2026-04-08 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
A threat actor enumerated our entire AD with Get-ADComputer, and none of our detections fired. The problem wasn't their evasion - it was an architectural blind spot in how PowerShell talks to Active Directory.
P0
2026-04-08 11:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
The Stryker incident revealed that a "Weaponized Remote Wipe" via compromised MDM is a more permanent and difficult threat than ransomware. Learn concrete steps to secure management platforms and prevent your security shield from becoming a weapon.
P15
2026-04-08 07:30 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Discover how North Korean threat actors use synthetic identities, AI-assisted workflows, and overlapping infrastructure to infiltrate companies, and learn actionable strategies to mitigate this insider threat.
P0
2026-04-07 21:00 UTC
Vendor Research
Cloudflare Security · Bas Westerbaan · indexed 2026-08-15 18:58 UTC
Recent advances in quantum hardware and software have accelerated the timeline on which quantum attack might happen. Cloudflare is responding by moving our target for full post-quantum security to 2029.
P0
2026-04-07 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
A recent incident linked to the NightSpire ransomware workflow gives insight into why the RaaS structure and model, or lack thereof, are important – especially when it comes to scoping and recovering from the incident.
P15
2026-04-07 09:00 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
Threat actors are using AI to supercharge tried-and-tested TTPs. When attacks move this fast, cyber-defenders need to rethink their own strategy.
P0
2026-04-06 14:04 UTC
Other
Black Lantern Security · Kyle Griffin · indexed 2026-09-07 17:30 UTC
The rise of AI opens more doors to attackers
P0
2026-04-02 19:14 UTC
Vendor Research
Google Security Blog · Adam Gavish · indexed 2026-08-15 18:55 UTC
Indirect prompt injection (IPI) is an evolving threat vector targeting users of complex AI applications with multiple data sources, such as Workspace with Gemini. This t…
P0
2026-04-02 16:00 UTC
Vendor Research
Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC
Posted by Adam Gavish, Google GenAI Security TeamIndirect prompt injection (IPI) is an evolving threat vector targeting users of complex AI applications with multiple data sources, such as Workspace with Gemini. This technique enables the attacker to influence the behavior of an LLM by injecting malicious instructions into the data or tools used by the LLM as it completes the user’s query. This may even be possible without any input directly from the user.IPI is not the kind of technical proble…
P0
2026-04-01 15:00 UTC
Government
CERT-EU Threat Intelligence · indexed 2026-08-15 18:50 UTC
Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
P0
2026-04-01 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
OpenClaw AI agents pose identity and data risks if deployed with broad cloud permissions. Learn how to find and secure these apps before an attacker does.
P0
2026-04-01 10:32 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB researchers uncover an ongoing phishing campaign targeting major banks in the Philippines. This blog details how threat actors abuse trusted and legitimate platforms to deceive users and evade detection. It highlights a significant threat escalation with the successful hijacking of a legitimate domain to host malicious infrastructure, enabling threat actors to operate with even greater credibility and reduced detection.
P0
2026-04-01 09:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
See why the viral "three-finger test" is almost outdated, and how to build resilient security processes that protect your organization from identity-based attacks and social engineering, no matter how advanced the AI gets.
P0
2026-04-01 09:00 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
Fraudsters often target the accounts of the deceased or their grieving relatives. Here’s how to keep the scammers at bay.
P0
2026-03-31 23:30 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
An NPM supply chain attack struck the ubiquitous open-source axios library and Huntress has observed over a hundred affected devices.
P0
2026-03-31 18:58 UTC
Vendor Research
Google Security Blog · Dirk Göhmann · indexed 2026-08-15 18:55 UTC
2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉! Originally started in 2010, our vulnerabi…
P0
2026-03-31 16:55 UTC
Vendor Research
Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC
Posted by Dirk Göhmann, Tony Mendez, and the Vulnerability Rewards Program Team2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉! Originally started in 2010, our vulnerability reward program (VRP) has seen constant additions and expansions over the past decade and a half, clearly indicating the value the programs under this umbrella contribute to the safety and security of Google and its users, but also highlighting…
P0
2026-03-31 08:27 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
The past four weeks have seen a slew of new cybersecurity wake-up calls that showed why every organization needs a well-thought-out cyber-resilience plan
P0
2026-03-31 06:56 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB shows how Business Email Protection blocked Phantom Stealer phishing emails across different campaign waves.
P0
2026-03-31 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
Le 15 octobre 2025, F5 a publié un avis de sécurité concernant entre autres la vulnérabilité CVE-2025-53521. Celle-ci affecte BIG-IP APM et permet à un attaquant non authentifié d'exécuter du code à distance. Le 29 mars 2026, l'éditeur indique que cette vulnérabilité est exploitée activement. Le...
P5
2026-03-30 16:51 UTC
Other
Black Lantern Security · Kevin O'Riley · indexed 2026-09-07 17:30 UTC
A Claude Code Agent Dashboard
P0
2026-03-30 15:25 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Global regulators are mandating fraud intelligence sharing. Learn how financial institutions can collaborate in real-time while maintaining privacy compliance through Distributed Tokenization.
P0
2026-03-30 08:20 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Is your cybersecurity truly built to withstand today’s nuanced threats or is it just living on paper? Find out more.
P0
2026-03-30 06:00 UTC
Vendor Research
Cloudflare Security · Zhiyuan Zheng · indexed 2026-08-15 18:58 UTC
We are opening our advanced Client-Side Security tools to all users, featuring a new cascading AI detection system. By combining graph neural networks and LLMs, we've reduced false positives by up to 200x while catching sophisticated zero-day exploits.
P25
2026-03-27 10:38 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
This year, AI agents took the center stage – as a defensive capability, but more pressingly as a risk many organizations haven't caught up with
P0
2026-03-27 07:00 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
Silver Fox is back in Japan, spoofing tax and HR emails timed to the one season when no one thinks twice about opening them
P0
2026-03-26 20:46 UTC
Other
Black Lantern Security · Hunter Jensen · indexed 2026-09-07 17:30 UTC
CVE-2026-2931
P5
2026-03-25 18:43 UTC
Vendor Research
Google Security Blog · Eric Lynch · indexed 2026-08-15 18:55 UTC
Modern digital security is at a turning point. We are on the threshold of using quantum computers to solve "impossible" problems in drug discovery, materials science, an…
P0
2026-03-25 17:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
That "friendly" prompt is a ClickFix scam. Learn about this advanced social engineering tactic that tricks users into running malicious code on their own systems, and why security resilience is your winning bet.
P0
2026-03-25 13:00 UTC
Vendor Research
Google Online Security Blog · Edward Fernandez · indexed 2026-08-15 14:33 UTC
Posted by Eric Lynch, Product Manager, Android and Dom Elliott, Group Product Manager, Google Play Modern digital security is at a turning point. We are on the threshold of using quantum computers to solve "impossible" problems in drug discovery, materials science, and energy—tasks that even the most powerful classical supercomputers cannot handle. However, the same unique ability to consider different options simultaneously also allows these machines to bypass our current digital locks. This p…
P0