Skip to content

Cybersecurity News & Advisories

Aggregated advisories, threat intel, and news from 23+ trusted sources · Updated every 4 hours RSS
23 / 23 active
Advisory
Threat Intel
Research
News
Media
Podcast
477 articles Updated 04 Jun 2026 20:40 UTC
News The Hacker News

Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public

CVE-2026-20230 ↗ Vuln Research

Cisco has patched a bug in Unified Communications Manager that lets an unauthenticated attacker on the network write files to the box and, from there, climb to root. It is tracked as CVE-2026-20230, and proof-of-concept…

↗ Open article ↗ CVE feed
News The Hacker News

Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories

Research

A security researcher found a flaw in Anthropic's Claude Code GitHub Action that let an attacker take over vulnerable public repositories running it, with nothing more than a single opened GitHub issue. Because…

↗ Open article
News The Hacker News

Agentic AI Is Transforming Defense, But Only Secure IT Infrastructure Will Maximize It

Over the past several weeks, the cybersecurity community has been reminded how quickly frontier and agentic AI in defense networks can challenge our assumptions. When Anthropic's Claude Mythos model was made available…

↗ Open article
News Cyber Security News

Proofpoint Warns TA4922 Deploys Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT

Malware

A sophisticated cybercrime group known as TA4922 is raising alarms across the global security community. The group has been deploying a growing arsenal of malware, including Atlas RAT, RomulusLoader, SilentRunLoader…

↗ Open article
News The Hacker News

ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New Stories

It got stupid again. The internet still feels held together with tape. Bad plugins, old bugs, fake tools, trusted apps doing shady things. Same mess, new wrapper. And now the weird stuff is normal. Forums go down and…

↗ Open article
Research Rapid7 Blog

How the “Swiss Cheese” model can help you choose the right MDR provider

Not all managed detection and response (MDR) solutions are equal. Finding the differences between vendors can be quite hard, and then understanding how those differences impact your business can be even harder. For…

↗ Open article
News Cyber Security News

Weaponized ChatGPT Download Site Delivers Malware Via Sponsored Search Results

Vuln Malware Research

A new malvertising campaign is exploiting ChatGPT’s popularity by promoting a weaponized fake download site via sponsored search results, delivering malware to both Windows and macOS users. Security researchers from…

↗ Open article
News Cyber Security News

Kali365 PhaaS Operation Expands Beyond Microsoft 365 to Target Okta and MAX Messenger

Phishing

A new and fast-growing phishing operation is making waves in the cybersecurity world, and it is moving far beyond its original targets. Kali365, a phishing-as-a-service (PhaaS) platform first spotted in April 2026, was…

↗ Open article
News Cyber Security News

Payouts King Ransomware Evades EDR With Obfuscation and Direct System Calls

Ransom

A new ransomware group known as Payouts King has quietly been building a reputation since it first appeared in April 2025. While it spent most of last year flying under the radar, early 2026 brought a noticeable spike…

↗ Open article
News The Hacker News

China-Linked TA4922 Expands Phishing Attacks to U.K., Germany, Italy, and South Africa

Phishing

A new China-linked cybercrime group known as TA4922 has expanded its targeting focus to target European organizations in the U.K., Germany, Italy, and South Africa. These efforts have been complemented by a "rapid…

↗ Open article
News Cyber Security News

Hackers Actively Exploiting WordPress Plugin Vulnerability to Inject Malicious PHP Code

Vuln

Hackers are actively exploiting a critical remote code execution (RCE) vulnerability in the Everest Forms Pro WordPress plugin, allowing unauthenticated attackers to inject and execute arbitrary PHP code on vulnerable…

↗ Open article
Advisory CISA Alerts & Advisories

NAVTOR NavBox

Vuln

View CSAF Summary Successful exploitation of this vulnerability could allow a local attacker to gain unauthorized access to SOAP methods, resulting in a disruption of operations. The following versions of NAVTOR NavBox…

↗ Open article
Advisory CISA Alerts & Advisories

Hitachi Energy MACH HiDraw

Vuln

View CSAF Summary Hitachi Energy is aware of a buffer overflow vulnerability that affects MACH HiDraw product versions listed in this document. Successful exploitation of this vulnerability could lead to a buffer…

↗ Open article
Advisory CISA Alerts & Advisories

Hitachi Energy ITT600 Explorer

Vuln DoS

View CSAF Summary Hitachi Energy is aware of vulnerabilities that affect ITT600 Explorer product versions listed in this document. These vulnerabilities can be exploited to carry out Denial of Service (DoS) attack on…

↗ Open article
Advisory CISA Alerts & Advisories

B&R PPT30 Operating System

Vuln

View CSAF Summary B&R is aware of a vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploits this vulnerability could make the OPC-UA server of the product…

↗ Open article
Advisory CISA Alerts & Advisories

Hitachi Energy RTU500

Vuln

View CSAF Summary Hitachi Energy is aware of vulnerabilities that affect RTU500 product versions listed in this document. If exploited, these vulnerabilities primarily impact product availability, with potential…

↗ Open article
News Cyber Security News

Teams and Google Drive Leveraged to Compromise Systems Within 20 Minutes

Malware

Hackers are increasingly abusing trusted enterprise platforms such as Microsoft Teams and Google Drive to deploy stealthy remote access malware, with a newly observed campaign leveraging social engineering and…

↗ Open article
Threat Intel Malwarebytes Labs

Travel scams are everywhere. Here’s how to avoid them

Planning a holiday should be exciting, fun, and not a cybersecurity risk. But booking flights, hotels, and rental properties often means sharing sensitive personal and financial information across multiple platforms…

↗ Open article
News The Hacker News

FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads

Malware Research

Cybersecurity researchers have shed light on a macOS malvertising campaign codenamed Operation FlutterBridge that spreads a new backdoor called FlutterShell. According to Palo Alto Networks Unit 42, the campaign is said…

↗ Open article
Media Schneier on Security

Hacking Meta’s AI Chatbot

Hackers are convincing Meta’s AI support chatbot to let them take over other peoples’ accounts: A video posted on X showed the step-by-step process to hack someone’s Instagram account. The hacker allegedly used a VPN to…

↗ Open article
News Cyber Security News

Comodo Internet Security 0-Day Vulnerability Lets Attacker Crash the User’s Windows System

Vuln

An unpatched zero-day vulnerability in Comodo Internet Security’s firewall driver, Inspect.sys, after receiving no response from the vendor following multiple disclosure attempts. The vulnerability, dubbed ComoDoS…

↗ Open article
News The Hacker News

Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS

Malware Research

Cybersecurity researchers have flagged a large-scale operation that impersonates open-source and freeware projects to funnel unsuspecting users through a Traffic Distribution System (TDS) and deliver malware families…

↗ Open article
News The Hacker News

Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five Months

Unknown attackers spent at least five months inside the Outlook mailbox of a senior executive at a major global stock exchange, copying the inbox out in small, repeated batches and routing it through Dropbox and…

↗ Open article
News Cyber Security News

Cisco Unified Communications Manager Vulnerability Exposed Along With PoC Exploit Code

CVE-2026-20230 ↗ Vuln Research

Cisco has disclosed a critical server-side request forgery (SSRF) vulnerability in its Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (SME). Tracked as CVE-2026-20230, with…

↗ Open article ↗ CVE feed
Threat Intel Malwarebytes Labs

Meta’s AI support bot happily handed Instagram accounts to hackers

Customer service chatbots have one job: get the user what they’re asking for without bothering a human. Meta’s new AI support assistant took that brief a little too seriously. Over the past few months, attackers have…

↗ Open article
News Cyber Security News

CISA Warns of Android Framework Integer Overflow Vulnerability Exploited in Attacks

CVE-2025-48595 ↗ Vuln

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a newly identified Android Framework vulnerability, tracked as CVE-2025-48595 , to its Known Exploited Vulnerabilities (KEV) catalog, warning…

↗ Open article ↗ CVE feed
News Cyber Security News

Hackers Use Fake Chrome Web Store Copyright Notices to Steal Google Credentials

Phishing

A new phishing campaign is targeting Chrome extension developers using fake copyright removal notices that look like official messages from the Chrome Web Store. The scam tricks developers into entering their Google…

↗ Open article
News The Hacker News

DoJ Disrupts Southeast Asia Crypto Fraud Networks, Freezes $3.8 Million in Assets

Crypto

The U.S. Department of Justice (DoJ) on Wednesday announced the results of a sweeping action undertaken by government authorities and private sector companies to combat cyber-enabled and cryptocurrency fraud targeting…

↗ Open article
News Bleeping Computer

CISA warns of cyberattacks targeting fuel tank monitoring systems

CISA, the FBI, the NSA, the Department of Energy, and other US government partners are warning that hackers are targeting internet-exposed automatic tank gauge (ATG) systems used to monitor fuel and liquid storage tanks…

↗ Open article
News The Hacker News

WhatsApp, Slack Notifications Could Hijack Google Gemini on Android

A single poisoned notification from WhatsApp, Slack, SMS, Signal, Instagram, or Messenger could have hijacked Google Gemini's voice assistant on Android and made it open a victim's connected windows, fake a message from…

↗ Open article
Threat Intel Malwarebytes Labs

We found this fake-invoice campaign while scammers were still building it

A new batch of fake payment invoices is being staged right now, and we caught the campaign while it was still being put together. The emails impersonate PayPal, Amazon, and Geek Squad, and others, and they all share one…

↗ Open article
News The Hacker News

One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens

Research

Cybersecurity researchers have disclosed a one-click attack via Microsoft Visual Studio Code (VS Code) that makes it possible to steal a user's GitHub token. "Just by clicking a link, it's possible for an attacker to…

↗ Open article
News The Hacker News

Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)

CVE-2026-23479 ↗ Vuln

Redis has patched a use-after-free in its blocking-client code that lets an authenticated user run arbitrary OS commands on the machine hosting the database. The flaw was found by an autonomous AI tool built to hunt…

