2026-01-05 15:00 UTC
Government
CERT-EU Threat Intelligence · indexed 2026-08-15 18:50 UTC
Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
P0
2026-01-05 08:15 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Learn how Group-IB’s Business Email Protection stops the growing wave of DocuSign impersonation before users are exposed, and protects them from credential-capturing websites built with real-time customizable LogoKit.
P0
2025-12-31 06:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
From lures involving Social Security statements to top domains and hashes used in attacks, here's an in-depth look at incidents involving ScreenConnect in 2025.
P0
2025-12-30 06:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Your LDAP detection rules work in the lab but fail in production. Here's why Event 1644 whitespace variations break your Sigma rules and how to fix them.
P0
2025-12-29 10:00 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
As 2025 draws to a close, Tony looks back at the cybersecurity stories that stood out both in December and across the whole of this year
P0
2025-12-24 07:04 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Fake online job ads continue to circulate across social media, especially in Arab countries, offering easy remote work and quick income. The sinister goal: to harvest sensitive information, from ID documents to banking details. This blog explains how the scheme operates, who the scammers target, and how to prevent falling victim to it.
P0
2025-12-23 10:00 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
Have you ever received a package you never ordered? It could be a warning sign that your data has been compromised, with more fraud to follow.
P0
2025-12-23 08:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
From "React2Shell" exploitation to sophisticated "Living off Trusted Sites" phishing, Huntress experts break down the threats targeting both enterprises and families today.
P0
2025-12-23 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn how supply chain attacks and shifting trust are reshaping the software supply chain, and what enterprises must do to strengthen resilience.
P0
2025-12-22 11:40 UTC
Other
Red Hunt Labs · Lohit · indexed 2026-09-07 17:30 UTC
Payment gateways are built to move money reliably. Attackers view them as systems built on trust, timing, and assumptions. A gateway that works consistently is not a sign of safety. It is a stable environment to study, probe, and eventually abuse. This blog examines payment gateways from an attacker’s perspective, grounded in real exploitation patterns and reinforced with direct insights from industry experts. These patterns are documented extensively in the RedHunt Labs Payment Gateway Integra…
P0
2025-12-22 09:55 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
A comprehensive analysis and assessment of a critical severity vulnerability with low likelihood of mass exploitation
P35
2025-12-22 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Think all threat actors are pros? This post reveals how 'unsophisticated' malware and attacker errors help defenders stop attacks before damage is done.
P0
2025-12-19 07:53 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB analyzes the evolution of Android malware in Uzbekistan, revealing advanced droppers, encrypted payload delivery, anti-analysis techniques, and Wonderland’s bidirectional SMS-stealing capabilities driving large-scale financial fraud.
P0
2025-12-18 23:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Threat actors are exploiting a vulnerability in Gladinet’s CentreStack and Triofox products that stems from hardcoded cryptographic keys in the AES implementation.
P0
2025-12-18 10:00 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
ESET researchers discovered a China-aligned APT group, LongNosedGoblin, which uses Group Policy to deploy cyberespionage tools across networks of governmental institutions
P0
2025-12-18 09:08 UTC
Government
CERT-EU Security Advisories · indexed 2026-08-15 18:50 UTC
On December 17, 2025, Cisco released a security advisory for a critical vulnerability affecting Cisco Secure Email Gateway and Cisco Secure Email and Web Manager products. It is recommended to follow Cisco's recommendations to check whether vulnerable appliances have been compromised, and to remediate the issue. There is no patch available for this vulnerability yet.
P10
2025-12-18 08:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Recently, the Huntress SOC has observed threat actors increasingly use PDQ and GoTo Resolve to deploy further remote monitoring and management (RMM) tools in attacks.
P0
2025-12-16 09:50 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
A view of the H2 2025 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts
P0
2025-12-16 06:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn why your LDAP detection rules never fire and how to fix them. Hint: it's the OID-to-bitwise transformation.
P0
2025-12-12 15:22 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
Behind the polished exterior of many modern buildings sit outdated systems with vulnerabilities waiting to be found
P0
2025-12-12 08:22 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
AI in cybersecurity is changing the threat landscape faster than ever. Stay current and prepared with Group-IB.
P0
2025-12-11 16:04 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
Being seen as reliable is good for ‘business’ and ransomware groups care about 'brand reputation' just as much as their victims
P15
2025-12-11 10:00 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
If you don’t look inside your environment, you can’t know its true state – and attackers count on that
P0
2025-12-11 07:32 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Comprehensive insights into Uzbekistan’s credit fraud trends, the methods used by fraudsters, and the practical security controls financial institutions are fighting back with.
P0
2025-12-10 20:00 UTC
Vendor Research
Google Online Security Blog · Google · indexed 2026-08-15 14:33 UTC
Posted by Chrome Root Program Team Secure connections are the backbone of the modern web, but a certificate is only as trustworthy as the validation process and issuance practices behind it. Recently, the Chrome Root Program and the CA/Browser Forum have taken decisive steps toward a more secure internet by adopting new security requirements for HTTPS certificate issuers. These initiatives, driven by Ballots SC-080, SC-090, and SC-091, will sunset 11 legacy methods for Domain Control Validation…
P0
2025-12-10 15:03 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
Interpreting the vast cybersecurity vendor landscape through the lens of industry analysts and testing authorities can immensely enhance your cyber-resilience.
P0
2025-12-10 07:45 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Stranger things are happening in the upside-down world of cybercrime. Group-IB’s CEO, Dmitry Volkov, shares his cyber predictions for 2026 — what’s coming next, and what we must collectively fight against.
P0
2025-12-10 06:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
CMMC is coming. Learn how to turn this challenge into a major revenue opportunity for your business.
P0
2025-12-10 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress is seeing threat actors exploit React2Shell (CVE-2025-55182) to deploy a Linux backdoor, a reverse proxy tunnel, and a Go-based post-exploitation implant.
P5
2025-12-09 17:00 UTC
Vendor Research
Google Online Security Blog · Edward Fernandez · indexed 2026-08-15 14:33 UTC
Posted by Liz Prucka, Hamzeh Zawawy, Rishika Hooda, Android Security and Privacy Team Last year, Google's Android Red Team partnered with Arm to conduct an in-depth security analysis of the Mali GPU, a component used in billions of Android devices worldwide. This collaboration was a significant step in proactively identifying and fixing vulnerabilities in the GPU software and firmware stack. While finding and fixing individual bugs is crucial, and progress continues on eliminating them entirely…
P0