2025-07-30 04:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Transform raw Windows event data into actionable insights. Learn expert methodologies for intrusion analysis, authentication events, credential dumping, and RDP activity to stay ahead of threats.
P0
2025-07-25 07:51 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Think threat actors are unpredictable? The rise of intelligence-driven defense and the push for incident predictions might just give us the edge to know their next moves…long before they make it.
P0
2025-07-23 07:48 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Uncovering the validity of a PDF by utilizing some of the tools and methods to detect changes made to a PDF, and understand the limitations in proving PDF integrity.
P0
2025-07-22 09:45 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Enable real-time, token-based account security that stops withdrawal fraud before your brand, players, and their revenue are compromised.
P0
2025-07-21 21:34 UTC
Vendor Research
Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC
Posted by Matthew Suozzo, Google Open Source Security Team (GOSST)Today we're excited to announce OSS Rebuild, a new project to strengthen trust in open source package ecosystems by reproducing upstream artifacts. As supply chain attacks continue to target widely-used dependencies, OSS Rebuild gives security teams powerful data to avoid compromise without burden on upstream maintainers.The project comprises:Automation to derive declarative build definitions for existing PyPI (Python), npm (JS/T…
P0
2025-07-21 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
**[Mise à jour du 23 juillet 2025]** Le 20 juillet 2025, Microsoft a publié des correctifs pour une vulnérabilité de type limitation insuffisante d'un chemin d'accès à un répertoire restreint, aussi appelé *path traversal*, affectant SharePoint Enterprise Server 2016, SharePoint Server 2019 et...
P0
2025-07-18 04:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress has observed a new ransomware variant, Crux, being used in multiple incidents.
P15
2025-07-17 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn top cybercrime trends from Huntress’ 2025 survey of more than 500 American IT professionals. Plus, learn tips for improving your cybersecurity.
P0
2025-07-17 06:27 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Scammers are using tools like MaisonReceipts to create fake receipts and exploit brands. Uncover how this growing fraud ecosystem works behind the scenes.
P0
2025-07-17 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
When a threat actor exploited an MSP's RMM tool to target businesses, Huntress investigated and uncovered another eerily similar incident with key differences that reveal evolving tactics
P0
2025-07-14 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress is collaborating with Microsoft to help your business get the most out of your Microsoft security investments.
P0
2025-07-10 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress discovered active exploitation of Wing FTP Server RCE (CVE-2025-47812). Learn more about the injection flaw, attack timeline, forensic artifacts, and how to protect your organization.
P40
2025-07-08 17:36 UTC
Vendor Research
Google Online Security Blog · Google · indexed 2026-08-15 14:33 UTC
Posted by David Adrian, Javier Castro & Peter Kotwicz, Chrome Security Team Android recently announced Advanced Protection, which extends Google’s Advanced Protection Program to a device-level security setting for Android users that need heightened security—such as journalists, elected officials, and public figures. Advanced Protection gives you the ability to activate Google’s strongest security for mobile devices, providing greater peace of mind that you’re better protected against the most s…
P0
2025-07-08 08:07 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Combolists and ULP files circulate on the dark web as new leaks, but most of what they contain was stolen years earlier and recycled many times over.
P0
2025-07-07 12:00 UTC
Government
NIST Cybersecurity Insights · Michael Prebil · indexed 2026-08-15 20:45 UTC
A lot has changed in America’s cybersecurity workforce development ecosystem since 2016: employment in cybersecurity occupations has grown by more than 300,000 [1]; the number of information security degrees awarded annually has more than tripled to nearly 35,000 [2]; and a wide array of new technologies and risks have emerged. Five regional cybersecurity workforce partnerships supported by the 2016 RAMPS program pilot, administered by NIST’s NICE Program Office, have weathered the changes in c…
P0
2025-07-07 07:03 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Introducing BioConfirm - Enable real-time, token-based user account security that stops withdrawal fraud before your brand, customers’ trust, and revenue are compromised.
P0
2025-07-04 10:59 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Discover how attackers leverage Windows Kernel loaders and abuse digitally signed drivers to gain privileged access, disable security tools, and stealthily maintain control — bypassing traditional defenses and enabling advanced threat operations.
P0
2025-07-04 07:50 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Discover how Smart Alert in Group-IB Managed XDR consolidates thousands of alerts into one, cuts alert volume by 80%, and automates SOC detection and triage with AI.
P0
2025-07-02 08:08 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Discovered by Group-IB in mid-2024, the Qwizzserial, which was initially not very active, began to spread strongly in Uzbekistan, masquerading as legitimate applications. The malware steals banking information and intercepts 2FA sms, transmitting it to fraudsters via Telegram bots.
P0
2025-07-01 15:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn what the OpenAI lawsuit and court order mean for data privacy, cybersecurity, and the future of AI innovation.
P0
2025-07-01 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
**[Mise à jour du 17 juillet 2025]** L'éditeur a publié un lien contenant une méthode d'évaluation permettant d'identifier des tentatives d'exploitation dans les journaux applicatifs et systèmes [12]. **[Mise à jour du 7 juillet 2025]** Le 17 juin 2025, Citrix a publié un bulletin de sécurité...
P0
2025-06-30 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Is AI in cybersecurity a tool for defenders or the attackers? Find out in our recap of Huntress’ June Tradecraft Tuesday, where we break it down.
P0
2025-06-25 22:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
A business email compromise (BEC) attack is a type of scam where bad actors impersonate a trusted source to obtain information from their targeted individual.
P0
2025-06-25 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Clear up common misconceptions about the Kerberos Diamond Ticket and learn how to refine the technique for better OPSEC, including more realistic PAC details and support for service tickets. You’ll learn how to apply the idea securely to both Ticket Granting Tickets and Service Tickets, creating forgeries that blend in more effectively with legitimate Kerberos traffic. The result is a stealthier alternative to traditional Silver Tickets and a more convincing method that raises the bar for Kerbe…
P0
2025-06-24 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress Managed ITDR closes the gap with AD-synchronized identity disablement. Secure identities on-prem and in the cloud with this powerful update.
P0
2025-06-23 18:22 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Regional Conflict Monitoring (June 13 - 20, 2025)
P0
2025-06-20 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn cybersecurity leadership insights on developing elite cybersecurity teams from a seasoned NSA, NASA, and Huntress leader. Learn to hire, retain, and prevent burnout with impactful team growth and success strategies.
P0
2025-06-19 06:01 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Scammers are using fake tax authority emails to deploy crypto drainers. Discover how the declaration trap works and how to protect your digital assets.
P0
2025-06-18 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn how DPRK's BlueNoroff group executed a Web3 macOS intrusion. Explore the attack chain, malware, and techniques in our detailed technical report.
P0
2025-06-17 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
A routine account review revealed the use of productivity monitoring tools in a medical clinic, highlighting the hidden risks associated with employee monitoring software. Learn the importance of proactive audits in protecting critical systems and sensitive data from potential threats.
P0