Advertisement
Hong Kong National Security Law: Forced Encryption Key Disclosure Risks
Hong Kong's revised National Security Law empowers police to compel individuals, including airport transits, to disclose encryption keys and device passwords.
White House FY2027 Budget Proposes $707 Million CISA Funding Cut
The White House proposes a $707 million reduction to CISA's budget for FY2027, refocusing the agency on federal agency and critical infrastructure protection.
Storm-1175: China-Linked Zero-Day Exploits Deploy Medusa Ransomware
China-linked actor Storm-1175 is weaponizing zero-day and N-day vulnerabilities in perimeter assets to execute high-velocity Medusa ransomware attacks.
German Authorities Identify GandCrab and REvil Ransomware Leaders
German and US authorities identify Russian nationals behind GandCrab and REvil ransomware operations, marking a major step in ransomware attribution.
DPRK Hackers Abuse GitHub Infrastructure for C2 in South Korea
North Korean state-sponsored actors are leveraging GitHub as a command-and-control platform in complex multi-stage attacks targeting South Korean organizations.
Iran-Linked Password-Spraying Targets 300+ Israeli Organizations
Iran-linked threat actors launched coordinated password-spraying attacks against Israeli and UAE Microsoft 365 environments in March 2026.
Advertisement
Managing Shadow AI Risks in Healthcare: Security Governance Guide
Healthcare organizations face rising risks from unsanctioned AI usage. Learn how to secure patient data and implement governance to prevent data leakage.
UAT-10608 Exploits Next.js CVE-2024-34351 via React2Shell Script
Threat actor UAT-10608 is leveraging an automated script to exploit a Next.js SSRF flaw, exfiltrating credentials and environment secrets from web applications.
Google DeepMind Research: Six Web Attack Vectors Against AI Agents
DeepMind researchers reveal how malicious web content can manipulate AI agents, highlighting risks like indirect prompt injection and data exfiltration.
Chrome Zero-Day and Fortinet Exploits: Weekly Threat Intelligence
Intelligence analysis of the latest Chrome zero-day, Fortinet vulnerabilities, and the Axios security breach, including technical remediation for SOC teams.
Multi-OS Attack Defense: Unifying SOC Workflows Across Platforms
Learn how modern threat actors exploit fragmented security silos to move across Windows, Linux, and macOS, and how SOCs can implement unified defenses.
Analyzing the Frequency of Open Redirects in Phishing Campaigns
Examine the technical drivers behind the use of open redirects in phishing delivery and learn strategies for detection and vulnerability remediation.
Google Accelerates Post-Quantum Cryptography Transition for 2029
Google announces a full migration to post-quantum cryptography by 2029 to ensure crypto-agility and defend against future quantum computing threats.
BKA Unmasks REvil Leadership Behind 130 German Ransomware Attacks
Germany's BKA unmasks the leadership of the REvil (Sodinokibi) ransomware group, including the representative UNKN, following a major threat intel investigation.
Germany Doxes UNKN: Identity of REvil and GandCrab Leader Revealed
German authorities identify Daniil Maksimovich Shchukin as UNKN, the lead operator behind the notorious GandCrab and REvil ransomware operations.
QR Code Phishing: SMS Traffic Violation Scams Bypass Mobile Filters
Scammers are using QR codes in SMS traffic violation scams to bypass security filters and steal financial data. Learn how to identify and block quishing.
DPRK Social Engineering Behind $285 Million Drift Hack: Analysis
A deep dive into the six-month DPRK social engineering operation targeting Drift protocol, resulting in a $285 million Solana-based cryptocurrency theft.
LinkedIn Browser Fingerprinting: Privacy Risks of Extension Scanning
LinkedIn is reportedly scanning users for over 6,000 Chrome extensions using browser fingerprinting techniques, raising significant privacy concerns.
BrowserGate: LinkedIn's Stealthy Chrome Extension Scanning and Data Collection
Analysis of 'BrowserGate' reveals LinkedIn's hidden JavaScript scanning over 6,000 Chrome extensions and collecting user device data. Understand the privacy implications.
Cookie-Controlled PHP Web Shells Evade Detection on Linux Servers
Microsoft researchers warn of stealthy PHP web shells on Linux using HTTP cookies for command execution and cron jobs for long-term persistence.
TA416 Targets European Govts with PlugX & OAuth Phishing
China-linked TA416 has resumed targeting European government and diplomatic entities since mid-2025 using PlugX and OAuth-based phishing attacks.
Emerging XR Authentication: Skull Vibrations for Identity
Emerging research suggests skull vibration harmonics from vital signs could serve as a novel authentication method for VR, AR, and MR headsets, offering unique identity…
TeamPCP Supply Chain Attacks Escalate Amidst Hacker Infighting
Runtime Rebel details how TeamPCP's supply chain attacks are leading to breaches, with ShinyHunters and Lapsus$ adding to the chaos.
Recent Cyber Threats: Data Leaks, Android Malware, Critical Infra Ransomware
Analysis of a ChatGPT data leak, the emergence of an Android rootkit, and a ransomware attack impacting a water facility. Essential insights for defenders.