2026-05-06 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
A vulnerability in the REST API of Cisco Slido could have allowed an authenticated, remote attacker to access the social profile data of other users or affect quiz and poll results. Cisco has addressed this vulnerability in Cisco Slido and no customer action is needed. This vulnerability existed because of the presence of an insecure direct object reference. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by sending a crafted request to the vulne…
P5
2026-05-06 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
Multiple vulnerabilities in the web-based management interface of Cisco IoT Field Network Director Software could allow an authenticated, remote attacker to access files, execute commands, and cause denial of service (DoS) conditions on managed routers. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is ava…
P5
2026-05-06 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco 350 Series Managed Switches (SG350) and Cisco 350X Series Stackable Managed Switches (SG350X) firmware could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling when parsing response data for a specific SNMP request. An attacker could exploit this vulnerability by sending a specific SNMP request to an aff…
P5
2026-05-06 08:44 UTC
Government
CERT-EU Security Advisories · indexed 2026-08-15 18:50 UTC
On 6 May 2026, Palo Alto published a security advisory addressing a critical vulnerability affecting PAN-OS. This vulnerability allows an unauthenticated attacker to execute arbitrary code with root privileges. Palo Alto observed limited exploitation of this vulnerability. It is strongly recommended updating affected appliances as soon as patches will be available, and to apply workarounds and mitigation in the meantime.
P10
2026-05-06 08:07 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
This blog examines how threat actors use deepfake impersonation and social media to manipulate real stocks, how a network of 208 connected fake investment platforms steals millions in cryptocurrency, and what a new approach to defence can do about it.
P0
2026-05-05 08:55 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
ESET researchers have investigated an ongoing attack by the ScarCruft APT group that targets the Yanbian region via backdoor-laced Windows and Android games
P0
2026-05-04 16:00 UTC
Vendor Research
Google Security Blog · Dave Kleidermacher · indexed 2026-08-15 18:55 UTC
A diagram of the architecture of accountability
P0
2026-05-04 15:00 UTC
Government
CERT-EU Threat Intelligence · indexed 2026-08-15 18:50 UTC
Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
P0
2026-05-04 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
A fully patched Windows Server 2025 domain is vulnerable to dMSA Ouroboros—a self-sustaining credential extraction technique requiring only standard delegated permissions. Learn how it works, why remediation fails, and how to detect it.
P0
2026-05-04 12:00 UTC
Government
NIST Cybersecurity Insights · Daniel Eliot · indexed 2026-08-15 20:45 UTC
Happy National Small Business Week! For over 60 years, the U.S. Small Business Administration has led this initiative to acknowledge the critical contributions of America’s entrepreneurs and small business owners. Part of the U.S. Department of Commerce, NIST’s mission is to drive U.S. innovation and global competitiveness, and the small business community is central to this mission. In this year’s blog, we shine a spotlight on some new and upcoming NIST resources that are all focused on streng…
P0
2026-05-01 17:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Social engineering has evolved. Device code phishing and AI lures bypass MFA and blend in. Build a cyber resilience strategy before the next attack lands.
P0
2026-04-30 14:00 UTC
Vendor Research
Cloudflare Security · Sharon Goldberg · indexed 2026-08-15 18:58 UTC
Cloudflare IPsec now has generally available support for post-quantum encryption via hybrid ML-KEM. We’ve confirmed interoperability with Cisco and Fortinet.
P0
2026-04-30 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Your background is gone, but malware is here. Huntress breaks down BackgroundFix, a new ClickFix social engineering tactic involving CastleLoader, NetSupport RAT, and CastleStealer. Read the analysis.
