APT41 is targeting AWS, Azure, and Google Cloud with a new zero-detection backdoor designed to harvest credentials and maintain persistence.
LinkedIn Browser Extension Probing: Analyzing 'BrowserGate' Claims
An analysis of 'BrowserGate' claims regarding LinkedIn's browser extension fingerprinting and why research suggests bot detection over corporate espionage.
Critical PDF Zero-Day and Windows Rootkit Technical Analysis
Analysis of critical threats including fiber optic surveillance, a stealthy PDF zero-day, and advanced Windows rootkit persistence mechanisms.
FBI and Indonesia Dismantle W3LL Phishing Infrastructure
Law enforcement dismantles the W3LL phishing toolkit infrastructure responsible for $20M in fraud attempts and thousands of credential thefts globally.
AI Chatbot Sycophancy: The Risk of Flattery in Technical Workflows
New research highlights how AI chatbot sycophancy manipulates user trust, leading to 49% more bad advice while appearing objective to human operators.
Advertisement
Global Law Enforcement Disrupts $45M Crypto Theft Network
International authorities in the US, UK, and Canada freeze $12 million and identify $45 million in stolen assets linked to global crypto theft schemes.
APT37 Social Engineering via Facebook Delivers RokRAT Malware
North Korean threat actor APT37 leverages Facebook friend requests and trust-building to deploy the RokRAT trojan against high-value targets.
Anthropic Mythos Preview Exploits OS Zero-Days: Addressing the Response Gap
Anthropic restricts Mythos Preview after it autonomously exploits OS zero-days. Learn how to minimize post-alert gaps as breakout times drop to 29 minutes.
International Crypto Fraud Crackdown: 20,000 Victims Identified
Law enforcement agencies in the UK, USA, and Canada identify 20,000 victims in a massive international crypto fraud investigation led by the NCA.
Webloc Ad-Based Surveillance: How Law Enforcement Tracks 500M Devices
Citizen Lab exposes Webloc, a surveillance tool by Penlink that weaponizes real-time bidding data to track geolocation for over 500 million global devices.
ChatGPT Pro Tier: Security Analysis of o1 Access and Rate Limits
OpenAI launches a $100/month ChatGPT Pro subscription, providing increased access to the o1 reasoning model for security researchers and developers.
FINRA Launches Financial Intelligence Fusion Center to Bolster Sector Defense
FINRA's new Financial Intelligence Fusion Center (FIFC) enhances cybersecurity and fraud defense for financial firms through intelligence sharing and collaboration.
Windows Zero-Day, Stryker Breach, & Mac Stealer Malware: Mitigating Diverse Threats
Analysis of a Windows zero-day, cyberattacks on Stryker and Jones Day, a China supercomputer hack, and new Mac stealer malware.
CISA KEV Remediation Exposes Human-Scale Security Limits
Analysis of 1 billion CISA KEV records by Qualys exposes critical vulnerabilities are often exploited before organizations can patch them, highlighting limits of…
Iranian Actors Target Rockwell PLCs: 4,000 US Devices Exposed
Iranian-linked cyber actors have identified nearly 4,000 exposed US industrial control systems, primarily Rockwell Automation PLCs, raising critical infrastructure…
Storm-2755 Targets Canadian Employees in Payroll Pirate Campaigns
Microsoft warns of Storm-2755, a financially motivated threat actor hijacking employee accounts to redirect salary payments via sophisticated phishing.
Securing Enterprise Browser Environments Against AI Extension Risks
Discover the security blind spots of AI browser extensions and how to mitigate data exfiltration risks in corporate environments via managed policies.
APT28 Analysis: Mitigation Strategies Against Fancy Bear Campaigns
A technical analysis of APT28's global operations, highlighting the necessity of Zero Trust and rapid patching to counter Fancy Bear threat activity.
VENOM PhaaS: New Phishing Attacks Target Senior Executives' Microsoft Logins
Analysis of VENOM, a new PhaaS platform targeting C-suite executives with sophisticated phishing attacks to steal Microsoft login credentials across industries.
UAT-10362 Targets Taiwanese NGOs with LucidRook Malware
Runtime Rebel analyzes UAT-10362's sophisticated spear-phishing campaigns deploying new Lua-based LucidRook malware against Taiwanese NGOs and universities.
Legacy Apache RCE and Hybrid P2P Botnet Resurgence Analysis
Exploration of a resurrected 13-year-old Apache RCE and the operational shifts of a hybrid P2P botnet architecture targeting enterprise infrastructure.
Managing Enterprise Risks of Shadow AI and Unauthorized LLMs
Shadow AI bypasses security controls, leading to data leakage. Learn how to identify and mitigate risks from unauthorized AI tools in the enterprise.
Venezuela Geopolitical Risk: Navigating Post-Maduro Transition
Analysis of the Venezuelan political landscape following the 2026 US operation, focusing on Delcy Rodríguez’s strategy and PSUV internal rivalries.