E4del and PINHOLE RATs Abuse FTP Banners as Dead Drop Resolvers
Cybersecurity researchers have uncovered a novel campaign that abuses FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote…
Cybersecurity researchers have uncovered a novel campaign that abuses FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote…
Cybersecurity researchers at OX Security have uncovered a campaign that abuses 24 npm packages as free phishing infrastructure. The packages host HTML…
A large-scale phishing campaign dubbed Mirage2FA has impacted over 4,500 organizations in the US and EU, abusing Microsoft 365 login flows to…
Frontier AI models, such as Anthropic's Mythos, are transforming vulnerability management by identifying zero-day flaws, chaining complex exploits, and adapting in real…
Threat actors are actively exploiting two critical authentication bypass vulnerabilities in the Xecurify miniOrange SAML 2.0 Single Sign On plugin for WordPress.…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a maximum-severity vulnerability affecting Oracle HTTP Server and Oracle WebLogic Server to…
Cybersecurity researchers have uncovered an ongoing campaign distributing the Weedhack malware to gamers through fake Minecraft clients and SEO poisoning. McAfee Labs…
Cybersecurity researchers have identified two new malware families, WordlistLoader and SynkLoader, which are being used to deliver next-stage payloads and potentially sell…
New research from Akamai reveals that a small fraction of enterprise employees—the top 5% of AI power users—are creating a disproportionate security…
Cybersecurity researchers have uncovered a cyber espionage campaign targeting Myanmar government and IT sectors, dubbed Operation QUICSILVER. The campaign, first observed in…