P0
2026-04-30 09:25 UTC
Government
CERT-EU Security Advisories · indexed 2026-08-15 18:50 UTC
On 29 April 2026, a high local privilege escalation vulnerability in the Linux kernel, tracked as CVE-2026-31431 and named "Copy Fail", was publicly disclosed. The vulnerability affects every mainstream Linux distributions shipping a kernel built since 2017. A public proof-of-concept exploit has been released. As of the date of this advisory, no distribution has shipped a fixed kernel package. The mainline fix was committed on 1 April 2026, but vendor updates are still pending across all major …
P15
2026-04-30 09:00 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
Warnings about helpdesk impersonation scams and Iran-linked hackers targeting critical sectors in the US, plus the most damaging scams of 2025 - here's some of what made the headlines this month
P0
2026-04-30 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress found threat actors using the Komari monitoring agent as a SYSTEM-level backdoor. Learn how they abused GitHub and what defenders should hunt for.
P0
2026-04-29 06:54 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
While analyzing global smishing operations spanning APAC, LATAM, Europe, and MEA, Group-IB researchers uncovered the 'Phoenix System' administrative panel, a centralized Phishing-as-a-Service (PhaaS) platform with real-time victim monitoring, geofencing, and live-phishing interventions to bypass multi-factor authentication.
P0
2026-04-28 12:00 UTC
Government
NIST Cybersecurity Insights · Bill Fisher, Ryan Galluzzo, Heather Flanagan · indexed 2026-08-15 20:45 UTC
In our last post in this series, we compared two credential formats that shape the digital identity ecosystem: ISO/IEC 18013-5 and -7 mobile documents (mdocs) and W3C Verifiable Credentials (VCs). Both formats define how a credential is structured and shared, but neither can function without an issuance process. This blog post explores what it takes to issue verifiable digital credentials, with a focus on mobile driver’s licenses (mDLs). We’ll look at how issuance works today in practice, where…
P0
2026-04-27 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
See how Huntress EDR/ITDR Correlations stop infostealer-driven attacks before stolen credentials can be reused, linking endpoint compromise to cloud identities for one coordinated response.
P0
2026-04-24 09:00 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
A breach claims the systems as well as the confidence that was, in retrospect, a major vulnerability
P0
2026-04-23 21:38 UTC
Vendor Research
Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC
Posted by Thomas Brunner, Yu-Han Liu, Moni PandeAt Google, our Threat Intelligence teams are dedicated to staying ahead of real-world adversarial activity, proactively monitoring emerging threats before they can impact users. Right now, Indirect Prompt Injection (IPI) is a top priority for the security community, anticipating it as a primary attack vector for adversaries to target and compromise AI agents. But while the danger of IPI is widely discussed, are threat actors actually exploiting th…
P20
2026-04-23 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-15 18:55 UTC
Written by: JP Glab, Tufail Ahmed, Josh Kelley, Muhammad Umair Introduction Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim’s environment to achieve deep network penetration. As with many other intrusions in recent years, UNC6692 relied heavily on impersonating IT helpdesk employees, convincing their victim…
P0
2026-04-23 12:48 UTC
Vendor Research
Google Security Blog · Thomas Brunner · indexed 2026-08-15 18:55 UTC
We initiated a broad sweep of the public web to monitor for known indirect prompt injection patterns. This is what we found.
P20
2026-04-23 08:59 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
ESET Research has discovered a new China-aligned APT group that we’ve named GopherWhisper, which targets Mongolian governmental institutions
P0
2026-04-23 04:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Strong passwords aren't enough. Learn how multi-factor authentication (MFA) adds a critical layer of security to protect your organization from unauthorized access.
P0
2026-04-23 04:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn cyber hygiene best practices with Huntress: from strong passwords and MFA to patching and security training.
P0
2026-04-22 20:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
The threat landscape has shifted. Here's what cybersecurity leaders need to know about RMM abuse, AI-powered attacks, ransomware, and identity threats in 2026.
P15
2026-04-22 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Attackers are building workflows around AI—fake tools, spoofed answers, and machine-speed phishing. See how Huntress is tracking this shift and what it means for defenders.
P0
2026-04-22 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
A developer used OpenAI’s Codex to handle suspicious activity, leading to unexpected outcomes found by Huntress SOC analysts during an investigation.
P0
2026-04-22 06:53 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
How corporate/retail accounts are exploited for financial fraud through sophisticated device fingerprinting and mule networks.
P0