↗ Open article ↗ CVE feed
News The Hacker News

CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog

CVE-2026-45247 ↗ Vuln

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical flaw impacting Mirasvit Cache Warmer, a popular Magento full-page cache extension, to its Known Exploited Vulnerabilities…

↗ Open article ↗ CVE feed
News The Hacker News

Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT

Malware Research

Cybersecurity researchers have flagged a new malspam campaign that makes use of Google's DoubleClick domain as a way to evade detection and ultimately deliver a remote access trojan (RAT) named DesckVB RAT. "Before the…

↗ Open article
Research Rapid7 Blog

A Day in the Life of an MDR Analyst: Inside the Modern SOC

What actually happens inside a SOC when an incident unfolds? Most teams see the alerts and the outcomes, but the decision-making in between is often less visible. At the Rapid7 2026 Global Cybersecurity Summit, the…

↗ Open article
News The Hacker News

Beyond the Zero-Day: See Your Network Like an Attacker | Webinar with HD Moore

Vuln Breach

Assume the breach. Zero-days keep shipping, AI is writing exploits faster than anyone patches, and "patch everything in time" stopped working years ago. Stop betting the org on winning that race. You don't control which…

↗ Open article
News The Hacker News

Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag

A development flag left switched on in production builds of several Microsoft 365 Android apps disabled the check that limits account-token sharing to trusted Microsoft apps. Any other app on the same phone could ask…

↗ Open article
Research SANS Internet Storm Center

Continuing Scans for swagger.json, (Wed, Jun 3rd)

Enterprise applications often still use complex standards like SOAP for web services. The big advantage of SOAP is its tight and extensive standards, which enable interoperability across an enterprise governed by web…

↗ Open article
Threat Intel Malwarebytes Labs

Keep getting calls from questionable numbers? Meet Scam Number Check

Have you ever gotten a phone call and had a gut feeling that those random digits looked extra suspicious? It happens to millions of people every day. While many people have trained themselves to ignore such calls, they…

↗ Open article
Advisory CISA Alerts & Advisories

CISA Adds One Known Exploited Vulnerability to Catalog

CVE-2026-45247 ↗ Vuln

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-45247 Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data…

↗ Open article ↗ CVE feed
News The Hacker News

Shrinking the IAM Attack Surface through Identity Visibility and Intelligence Platforms (IVIP)

The Fragmented State of Modern Enterprise Identity Enterprise IAM is approaching a breaking point. As organizations scale, identity becomes increasingly fragmented across thousands of applications, decentralized teams…

↗ Open article
Research Trail of Bits

The sorry state of skill distribution

Public skill marketplaces are being flooded with malicious skills that steal credentials, exfiltrate data, and hijack agents. In response, a segment of the security industry released skill scanners, a new family of…

↗ Open article
News The Hacker News

Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes

CVE-2026-33829 ↗ Vuln Research

Cybersecurity researchers have disclosed details of an unpatched issue that could be exploited to disclose a user's NTLMv2 hash to the attacker. Like in the case of CVE-2026-33829, which impacted the Windows Snipping…

↗ Open article ↗ CVE feed
Threat Intel Malwarebytes Labs

Infostealers are becoming the go-to phishing payload

Phishing

Phishing has changed. Slowly but surely, cybercriminals are turning to infostealers instead. Traditional phishing hasn’t gone away. Far from it. But many attackers are no longer focused solely on tricking victims into…

↗ Open article
Advisory Microsoft Security

CVE-2023-27043 The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after verifying receipt of e-mail to a specific domain (e.g., only @company.example.com addresses may be used for signup). This occurs in email/_parseaddr.py in recent versions of Python

CVE-2023-27043 ↗
↗ Open article ↗ CVE feed
News The Hacker News

New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare

Vuln DoS Research

Cybersecurity researchers have discovered a remote denial-of-service exploit that affects major web servers, including NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora. The vulnerability has been…

↗ Open article
News The Hacker News

Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content

Malware Research

Cybersecurity researchers have flagged a new campaign targeting Minecraft players via YouTube to spread malware capable of gaining control of victims' systems. The Minecraft-focused malware-as-a-service (MaaS) campaign…

↗ Open article
News The Hacker News

Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited

Vuln

Google on Monday released patches for 124 security vulnerabilities impacting its Android operating system for the month of June 2026, including one high-severity flaw in the Framework component that has come under…

↗ Open article
Threat Intel Malwarebytes Labs

These convincing copyright notices are designed to steal Google logins

A new scam is targeting people who publish Chrome extensions. The scam arrives as an official-looking “copyright removal request” claiming your extension is about to be removed from the Chrome Web Store and that you…

↗ Open article
News The Hacker News

Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine

Vuln Malware Breach

The Russian hacking group known as Gamaredon has been attributed to the continued exploitation of a WinRAR vulnerability to deliver multiple malware families aimed at data theft and propagation. Per Sekoia, the activity…

↗ Open article
News The Hacker News

Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation

CVE-2024-21182 ↗ Vuln

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of…

↗ Open article ↗ CVE feed
Advisory CISA Alerts & Advisories

CISA and Partners Urge Hardening Automatic Tank Gauge Systems

CISA and Partners Urge Hardening Automatic Tank Gauge Systems Overview The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), the National Security Agency (NSA), the…

↗ Open article
Advisory CISA Alerts & Advisories

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CVE-2022-0492 ↗ CVE-2025-48595 ↗ Vuln

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2022-0492 Linux Kernel Improper Authentication Vulnerability CVE-2025-48595…

↗ Open article ↗ CVE feed
News The Hacker News

AI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It

Vuln

AI-driven exploitation timelines are rapidly shrinking, and they are not going to stop shrinking. Vulnerabilities are being discovered, reproduced, and weaponized faster than ever in the history of enterprise security…

↗ Open article
Media Schneier on Security

The Intersection of Encryption and AI

As part of their 20th Anniversary celebration, Dark Reading asked five cybersecurity industry leaders who wrote blogs or columns for them over the years to select their favorite piece and share their reflections on the…

↗ Open article
Media Schneier on Security

Microsoft Threatening Security Researcher

Vuln Research

An anonymous security researcher called “Nightmare Eclipse” has been publishing a series of significant security exploits against Microsoft Windows—including one that breaks BitLocker. Microsoft has threatened legal…

↗ Open article
Threat Intel Any.Run Malware Analysis

From Fake Purchase Orders to Remote Access: Analyzing the JS.MonoGlyphRAT Threat to US Enterprises

Malware Research

A previously unidentified cyberattack is quietly spreading through US businesses — and most security tools are not catching it. Researchers at ANY.RUN have identified a new backdoor called JS.MonoGlyphRAT, an advanced…

↗ Open article
News The Hacker News

How Leading Organizations Are Turning EDR Into Operational Resilience

Most organizations now recognize that endpoint protection alone is no longer sufficient. That's why adoption of endpoint detection and response (EDR) has accelerated rapidly in recent years. Organizations understand…

↗ Open article
Threat Intel Malwarebytes Labs

23andMe exposed genetic information of millions, lawsuit says

Breach

California has sued the former shell of DNA testing company 23andMe over alleged security failures and misleading statements surrounding its 2023 data breach. On May 27, 2026, Attorney General Rob Bonta filed suit in…

↗ Open article
News The Hacker News

Pakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAT

Phishing Malware Research

Cybersecurity researchers have disclosed details of a spear-phishing campaign likely undertaken by the Pakistan-aligned SideCopy group targeting Afghanistan's Ministry of Finance with an open-source remote access trojan…

↗ Open article
Threat Intel Malwarebytes Labs

Fake virus alerts are invading mobile games

Sometimes it happens. You’re happily playing a game on your phone or laptop when suddenly alarms pop up out of nowhere: “Your device is infected!” “Your iCloud is full!” “Your account is restricted for watching porn!”…

↗ Open article
Research SANS Internet Storm Center

New Wave Of Phishing Emails with SVG Files, (Tue, Jun 2nd)

Phishing

For a few days, my SANS ISC mailbox is flooded with emails that delivers SVG files. An SVG ("Scalable Vector Graphic") is a web-friendly vector file format used for graphics and icons. No URL in the body, just “an…

↗ Open article
Podcast Darknet Diaries

175: Bayrob

Malware

It started with a fake car listing on eBay. What looked like a simple online scam quietly grew, over more than a decade, into one of the most sophisticated cybercrime operations the FBI had ever traced. Custom malware…

↗ Open article
News The Hacker News

Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded

Password manager Dashlane has disclosed that "fewer than" 20 users on the personal subscription plan had their encrypted vaults downloaded following a brute-force attack launched by an unknown party. On May 31, 2026…

↗ Open article
News The Hacker News

Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

Malware Breach

A new Mini Shai-Hulud supply chain attack campaign, codenamed Miasma, has compromised @redhat-cloud-services packages to steal credentials and secrets from developer machines and deliver a self-propagating worm. "This…

↗ Open article
News Krebs On Security

Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend, after instructions began circulating on…

↗ Open article
Media Schneier on Security

Vulnerability Disclosure in the Age of AI

Vuln

New article: “ Responsible Disclosure in the Age of AI: A Call for Urgent Action ,” by Melissa Hathaway. Abstract: Artificial intelligence is fundamentally reshaping the balance between vulnerability discovery and…

↗ Open article
Threat Intel Malwarebytes Labs

Fake BlueWallet steals passwords, accounts, and crypto from Macs

Breach Crypto

A fake website impersonating BlueWallet (a real Bitcoin wallet) is targeting Mac users with a simple but effective attack. BlueWallet itself has not been compromised. Instead, cybercriminals have stolen the name and…

↗ Open article
News The Hacker News

⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More

Vuln Phishing

Monday hit like a cron job with anger issues. A busted auth path here, a repo-side faceplant there, some "patched-ish" thing already getting chewed on in the wild, and then the usual bonus round: poisoned dev tools…

↗ Open article
Research Rapid7 Blog

CVE-2026-0826: Critical unauthenticated stack buffer overflow in HP Poly VVX and Trio VoIP Phones (FIXED)

CVE-2026-0826 ↗ Vuln Research

Overview Rapid7 Labs conducted a zero-day research project against an HP Poly VVX 450 Voice over Internet Protocol (VoIP) phone. This research resulted in the discovery of a critical unauthenticated stack-based buffer…

↗ Open article ↗ CVE feed
Research Rapid7 Blog

CVE-2026-0826: How an Old Bug Can Feed AI-Powered Impersonation

CVE-2026-0826 ↗

One of the more persistent myths in security is that old bug classes become old problems. They don’t. They just show up in different places, under different conditions, and usually at the exact moment we’ve convinced…

↗ Open article ↗ CVE feed
Advisory CISA Alerts & Advisories

CISA Adds One Known Exploited Vulnerability to Catalog

CVE-2024-21182 ↗ Vuln

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2024-21182 Oracle WebLogic Server Unspecified Vulnerability This type of…

↗ Open article ↗ CVE feed
News The Hacker News

China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan

APT

A new cyber espionage campaign codenamed Operation Dragon Weave has been observed targeting officials and citizens in the Czech Republic and Taiwan to deliver an AdaptixC2 agent. According to Seqrite Labs, targets of…

↗ Open article
News The Hacker News

The Security Growth Platform: Why MSPs Are Moving Beyond vCISO Tools

Three years ago, the practical question for an MSP building a cybersecurity practice was which "vCISO platform" to buy. The term was good shorthand for the work at the time: assessments, advisory, reporting, maybe a…

↗ Open article
News The Hacker News

OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack

Research

Cybersecurity researchers have disclosed details of a new malicious supply chain campaign that's targeting developers using OpenAI Codex through a legitimate-looking remote web UI. The tool, named codexui-android, is…

↗ Open article
News The Hacker News

Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts

Vuln

Threat actors are attempting to actively exploit a critical security flaw impacting WP Maps Pro, a WordPress plugin that has had over 15,000 sales on the Envato Market, to create malicious administrator accounts on…

↗ Open article
Threat Intel Malwarebytes Labs

Your phone called. It needs a cleanup

Does it sometimes take your phone a few minutes to accomplish one simple task? That can be wildly frustrating. But you’re in luck, because we’ve got a free tool that scans your phone for leftover files, temporary data…

↗ Open article
Research Rapid7 Blog

Rapid7 and Exclusive Networks Expand Partnership Across the Nordics

Building stronger cybersecurity outcomes together The cybersecurity landscape across the Nordics is evolving rapidly. Organizations are facing increasing pressure to modernize security operations, reduce complexity, and…

↗ Open article
Threat Intel Malwarebytes Labs

A week in security (May 25 – May 31)

Last week on Malwarebytes Labs: Payment apps are watching what you say (Lock and Code S07E11) Scammers pretending to be Microsoft had help from US executives 700+ education and tech websites hijacked in huge ClickFix…

↗ Open article
Threat Intel Malwarebytes Labs

Payment apps are watching what you say (Lock and Code S07E11)

This week on the Lock and Code podcast… In the United States today, you can have your bank account closed, your credit cards cancelled, and your online payments revoked for any number of crimes, like funding terrorism…

↗ Open article
News The Hacker News

Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices

Malware

Dutch authorities have announced the takedown of a botnet that enslaved millions of infected devices, including computers, tablets, smartphones, and IoT devices, to carry out malicious attacks. The bot network, per the…

↗ Open article
News The Hacker News

PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

CVE-2026-0257 ↗ Vuln

Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-0257 (CVSS…

↗ Open article ↗ CVE feed
Media Schneier on Security

Friday Squid Blogging: Another Squid

Someone named “Squid” seems to be a “ West Country legend .” As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.

↗ Open article
Research Rapid7 Blog

Metasploit Wrap Up 05/29/2026

More Linux LPEs Hark the age of the Linux LPE has arrived. This week’s release follows up on recent work bringing new Linux LPEs to Metasploit users. Copy Fail seemed to have kicked off a trend of similar bugs and hot…

↗ Open article
News The Hacker News

ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface

Vuln Phishing Research

Cybersecurity researchers have disclosed details of a vulnerability in OpenAI ChatGPT that leverages the artificial intelligence (AI) assistant's implicit trust in Markdown links and images to trigger prompt injections…

↗ Open article
Research Rapid7 Blog

Rapid7 Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257)

CVE-2026-0257 ↗ Vuln

Overview On May 13, 2026, Palo Alto Networks published a security advisory for CVE-2026-0257, a medium severity authentication bypass affecting PAN-OS and Prisma Access when a specific configuration is present…

↗ Open article ↗ CVE feed
News The Hacker News

Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit

CVE-2026-39987 ↗ Vuln APT

An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining initial access following the exploitation of a publicly-accessible Marimo network…

↗ Open article ↗ CVE feed
Threat Intel Malwarebytes Labs

Signal users targeted in backup-stealing phishing attacks

Phishing

A new phishing campaign is targeting Signal users by attempting to steal their backup recovery keys to access encrypted message archives. The attack is initiated by a text message pretending to come from Signal Support…

↗ Open article
Advisory CISA Alerts & Advisories

CISA Adds One Known Exploited Vulnerability to Catalog

CVE-2026-0257 ↗ Vuln

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-0257 Palo Alto Networks PAN-OS Authentication Bypass Vulnerability This type…

↗ Open article ↗ CVE feed
News The Hacker News

New Russia-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks

APT

A previously undocumented threat actor dubbed GREYVIBE has been attributed to ongoing and persistent attacks targeting Ukraine and Ukraine-related entities since at least August 2025. GREYVIBE, per WithSecure, is…

↗ Open article
News The Hacker News

What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks

Shadow AI used to mean employees pasting things they shouldn't into ChatGPT. It now means something bigger: employees building full applications with AI, wiring them into production systems, and publishing them on the…

↗ Open article
News The Hacker News

Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets

Research

Cybersecurity researchers have discovered a malicious NuGet package that masquerades as a C# software development kit for Sicoob, one of Brazil's largest cooperative financial systems, to siphon client IDs and PFX…

↗ Open article
News The Hacker News

Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels

APT

The North Korean state-sponsored threat actor known as Kimsuky (aka Velvet Chollima) has been attributed to a fresh set of cyber attacks targeting South Korean military and corporate entities through March and April…

↗ Open article
News The Hacker News

Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code

Vuln

A critical security vulnerability has been disclosed in Gogs, a popular open-source self-hosted Git service, that allows an authenticated user to execute arbitrary code under certain conditions. The security flaw, per…

↗ Open article
News The Hacker News

Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer

Vuln Malware

Threat actors are continuing to exploit a critical, now-patched security flaw impacting FortiClient Endpoint Management Server (EMS) deployments to deliver a credential-stealing malware family dubbed EKZ Infostealer…

↗ Open article
News The Hacker News

Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal

Vuln Research

Microsoft has come out strongly in favor of Coordinated Vulnerability Disclosure (CVD), urging the research community to share their findings and give affected vendors an opportunity to better understand the impact and…

↗ Open article
News The Hacker News

ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More

Every time you think the industry has finally stopped doing some reckless, low-effort crap, somebody spins up a fresh box full of sketchy loaders, fake installers, recycled social-engineering bait, and enough exposed…

↗ Open article
Research Rapid7 Blog

Experts on Experts: Why Compliance is becoming Continuous

Policy

This week on Experts on Experts, I’m joined by Sergio Alonso – Rapid7’s Director of Trust, Risk, and Compliance – to talk about how compliance is changing and why many security teams are rethinking the way they approach…

↗ Open article
Threat Intel Malwarebytes Labs

Carnival confirms data breach impacting nearly 6 million

Breach

Carnival Corporation, parent of Carnival Cruise Line, is sending out fresh “Notice of Cybersecurity Event” letters dated May 27, 2026. If you feel like you’ve read that sentence before, you’re not imagining things. Over…

↗ Open article
Research Rapid7 Blog

Authenticated RCE via Argument Injection in Gogs (NOT FIXED)

Vuln

Overview Rapid7 Labs discovered a critical argument injection ( CWE-88 ) vulnerability in Gogs , a popular open-source self-hosted Git service. Rapid7 Labs scores this vulnerability as CVSSv4 9.4 (Critical). The…

↗ Open article
Advisory CISA Alerts & Advisories

CP Plus 8 Ch. Network Video Recorder

Vuln

View CSAF Summary Successful exploitation of this vulnerability allows an attacker's malicious script to execute in the browser of any authenticated user or administrator who accesses the affected interface. This could…

↗ Open article
Advisory CISA Alerts & Advisories

Supply Chain Compromises Impact Nx Console and GitHub Repositories

CISA is prioritizing the response to multiple emerging software supply chain intrusion campaigns targeting developer ecosystems Continuous Integration/Continuous Development (CI/CD) pipelines. These recent incidents…

↗ Open article
Advisory CISA Alerts & Advisories

XCharge C6

Vuln

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain administrator rights or execute code on the affected device. The following versions of XCharge C6 are affected: C6 CVSS…

↗ Open article
Advisory CISA Alerts & Advisories

KMW CCTV Security Cameras

Vuln

View CSAF Summary Successful exploitation of this vulnerability may grant full unauthorized access to camera feeds and settings. The following versions of KMW CCTV Security Cameras are affected: KM-IP521…

↗ Open article
Advisory CISA Alerts & Advisories

MacGregor Voyage Data Recorder (VDR) G4e

Vuln

View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker gaining administrator access to the device. The following versions of MacGregor Voyage Data Recorder (VDR) G4e are affected…

↗ Open article
Advisory CISA Alerts & Advisories

Schneider Electric EcoStruxure Machine Expert HVAC

Vuln

View CSAF Summary Schneider Electric is aware of a vulnerability in its EcostruxureTM Machine Expert HVAC product. The [EcostruxureTM Machine Expert HVAC](https://www.se.com/ww/en/download/document/EcoStruxureME_HVAC/)…

↗ Open article
Advisory CISA Alerts & Advisories

ABB EIBPORT

Vuln

View CSAF Summary ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. A firmware update is available that resolves these privately reported vulnerabilities in the product versions…

↗ Open article
Advisory CISA Alerts & Advisories

Fourth Frontier Frontier X Mobile Application, Frontier X2

Vuln

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to read and write arbitrary handle values and change clinical readings, which could result in taking control of the device and lead…

↗ Open article
Advisory CISA Alerts & Advisories

ABB Busch-Welcome 2 Wire Door Opener Actuator

Vuln

View CSAF Summary ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could gain physical, unauthorized access to a…

↗ Open article
Advisory CISA Alerts & Advisories

Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter

Vuln

View CSAF Summary Successful exploitation of this vulnerability could result in an attacker gaining administrator access to the device. The following versions of Jinan USR IOT Technology Limited (PUSR) USR-W610…

↗ Open article
News The Hacker News

New AI Usage Report: Enterprise AI Risk Is Heavily Concentrated Among a Small Group of AI "Power users"

State of AI Usage Report 2026 (full report here) by LayerX Security reveals the extent of the enterprise AI visibility gap and why most organizations still don't understand where their AI exposure is actually coming…

↗ Open article
Threat Intel Malwarebytes Labs

Your Windows PC has a security deadline in June 2026

A Secure Boot certificate refresh is rolling out across supported Windows devices through Windows Update. In June 2026, the Secure Boot certificates that have shipped inside Windows since 2011 begin to expire, and…

↗ Open article
Threat Intel Malwarebytes Labs

Fake ChatGPT download site infects Windows and Mac users with malware

Malware Crypto

A convincing fake website is impersonating OpenAI’s ChatGPT download page and infecting visitors with malware designed to steal passwords, browser data, cryptocurrency wallets, and other sensitive information. The site…

↗ Open article
News The Hacker News

JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware

Malware APT Crypto

A new campaign orchestrated by a previously undocumented threat actor has targeted cryptocurrency organizations with an aim to facilitate digital asset theft using recruitment-themed social engineering and bespoke macOS…

↗ Open article
News The Hacker News

Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users

Malware

Latin America and Europe become the target of two banking trojan campaigns that are designed to infect Windows and Android devices with Grandoreiro and BTMOB malware, respectively. That's according to new findings from…

↗ Open article
News The Hacker News

Malicious npm Package Stole Files From Claude AI User Directory via GitHub

Research

Cybersecurity researchers have discovered a new malicious package on the npm registry that comes with information stealing capabilities. According to OX Security, the package, named "mouse5212-super-formatter," is…

↗ Open article
News The Hacker News

5 Steps to Managing Shadow AI Tools Without Slowing Down Employees

When an employee installs an AI writing assistant, connects a coding copilot to their IDE, or starts summarizing meetings with a new browser tool, they are doing exactly what a productive employee should do: finding…

↗ Open article
Advisory CISA Alerts & Advisories

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CVE-2026-8398 ↗ Vuln

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-8398 Daemon Tools Lite Embedded Malicious Code Vulnerability…

↗ Open article ↗ CVE feed
Threat Intel Malwarebytes Labs

Kali365 phishing kit bypasses MFA and steals Microsoft logins

Phishing

When the Federal Bureau of Investigation (FBI) publishes a dedicated public service announcement about a new phishing kit, it’s worth paying attention to. The agency is now warning about “Kali365,” a…

↗ Open article
Threat Intel Malwarebytes Labs

Company bragged phone mics could listen to conversations. They couldn’t

A media company and two of its marketing partners have been fined for selling a service which, they said, listened in to people’s conversations through their phones. Actually they did nothing of the sort. Most people…

↗ Open article
Threat Intel Malwarebytes Labs

Fake LinkedIn emails abuse Adobe to track victims

Phishing

Cybercriminals are abusing Adobe infrastructure in a LinkedIn phishing campaign that steals passwords and redirects victims to the legitimate LinkedIn site afterward. The phishing email masquerades as a business inquiry…

↗ Open article
Threat Intel Malwarebytes Labs

Fake software on GitHub and SourceForge distribute Deno RAT

Malware

During our threat hunting activities, we found fake installers and plugins impersonating popular software including ChatGPT, Claude, AutoTune, and Kontakt on GitHub and SourceForge distributing a Deno backdoor known as…

↗ Open article
Research Rapid7 Blog

How Security Leaders Cut Through Complexity to Drive Better Outcomes

Security leaders are operating in an environment that is only getting more complex. Expanding attack surfaces, rapid AI adoption, growing toolsets, and increasing pressure to respond faster have made it harder to…

↗ Open article
Advisory CISA Alerts & Advisories

ABB Ability Camera Connect

Vuln

View CSAF Summary ABB is aware of public reports of vulnerabilities in a 3rd party component VLC media player Version 2.2.4 which was delivered together with the installation package of Camera Connect Version 1.5.0.14…

↗ Open article
Advisory CISA Alerts & Advisories

ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM)

Vuln

View CSAF Summary An update is available that resolves a vulnerability identified by B&Rs internal security analysis in the product versions listed as affected in this advisory. An attacker who successfully exploited…

↗ Open article
Advisory CISA Alerts & Advisories

CISA Adds One Known Exploited Vulnerability to Catalog

CVE-2026-48172 ↗ Vuln

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-48172 LiteSpeed cPanel Plugin Privilege Escalation Vulnerability This type…

↗ Open article ↗ CVE feed
Advisory CISA Alerts & Advisories

ABB LVS MConfig

Vuln

View CSAF Summary ABB became aware of an internally discovered vulnerability in the MConfig product versions listed as affected in the advisory. An attacker with access to local networks who successfully exploits…

↗ Open article
Advisory CISA Alerts & Advisories

ABB AC500 V2

Vuln ICS/OT

View CSAF Summary ABB became aware of vulnerabilities in AC500 V2 listed as affected in the advisory. An attacker who successfully exploited this vulnerability could access fragments of Modbus telegrams that have been…

↗ Open article
Advisory CISA Alerts & Advisories

ABB Terra AC

Vuln

View CSAF Summary ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the pollution of heap memory which…

↗ Open article
Advisory CISA Alerts & Advisories

ABB Ability Zenon Remote Transport Vulnerability (Update A)

Vuln

View CSAF Summary ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. The vulnerability enables unauthorized access to the Reboot OS function within the Remote Transport Service…

↗ Open article
Advisory CISA Alerts & Advisories

Eppendorf BioFlo 320

Vuln

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain full access to functionality and data with the bioreactor. The following versions of Eppendorf BioFlo 320 are affected…

↗ Open article
Threat Intel Any.Run Malware Analysis

Major Cyber Attacks in May 2026: Fake Invitations, Agent Tesla, BlobPhish, and More

Phishing Malware

May 2026 showed how fast routine business activity can turn into real security exposure. ANY.RUN observed phishing campaigns, fileless malware delivery, credential theft, OTP interception, and remote access abuse…

↗ Open article
News Krebs On Security

Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks

Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry out cyberattacks, influence operations and disinformation…

↗ Open article
Media Schneier on Security

Friday Squid Blogging: Regulating Squid Fishing in the South Pacific

The South Pacific Regional Fisheries Management Organization (SPRFMO) needs to regulate squid fishing in the South Pacific. As usual, you can also use this squid post to talk about the security stories in the news that…

↗ Open article
Research Rapid7 Blog

Metasploit Wrap Up 05/22/2026

Vuln

Another week, another authentication bypass Our humble Metasploit weekly(ish) blog has been blessed with a new network component vulnerability. The dynamic duo of @sfewer-r7 and @jburgess-r7 have discovered and authored…

↗ Open article
News Krebs On Security

Lawmakers Demand Answers as CISA Tries to Contain Data Leak

Breach

Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS…

↗ Open article
Advisory CISA Alerts & Advisories

CISA Adds One Known Exploited Vulnerability to Catalog

CVE-2026-9082 ↗ Vuln

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-9082 Drupal Core SQL Injection Vulnerability This type of vulnerability is a…

↗ Open article ↗ CVE feed
Research Trail of Bits

We hardened zizmor's GitHub Actions static analyzer

Vuln Malware

In March 2026, attackers exploited a pull_request_target misconfiguration in the aquasecurity/trivy-action GitHub Action to exfiltrate organization and repository secrets, then used those credentials to backdoor LiteLLM…

↗ Open article
News Krebs On Security

Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada

Malware

Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf , a fast spreading Internet-of-Things botnet that enslaved millions of devices for use in a series of…

↗ Open article
Advisory Tenable Security Advisories

[R1] Sensor Proxy Version 1.4.0 Fixes Multiple Vulnerabilities

Vuln

[R1] Sensor Proxy Version 1.4.0 Fixes Multiple Vulnerabilities Jason Schavel Thu, 05/21/2026 - 16:00 Sensor Proxy leverages third-party software to help provide underlying functionality. Several of the third-party…

↗ Open article
News Dark Reading

AI Agents Are Shifting Identity Security Budget Dynamics

Research

AI agent projects are proliferating throughout the enterprise, and those AI agent identities require management, security, and governance. New Omdia research shows the AI agent identity budget dynamics are very…

↗ Open article
Research Rapid7 Blog

Q1 2026 Threat Landscape Report: Zero-clicks, geopolitical tensions, and some wins for law enforcement

Vuln

The first quarter of 2026 reinforced that attackers are moving faster, operating with greater coordination, and exploiting weaknesses before most organizations can respond effectively. From escalating geopolitical…

↗ Open article
Research Rapid7 Blog

Operationalizing CTEM Faster: Build Surface Command Dashboards in Minutes

Modern attack surfaces don’t sit still. Cloud expansion, SaaS sprawl, identity complexity, and shadow IT are continuously reshaping organizational risk. For security leaders, visibility isn’t the challenge anymore, but…

↗ Open article
Research Rapid7 Blog

Rapid7’s 2026 Global Cybersecurity Summit: Key Takeaways for Security Leaders

Security teams are working in an environment where speed, scale, and complexity are all increasing at the same time. Across the Rapid7 2026 Global Cybersecurity Summit , the focus was not just on how the threat…

↗ Open article
News Krebs On Security

CISA Admin Leaked AWS GovCloud Keys on Github

Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a…

↗ Open article
Research Rapid7 Blog

Metasploit Wrap-Up 05/15/2026

Weaponizing a text editor for fun and profit Gather round, dear readers, because today, we (by we, we mean @h00die) dropped the ultimate persistence mechanism: Vim plugin persistence. And honestly, calling it…

↗ Open article
Research Rapid7 Blog

CVE-2026-0265: Authentication Bypass in Palo Alto Networks PAN-OS

CVE-2026-0265 ↗ Vuln

Overview On May 13, 2026, Palo Alto Networks published a security advisory for CVE-2026-0265 , a signature verification vulnerability that facilitates authentication bypass on PAN-OS , the operating system that most…

↗ Open article ↗ CVE feed
Advisory Tenable Security Advisories

[R2] Tenable Network Monitor 6.5.4 Fixes Multiple Vulnerabilities

Vuln

[R2] Tenable Network Monitor 6.5.4 Fixes Multiple Vulnerabilities Jason Schavel Thu, 05/14/2026 - 13:00 Tenable Network Monitor leverages third-party software to help provide underlying functionality. Several of the…

↗ Open article
Research Rapid7 Blog

CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)

CVE-2026-20127 ↗ CVE-2026-20182 ↗ Vuln Research

Overview While researching a critical authentication bypass vulnerability, CVE-2026-20127 , which was exploited in-the-wild , Rapid7 Labs discovered a new authentication bypass vulnerability affecting Cisco Catalyst…

↗ Open article ↗ CVE feed
Research Rapid7 Blog

The Dark Side of Efficiency: When Network Controllers Become "God Mode" for Attackers

Privacy

Imagine you build a massive corporate campus with every security control money can buy. Blast resistant doors. Biometric scanners. Guards at every entrance. Maybe something similar to the infamous Death Star. On paper…

↗ Open article
Threat Intel Any.Run Malware Analysis

LATAM Under Siege: Agent Tesla’s 18-Month Credential Theft Campaign Against Chilean Enterprises

Ransom Malware Research

Editor’s note: The analysis is authored by Moises Cerqueira, malware researcher & threat hunter. You can find Moises on LinkedIn and X . Credential theft malware rarely announces itself with ransomware-level noise…

↗ Open article
Research Rapid7 Blog

When IT Support Calls: Dissecting a ModeloRAT Campaign from Teams to Domain Compromise

Overview Attackers do not need to break into the front door when they can convince employees to open it for them through the tools they already trust. In April 2026, Rapid7 investigated an enterprise intrusion that…

↗ Open article
Research Rapid7 Blog

Rapid7 Partner Academy: Driving Impact with Gold Stevie Award-Winning Partner Services Certifications

At Rapid7, our commitment to our partners is built on the foundation of the PACT (Partnering with Accountability, Consistency, and Transparency) program. Central to this mission is the Rapid7 Partner Academy, which was…

↗ Open article
News Krebs On Security

Patch Tuesday, May 2026 Edition

Vuln

Artificial intelligence platforms may be just as susceptible to social engineering as human beings, but they are proving remarkably good at finding security vulnerabilities in human-made computer code. That reality is…

↗ Open article
Research Trail of Bits

Go fuzzing was missing half the toolkit. We forked the toolchain to fix it

Go’s native fuzzing is useful, but it stands far behind state-of-the-art tooling that the Rust, C, and C++ ecosystems offer with LibAFL and AFL++. Path constraints are hard to solve. Structured inputs usually need…

↗ Open article
News Krebs On Security

Canvas Breach Disrupts Schools & Colleges Nationwide

Ransom Breach

An ongoing data extortion attack targeting the widely-used education technology platform Canvas disrupted classes and coursework at school districts and universities across the United States today, after a cybercrime…

↗ Open article
Threat Intel Any.Run Malware Analysis

New Phishing Campaign Targets US with Credential Theft: What CISOs Need to Know

Phishing Research

A new large-scale phishing campaign is targeting U.S. organizations with fake event invitations that lead to credential theft, OTP interception, or RMM tool installation. ANY.RUN researchers found that the campaign uses…

↗ Open article
Research Trail of Bits

C/C++ checklist challenges, solved

We recently added a C/C++ security checklist to the Testing Handbook and challenged readers to spot the bugs in two code samples : a deceptively simple Linux ping program and a Windows driver registry handler. If you…

↗ Open article
Podcast Darknet Diaries

174: Pacific Rim

For six years, Sophos fought a secret cyber war against a state-backed hacking group targeting its firewalls. This forced Sophos to drastically change tactics to properly secure their firewalls. Was it ethical? Was it…

↗ Open article
Research NIST Cybersecurity Insights

Stronger Cybersecurity, Stronger Business: NIST Celebrates 2026 National Small Business Week

Happy National Small Business Week! For over 60 years, the U.S. Small Business Administration has led this initiative to acknowledge the critical contributions of America’s entrepreneurs and small business owners. Part…

↗ Open article
News Krebs On Security

Anti-DDoS Firm Heaped Attacks on Brazilian ISPs

Malware DoS

A Brazilian tech firm that specializes in protecting networks from distributed denial-of-service (DDoS) attacks has been enabling a botnet responsible for an extended campaign of massive DDoS attacks against other…

↗ Open article
Research Trail of Bits

Extending Ruzzy with LibAFL

LibAFL is all the rage in the fuzzing community these days, especially with LLVM’s libFuzzer being placed in maintenance mode . Written in Rust, LibAFL claims improved performance, modularity, state-of-the-art fuzzing…

↗ Open article
Research MITRE ATT&CK

ATT&CK v19: The Defense Evasion Split, ICS Sub-Techniques, New AI & Social Engineering Coverage…

ICS/OT

ATT&CK v19: The Defense Evasion Split, ICS Sub-Techniques, New AI & Social Engineering Coverage, and Detection Strategies for Mobile ATT&CK v19 is here, and this release has been a long time coming. The Defense Evasion…

↗ Open article
Threat Intel Any.Run Malware Analysis

Phishing-to-RMM Attacks: The Remote Access Blind Spot CISOs Can’t Ignore

Phishing

CISOs are under pressure to prove that their security programs can detect threats early, reduce business risk, and support fast, confident response. But that becomes harder when attackers stop relying on obviously…

↗ Open article
Research NIST Cybersecurity Insights

From DMV to Wallet: Understanding Verifiable Digital Credential Issuance

In our last post in this series, we compared two credential formats that shape the digital identity ecosystem: ISO/IEC 18013-5 and -7 mobile documents (mdocs) and W3C Verifiable Credentials (VCs). Both formats define…

↗ Open article
Threat Intel Any.Run Malware Analysis

Inside agenteV2: How Brazilian Attackers Use Fake Court Summons to Steal Banking Credentials in Real Time

Phishing Malware Research

Editor’s note: The analysis is authored by Moises Cerqueira, malware researcher & threat hunter. You can find Moises on LinkedIn and X . A new phishing campaign targeting Brazilian users demonstrates how modern…

↗ Open article
Research Google Security Blog

AI threats in the wild: The current state of prompt injections on the web

Posted by Thomas Brunner, Yu-Han Liu, Moni Pande At Google, our Threat Intelligence teams are dedicated to staying ahead of real-world adversarial activity, proactively monitoring emerging threats before they can impact…

↗ Open article
Advisory Tenable Security Advisories

[R1] Nessus Versions 10.11.4 and 10.12.0 Fixes Arbitrary File Deletion

Vuln

[R1] Nessus Versions 10.11.4 and 10.12.0 Fixes Arbitrary File Deletion Jason Schavel Thu, 04/23/2026 - 14:30 A vulnerability has been identified in Nessus on Windows where an attacker to create a junction, enabling the…

↗ Open article
Advisory Tenable Security Advisories

[R1] Nessus Agent Version 11.1.3 Fixes Arbitrary File Deletion

Vuln

[R1] Nessus Agent Version 11.1.3 Fixes Arbitrary File Deletion Jason Schavel Thu, 04/23/2026 - 14:10 A vulnerability has been identified in Nessus Agent on Windows where an attacker to create a junction, enabling the…

↗ Open article
Research Trail of Bits

Trailmark turns code into graphs

We’re open-sourcing Trailmark , a library that parses source code into a queryable call graph of functions, classes, call relationships, and semantic metadata, then exposes that graph through a Python API that Claude…

↗ Open article
News Krebs On Security

‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty

A 24-year-old British national and senior member of the cybercrime group “ Scattered Spider ” has pleaded guilty to wire fraud conspiracy and aggravated identity theft. Tyler Robert Buchanan admitted his role in a…

↗ Open article
Threat Intel Any.Run Malware Analysis

New Lazarus APT Campaign: “Mach-O Man” macOS Malware Kit Hits Businesses

Malware APT Research

Editor’s note: The research is authored by Mauro Eldritch, offensive security expert and a founder of BCA LTD, a company dedicated to threat intelligence and hunting. You can find Mauro on X . The recent wave of…

↗ Open article
Research Trail of Bits

We beat Google’s zero-knowledge proof of quantum cryptanalysis

Two weeks ago, Google’s Quantum AI group published a zero-knowledge proof of a quantum circuit so optimized, they concluded that first-generation quantum computers will break elliptic curve cryptography keys in as…

↗ Open article
Threat Intel Any.Run Malware Analysis

BlobPhish: The Phantom Phishing Campaign Hiding in Browser Memory

Phishing

ANY.RUN has observed a sustained surge in a credential-phishing campaign active since 2024. This campaign, dubbed BlobPhish, introduces a sneaky twist: instead of delivering phishing pages via traditional HTTP requests…

↗ Open article
News Krebs On Security

Patch Tuesday, April 2026 Edition

Vuln

Microsoft today pushed software updates to fix a staggering 167 security vulnerabilities in its Windows operating systems and related software, including a SharePoint Server zero-day and a publicly disclosed weakness in…

↗ Open article
Advisory Tenable Security Advisories

[R3] Tenable Identity Exposure Version 3.77.17 Fixes Multiple Vulnerabilities

Vuln

[R3] Tenable Identity Exposure Version 3.77.17 Fixes Multiple Vulnerabilities Aaron Roy Tue, 04/14/2026 - 10:54 Tenable Identity Exposure leverages third-party software to help provide underlying functionality. Several…

↗ Open article
Threat Intel Any.Run Malware Analysis

When Trust Becomes a Weapon: Google Cloud Storage Phishing Deploying Remcos RAT

Phishing Malware

Modern phishing campaigns increasingly abuse legitimate services. Cloud platforms, file-sharing tools, trusted domains, and widely used SaaS applications are now part of the attacker’s toolkit. Instead of breaking…

↗ Open article
Research Google Security Blog

Bringing Rust to the Pixel Baseband

Vuln

Posted by Jiacheng Lu, Software Engineer, Google Pixel Team Google is continuously advancing the security of Pixel devices. We have been focusing on hardening the cellular baseband modem against exploitation…

↗ Open article
Research Google Security Blog

Protecting Cookies with Device Bound Session Credentials

Posted by Ben Ackerman, Chrome team, Daniel Rubery, Chrome team and Guillaume Ehinger, Google Account Security team Following our April 2024 announcement , Device Bound Session Credentials (DBSC) is now entering public…

↗ Open article
Threat Intel Any.Run Malware Analysis

How Phishing Is Targeting Germany’s Economy: Active Threats from Finance to Manufacturing

Phishing

Germany’s economy is a precision machine: finance fuels it, manufacturing builds it, telecom connects it, IT optimizes it, and healthcare sustains it. The country sits at the crossroads of industrial power and digital…

↗ Open article
Research Trail of Bits

Master C and C++ with our new Testing Handbook chapter

We added a new chapter to our Testing Handbook: a comprehensive security checklist for C and C++ code . We’ve identified a broad range of common bug classes, known footguns, and API gotchas across C and C++ codebases…

↗ Open article
Advisory Tenable Security Advisories

[R2] Stand-alone Security Patch Available for Tenable Security Center Versions 6.5.1, 6.6.0, 6.7.2 and 6.8.0: SC202604.1

Vuln

[R2] Stand-alone Security Patch Available for Tenable Security Center Versions 6.5.1, 6.6.0, 6.7.2 and 6.8.0: SC202604.1 Aaron Roy Tue, 04/07/2026 - 11:35 Security Center leverages third-party software to help provide…

↗ Open article
Research Trail of Bits

What we learned about TEE security from auditing WhatsApp's Private Inference

WhatsApp’s new “Private Inference” feature represents one of the most ambitious attempts to combine end-to-end encryption with AI-powered capabilities, such as message summarization. To make this possible, Meta built a…

↗ Open article
Research Trail of Bits

Simplifying MBA obfuscation with CoBRA

Malware

Mixed Boolean-Arithmetic (MBA) obfuscation disguises simple operations like x + y behind tangles of arithmetic and bitwise operators. Malware authors and software protectors rely on it because no standard simplification…

↗ Open article
Research Google Security Blog

Google Workspace’s continuous approach to mitigating indirect prompt injections

Posted by Adam Gavish, Google GenAI Security Team Indirect prompt injection (IPI) is an evolving threat vector targeting users of complex AI applications with multiple data sources, such as Workspace with Gemini. This…

↗ Open article
Research Trail of Bits

Mutation testing for the agentic era

Code coverage is one of the most dangerous quality metrics in software testing. Many developers fail to realize that code coverage lies by omission: it measures execution, not verification. Test suites with high…

↗ Open article
Research MITRE ATT&CK

Defense Evasion Split: A Tale of Two Tactics

By Allison Henao and Alice Koeninger, Art by Cat Self If you’ve been following the ATT&CK community channels, you’ve probably heard us talking about changes to Enterprise’s Defense Evasion tactic ( ATT&CKcon 5.0 …

↗ Open article
Research Google Security Blog

VRP 2025 Year in Review

Vuln

Posted by Dirk G ö hmann, Tony Mendez, and the Vulnerability Rewards Program Team 2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉!…

↗ Open article
Research Trail of Bits

How we made Trail of Bits AI-native (so far)

This post is adapted from a talk I gave at [un]prompted , the AI security practitioner conference. Thanks to Gadi Evron for inviting me to speak. You can watch the recorded presentation below or download the slides …

↗ Open article
Research Google Security Blog

Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android

Posted by Eric Lynch, Product Manager, Android and Dom Elliott, Group Product Manager, Google Play Modern digital security is at a turning point. We are on the threshold of using quantum computers to solve "impossible"…

↗ Open article
Research Trail of Bits

Try our new dimensional analysis Claude plugin

We’re releasing a new Claude plugin for developing and auditing code that implements dimensional analysis, a technique we explored in our most recent blog post . Most LLM-based security skills ask the model to find…

↗ Open article
Research Trail of Bits

Spotting issues in DeFi with dimensional analysis

Using dimensional analysis, you can categorically rule out a whole category of logic and arithmetic bugs that plague DeFi formulas. No code changes required, just better reasoning! One of the first lessons in physics is…

↗ Open article
Research NIST Cybersecurity Insights

Reflections from the Second NIST Cyber AI Profile Workshop

Thank you to everyone who participated in the Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile) Workshop in January! The input we received on the Preliminary Draft during this workshop has…

↗ Open article
Research NIST Cybersecurity Insights

All aboard: the NIST Cybersecurity for IoT Program is headed to our next stop! Share your input on where we’re headed during our Future Directions Two-Day Workshop on March 31st

Workshop Details… We’re looking forward to hearing from the community during our “Future Directions” Workshop! Date: March 31 - April 1, 2026 Where: NIST’s Gaithersburg campus! Registration and Details: HERE Can’t make…

↗ Open article
Advisory Tenable Security Advisories

[R1] Stand-alone Security Patch Available for Tenable OT version 4.2.40: tenable-ot-platform-137

Vuln

[R1] Stand-alone Security Patch Available for Tenable OT version 4.2.40: tenable-ot-platform-137 Jason Schavel Thu, 03/19/2026 - 15:06 An SSH misconfigurations exists in Tenable OT that led to the potential exfiltration…

↗ Open article
Research Trail of Bits

Six mistakes in ERC-4337 smart accounts

Account abstraction transforms fixed “private key can do anything” models into programmable systems that enable batching, recovery and spending limits, and flexible gas payment. But that programmability introduces…

↗ Open article
Advisory Tenable Security Advisories

[R1] Nessus Manager Versions 10.10.3 and 10.11.3 Fix One Vulnerability

Vuln

[R1] Nessus Manager Versions 10.10.3 and 10.11.3 Fix One Vulnerability Arnie Cabral Tue, 03/03/2026 - 12:08 A path traversal vulnerability exists in Nessus Manager where an authenticated, remote attacker could read…

↗ Open article
Research Google Security Blog

Cultivating a robust and efficient quantum-safe HTTPS

Posted by Chrome Secure Web and Networking Team Today we're announcing a new program in Chrome to make HTTPS certificates secure against quantum computers. The Internet Engineering Task Force (IETF) recently created a…

↗ Open article
Research Google Security Blog

Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection

Posted by Lyubov Farafonova, Product Manager, Phone by Google; Alberto Pastor Nieto, Sr. Product Manager Google Messages and RCS Spam and Abuse We’ve shared how Android’s proactive, multi-layered scam defenses utilize…

↗ Open article
Research Trail of Bits

mquire: Linux memory forensics without external dependencies

If you’ve ever done Linux memory forensics, you know the frustration: without debug symbols that match the exact kernel version, you’re stuck. These symbols aren’t typically installed on production systems and must be…

↗ Open article
Research NIST Cybersecurity Insights

Celebrating Two Years of CSF 2.0!

Celebrate this milestone with us! Email us at csf [at] nist.gov (csf[at]nist[dot]gov) or tag @NISTcyber on X telling us what your favorite CSF 2.0 resource is (or how your organization has benefitted from implementing…

↗ Open article
Research Trail of Bits

Using threat modeling and prompt injection to audit Comet

Before launching their Comet browser, Perplexity hired us to test the security of their AI-powered browsing features. Using adversarial testing guided by our TRAIL threat model, we demonstrated how four prompt injection…

↗ Open article
Research Google Security Blog

Keeping Google Play & Android app ecosystems safe in 2025

Posted by Vijaya Kaza, VP and GM, App & Ecosystem Trust The Android ecosystem is a thriving global community built on trust, giving billions of users the confidence to download the latest apps. In order to maintain that…

↗ Open article
Advisory Tenable Security Advisories

[R2] Security Center Version 6.8.0 Fixes Multiple Vulnerabilities

Vuln

[R2] Security Center Version 6.8.0 Fixes Multiple Vulnerabilities Arnie Cabral Wed, 02/18/2026 - 08:32 Security Center leverages third-party software to help provide underlying functionality. Several of the third-party…

↗ Open article
Research Trail of Bits

Carelessness versus craftsmanship in cryptography

Two popular AES libraries, aes-js and pyaes, “helpfully” provide a default IV in their AES-CTR API, leading to a large number of key/IV reuse bugs. These bugs potentially affect thousands of downstream projects. When we…

↗ Open article
Advisory Tenable Security Advisories

[R2] Stand-alone Security Patches Available for Tenable Security Center versions 6.5.1, 6.6.0 and 6.7.2: SC-202602.1 + SC-202602.2

Vuln

[R2] Stand-alone Security Patches Available for Tenable Security Center versions 6.5.1, 6.6.0 and 6.7.2: SC-202602.1 + SC-202602.2 Arnie Cabral Tue, 02/17/2026 - 08:32 Security Center leverages third-party software to…

↗ Open article
Research Trail of Bits

Celebrating our 2025 open-source contributions

Last year, our engineers submitted over 375 pull requests that were merged into non–Trail of Bits repositories, touching more than 90 projects from cryptography libraries to the Rust compiler. This work reflects one of…

↗ Open article
Research Trail of Bits

Building cryptographic agility into Sigstore

Software signatures carry an invisible expiration date. The container image or firmware you sign today might be deployed for 20 years, but the cryptographic signature protecting it may become untrustworthy within 10…

↗ Open article
Research Google Security Blog

New Android Theft Protection Feature Updates: Smarter, Stronger

Posted by Nataliya Stanetsky, Fabricio Ferracioli, Elliot Sisteron, Irene Ang of the Android Security Team Phone theft is more than just losing a device; it's a form of financial fraud that can leave you suddenly…

↗ Open article
Research NIST Cybersecurity Insights

Celebrating Data Privacy Week with NIST’s Privacy Engineering Program

Privacy

Grab your party hats – it’s Data Privacy Week! Data Privacy Week is a global initiative led by the National Cybersecurity Alliance to spread awareness about online privacy and empower individuals and businesses to…

↗ Open article
Research NIST Cybersecurity Insights

Digital Identities: Getting to Know the Verifiable Digital Credential Ecosystem

Understanding mDL credential formats Standards in the VDC Ecosystem In our first blog post in this series, we highlighted that VDCs can represent a wide range of credentials, from a driver’s license to a diploma to…

↗ Open article
Research Google Security Blog

HTTPS certificate industry phasing out less secure domain validation methods

Posted by Chrome Root Program Team Secure connections are the backbone of the modern web, but a certificate is only as trustworthy as the validation process and issuance practices behind it. Recently, the Chrome Root…

↗ Open article
Research Google Security Blog

Further Hardening Android GPUs

Privacy

Posted by Liz Prucka, Hamzeh Zawawy, Rishika Hooda, Android Security and Privacy Team Last year, Google's Android Red Team partnered with Arm to conduct an in-depth security analysis of the Mali GPU, a component used in…

↗ Open article
Research Google Security Blog

Architecting Security for Agentic Capabilities in Chrome

Posted by Nathan Parker, Chrome security team Chrome has been advancing the web’s security for well over 15 years, and we’re committed to meeting new challenges and opportunities with AI. Billions of people trust Chrome…

↗ Open article
Research Google Security Blog

Android expands pilot for in-call scam protection for financial apps

Posted by Aden Haussmann, Associate Product Manager and Sumeet Sharma, Play Partnerships Trust & Safety Lead Android uses the best of Google AI and our advanced security expertise to tackle mobile scams from every…

↗ Open article
Research NIST Cybersecurity Insights

A NICE Retrospective on Shaping Cybersecurity’s Future

Rodney Petersen has served as the Director of NICE at the National Institute for Standards and Technology (NIST) for the past eleven years where his focus has been on advancing cybersecurity education and workforce…

↗ Open article
Research Google Security Blog

Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing

Privacy

Posted by Dave Kleidermacher, VP, Platforms Security & Privacy, Google Technology should bring people closer together, not create walls. Being able to communicate and connect with friends and family should be easy…

↗ Open article
Research Google Security Blog

Rust in Android: move fast and fix things

Vuln

Posted by Jeff Vander Stoep, Android Last year, we wrote about why a memory safety strategy that focuses on vulnerability prevention in new code quickly yields durable and compounding gains. This year we look at how…

↗ Open article
Research Google Security Blog

How Android provides the most effective protection to keep you safe from mobile scams

Posted by Lyubov Farafonova, Product Manager, Phone by Google; Alberto Pastor Nieto, Sr. Product Manager Google Messages and RCS Spam and Abuse; Vijay Pareek, Manager, Android Messaging Trust and Safety As Cybersecurity…

↗ Open article
Research Google Security Blog

HTTPS by default

One year from now, with the release of Chrome 154 in October 2026, we will change the default settings of Chrome to enable “Always Use Secure Connections”. This means Chrome will ask for the user's permission before the…

↗ Open article
Research MITRE ATT&CK

ATT&CK v18: Detection Strategies, More Adversary Insights

ATT&CK v18: The Detection Overhaul You’ve Been Waiting For We’ve spent the last six months focused on making ATT&CK more usable and actionable for defenders, and with the help of the community the results are here!…

↗ Open article
Research NIST Cybersecurity Insights

Sharpening the Focus on Product Requirements and Cybersecurity Risks: Updating Foundational Activities for IoT Product Manufacturers

Update: The comment period for your feedback on the second public draft of NIST IR 8259 has been extended through December 10, 2025. Over the past few months, NIST has been revising and updating Foundational Activities…

↗ Open article
Research Google Security Blog

Accelerating adoption of AI for cybersecurity at DEF CON 33

Privacy

Posted by Elie Bursztein and Marianna Tishchenko, Google Privacy, Safety and Security Team Empowering cyber defenders with AI is critical to tilting the cybersecurity balance back in their favor as they battle…

↗ Open article
Research Google Security Blog

Supporting Rowhammer research to protect the DRAM ecosystem

Vuln Research

Posted by Daniel Moghimi Rowhammer is a complex class of vulnerabilities across the industry. It is a hardware vulnerability in DRAM where repeatedly accessing a row of memory can cause bit flips in adjacent rows…

↗ Open article
Research Google Security Blog

How Pixel and Android are bringing a new level of trust to your images with C2PA Content Credentials

Posted by Eric Lynch, Senior Product Manager, Android Security, and Sherif Hanna, Group Product Manager, Google C2PA Core At Made by Google 2025, we announced that the new Google Pixel 10 phones will support C2PA…

↗ Open article
Research Google Security Blog

Android’s pKVM Becomes First Globally Certified Software to Achieve Prestigious SESIP Level 5 Security Certification

Privacy

Posted by Dave Kleidermacher, VP Engineering, Android Security & Privacy Today marks a watershed moment and new benchmark for open-source security and the future of consumer electronics. Google is proud to announce that…

↗ Open article
Research NIST Cybersecurity Insights

Let’s get Digital! Updated Digital Identity Guidelines are Here!

Today is the day! Digital Identity Guidelines, Revision 4 is finally here...it’s been an exciting journey and NIST is honored to be a part of it. What can we expect? Serving as a culmination of a nearly four-year…

↗ Open article
Research NIST Cybersecurity Insights

Reflections from the First Cyber AI Profile Workshop

Thank you to everyone who participated in the Cyber AI Profile Workshop NIST hosted this past April! This work intends to support the cybersecurity and AI communities — and the input you provided during this workshop is…

↗ Open article
Research Google Security Blog

Introducing OSS Rebuild: Open Source, Rebuilt to Last

Posted by Matthew Suozzo, Google Open Source Security Team (GOSST) Today we're excited to announce OSS Rebuild, a new project to strengthen trust in open source package ecosystems by reproducing upstream artifacts. As…

↗ Open article
Research MITRE ATT&CK

What Comes After Detection Rules? Smarter Detection Strategies in ATT&CK

By Lex Crumpton Updated: October 22, 2025 Key updates: - Website example images added - No more Log Source SDO → log sources now live as a x_mitre_log_sources field on the Data Components SDO. - No more <detects> SRO…

↗ Open article
Research Google Security Blog

Advancing Protection in Chrome on Android

Posted by David Adrian, Javier Castro & Peter Kotwicz, Chrome Security Team Android recently announced Advanced Protection , which extends Google’s Advanced Protection Program to a device-level security setting for…

↗ Open article
Research NIST Cybersecurity Insights

Nine Years and Counting: NICE RAMPS Communities Keep Expanding Opportunities in Cybersecurity Work and Learning

A lot has changed in America’s cybersecurity workforce development ecosystem since 2016: employment in cybersecurity occupations has grown by more than 300,000 [1]; the number of information security degrees awarded…

↗ Open article
Research Google Security Blog

Mitigating prompt injection attacks with a layered defense strategy

Posted by Adam Gavish, Google GenAI Security Team With the rapid adoption of generative AI, a new wave of threats is emerging across the industry with the aim of manipulating the AI systems themselves. One such emerging…

↗ Open article
Research NIST Cybersecurity Insights

The Impact of Artificial Intelligence on the Cybersecurity Workforce

The NICE Workforce Framework for Cybersecurity ( NICE Framework) was revised in November 2020 as NIST Special Publication 800-181 rev.1 to enable more effective and rapid updates to the NICE Framework Components…

↗ Open article
Research NIST Cybersecurity Insights

Cybersecurity and AI: Integrating and Building on Existing NIST Guidelines

What is NIST up to? On April 3, 2025, NIST hosted a Cybersecurity and AI Profile Workshop at our National Cybersecurity Center of Excellence (NCCoE) to hear feedback on our concept paper which presented opportunities to…

↗ Open article
Research NIST Cybersecurity Insights

Five Years Later: Evolving IoT Cybersecurity Guidelines

The Background…and NIST’s Plan for Improving IoT Cybersecurity The passage of the Internet of Things (IoT) Cybersecurity Improvement Act in 2020 marked a pivotal step in enhancing the cybersecurity of IoT products…

↗ Open article
Research NIST Cybersecurity Insights

Small Businesses Create Big Impact: NIST Celebrates 2025 National Small Business Week

This week we’re celebrating National Small Business Week—which recognizes and celebrates the small and medium-sized business (SMB) community’s significant contributions to the nation. SMBs are a substantial and critical…

↗ Open article
Research MITRE ATT&CK

ATT&CK v17: New Platform (ESXi), Collection Optimization, & More Countermeasures

By: Amy Robertson and Adam Pennington Our goal with ATT&CK v17 is to help defenders stay aligned with where adversaries are headed by looking at where they’ve recently been. This release aims to inform defensive efforts…

↗ Open article
Research NIST Cybersecurity Insights

Celebrating 1 Year of CSF 2.0

It has been one year since the release of the NIST Cybersecurity Framework (CSF) 2.0 ! To make improving your security posture even easier, in this blog we are: Sharing new CSF 2.0 resources; Taking a retrospective look…

↗ Open article
Research NIST Cybersecurity Insights

Privacy-Preserving Federated Learning – Future Collaboration and Continued Research

Privacy Research

This post is the final blog in a series on privacy-preserving federated learning . The series is a collaboration between NIST and the UK government’s Responsible Technology Adoption Unit (RTA), previously known as the…

↗ Open article
Research NIST Cybersecurity Insights

NIST’s International Cybersecurity and Privacy Engagement Update – New Translations

Privacy

As the year comes to a close, NIST continues to engage with our international partners to strengthen cybersecurity, including sharing over ten new international translations in over six languages as resources for our…

↗ Open article
Research NIST Cybersecurity Insights

Data Pipeline Challenges of Privacy-Preserving Federated Learning

Privacy

This post is part of a series on privacy-preserving federated learning. The series is a collaboration between NIST and the UK government’s Responsible Technology Adoption Unit (RTA), previously known as the Centre for…

↗ Open article
Research NIST Cybersecurity Insights

Kicking-Off with a December 4th Workshop, NIST is Revisiting and Revising Foundational Cybersecurity Activities for IoT Device Manufacturers, NIST IR 8259!

In May 2020, NIST published Foundational Cybersecurity Activities for IoT Device Manufacturers (NIST IR 8259), which describes recommended cybersecurity activities that manufacturers should consider performing before…

↗ Open article
Research NIST Cybersecurity Insights

Unlocking Cybersecurity Talent: The Power of Apprenticeships

Cybersecurity is a fast-growing field, with a constant need for skilled professionals. But unlike other professions — like medicine or aviation — there’s no clear-cut pathway to qualifying for cybersecurity positions…

↗ Open article
Research NIST Cybersecurity Insights

Digital Identities: Getting to Know the Verifiable Digital Credential Ecosystem

If you are interested in the world of digital identities, you have probably heard some of the buzzwords that have been floating around for a few years now… “verifiable credential,” “digital wallet,” “mobile driver’s…

↗ Open article
Research MITRE ATT&CK

v16 Cloud Rebalancing, Analytics

V16 Brings (Re)Balance: Restructured Cloud, New Analytics, and More Cybercriminals In v16, we’re all about balance — striking that perfect chord between familiar and pioneering to keep things real and actionable. This…

↗ Open article
Research NIST Cybersecurity Insights

Staff Stories Spotlight Series: Cybersecurity Awareness Month 2024

This blog is part of a larger NIST series during the month of October for Cybersecurity Awareness Month , called 'Staff Stories Spotlight.' Throughout the month of October this year, Q&A style blogs will be published…

↗ Open article
Research NIST Cybersecurity Insights

Staff Stories Spotlight Series: Cybersecurity Awareness Month 2024

This blog is part of a larger NIST series during the month of October for Cybersecurity Awareness Month , called 'Staff Stories Spotlight.' Throughout the month of October this year, Q&A style blogs will be published…

↗ Open article
Research NIST Cybersecurity Insights

IoT Assignment Completed! Report on Barriers to U.S. IoT Adoption

The 16 members of the NIST-managed Internet of Things (IoT) Advisory Board have completed their report on barriers to the U.S. receiving the benefits of IoT adoption, along with their recommendations for overcoming…

↗ Open article
Research NIST Cybersecurity Insights

Staff Stories Spotlight Series: Cybersecurity Awareness Month 2024

This blog is part of a larger NIST series during the month of October for Cybersecurity Awareness Month , called 'Staff Stories Spotlight.' Throughout the month of October this year, Q&A style blogs will be published…

↗ Open article
Research NIST Cybersecurity Insights

Staff Stories Spotlight Series: Cybersecurity Awareness Month 2024

This blog is part of a larger NIST series during the month of October for Cybersecurity Awareness Month , called 'Staff Stories Spotlight.' Throughout the month of October this year, Q&A style blogs will be published…

↗ Open article
Research NIST Cybersecurity Insights

Staff Stories Spotlight Series: Cybersecurity Awareness Month 2024

This blog is part of a larger NIST series during the month of October for Cybersecurity Awareness Month , called 'Staff Stories Spotlight.' Throughout the month of October this year, Q&A style blogs will be published…

↗ Open article
Research NIST Cybersecurity Insights

Scalability Challenges in Privacy-Preserving Federated Learning

Privacy

This post is part of a series on privacy-preserving federated learning. The series is a collaboration between NIST and the UK government’s Responsible Technology Adoption Unit (RTA), previously known as the Centre for…

↗ Open article
Research NIST Cybersecurity Insights

Staff Stories Spotlight Series: Cybersecurity Awareness Month 2024

This blog is part of a larger NIST series during the month of October for Cybersecurity Awareness Month , called 'Staff Stories Spotlight.' Throughout the month of October this year, Q&A style blogs will be published…

↗ Open article
Research NIST Cybersecurity Insights

Managing Cybersecurity and Privacy Risks in the Age of Artificial Intelligence: Launching a New Program at NIST

Privacy

The rapid proliferation of Artificial Intelligence (AI) promises significant value for industry, consumers, and broader society, but as with many technologies, new risks from these advancements in AI must be managed to…

↗ Open article
Research NIST Cybersecurity Insights

Learning, Sharing, and Exploring with NIST’s New Human-Centered Cybersecurity Community of Interest

Human-centered cybersecurity (also known as ‘usable security’) involves the social, organizational, and technological influences on people’s understanding of and interactions with cybersecurity. By taking a…

↗ Open article
Research MITRE ATT&CK

Introducing TAXII 2.1 and a fond farewell to the TAXII 2.0 Server

As mentioned in our 2024 Roadmap and the v15 release blog , we’re excited to introduce our new TAXII server and the latest addition to the ATT&CK Workbench software suite: the MITRE ATT&CK Workbench TAXII 2.1 Server …

↗ Open article
Research NIST Cybersecurity Insights

Implementation Challenges in Privacy-Preserving Federated Learning

Privacy

In this post, we talk with Dr. Xiaowei Huang and Dr. Yi Dong (University of Liverpool), Dr. Mat Weldon ( United Kingdom (UK) Office of National Statistics (ONS)), and Dr. Michael Fenton (Trūata) who were winners in the…

↗ Open article
Research NIST Cybersecurity Insights

Protecting Trained Models in Privacy-Preserving Federated Learning

Privacy

This post is part of a series on privacy-preserving federated learning. The series is a collaboration between NIST and the UK government’s Responsible Technology Adoption Unit (RTA), previously known as the Centre for…

↗ Open article
Research NIST Cybersecurity Insights

NIST’s International Cybersecurity and Privacy Engagement Update – Mexico City, RSA Conference, and More

Privacy

The last few months have brought even more opportunities for NIST to engage with our international partners to enhance cybersecurity. Here are some updates on our recent international engagement: Conversations have…

↗ Open article
Research NIST Cybersecurity Insights

Check Your Wallet? How Mobile Driver’s Licenses are Changing Online Transactions

Can you recall the last time you opened a bank account? It’s likely you walked into a local bank branch and spoke to a representative who asked for your driver’s license and social security card to verify your identity…

↗ Open article
Research NIST Cybersecurity Insights

Latest NICE Framework Update Offers Improvements for the Cybersecurity Workforce

I joined NIST as the first full-time manager of the NICE Framework in October 2020, just one short month before NICE published the first revision NIST Special Publication 800-181, the NICE Workforce Framework for…

↗ Open article
Research NIST Cybersecurity Insights

Protecting Model Updates in Privacy-Preserving Federated Learning: Part Two

Privacy

The problem The previous post in our series discussed techniques for providing input privacy in PPFL systems where data is horizontally partitioned. This blog will focus on techniques for providing input privacy when…

↗ Open article
Research NIST Cybersecurity Insights

Take A Tour! NIST Cybersecurity Framework 2.0: Small Business Quick Start Guide

The U.S. Small Business Administration is celebrating National Small Business Week from April 28 - May 4, 2024. This week recognizes and celebrates the small business community’s significant contributions to the nation…

↗ Open article
Research MITRE ATT&CK

ATT&CK v15 Brings the Action

ATT&CK v15 Brings the Action: Upgraded Detections, New Analytic Format, & Cross-Domain Adversary Insights v15 is all about actionability and bringing defenders’ reality into focus — we prioritized what you need to…

↗ Open article
Research MITRE ATT&CK

ATT&CK 2024 Roadmap

Enhancing usability, expanding scope, optimizing defenses 2023 was dynamic year for ATT&CK. We marked a decade of progress since the framework’s inception and achieved some key milestones to make ATT&CK more accessible…

↗ Open article
Research MITRE ATT&CK

ATT&CK v14 Unleashes Detection Enhancements, ICS Assets, and Mobile Structured Detections

ICS/OT

Credit: https://flic.kr/p/dzyK9x CC BY-SA 2.0 ATT&CK has been brewing up something eerie for this Halloween — a release so hauntingly powerful that it will send a chill down the spine of even the most formidable…

↗ Open article
No articles found
Try adjusting your search, category, tags, source selection, or date range.