Security researchers at Socket have uncovered a coordinated attack targeting PHP Composer packages by hiding malicious JavaScript...
infosec
A newly analyzed ransomware campaign is turning traditional endpoint defense playbooks upside down by executing its entire...
A sweeping forensic threat intelligence report has exposed the inner workings of a sophisticated, highly commercialized cybercriminal...
Bypassing Terminal Protections: New SHub “Reaper” Variant Abuses AppleScript to Loot macOS Endpoints
Bypassing Terminal Protections: New SHub “Reaper” Variant Abuses AppleScript to Loot macOS Endpoints
Information stealers targeting macOS have continued to proliferate over the last two years, with threat actors iterating...
A sophisticated new threat actor is forcing corporate security leaders to re-evaluate their entire relationship with cloud...
A critical vulnerability in the LiteSpeed User-End cPanel Plugin is currently being actively exploited in the wild,...
A sophisticated, highly targeted cyber-espionage campaign is actively penetrating corporate and critical infrastructure networks across the Asia-Pacific...
Ubiquiti has issued a major security advisory addressing five distinct vulnerabilities across its UniFi OS ecosystem. Three...
A newly disclosed vulnerability was found in Apache Camel K, a widely trusted open-source integration framework designed...
In the world of Node.js development, the vm2 library has long served as a popular mechanism for...
A fresh security advisory has issued an urgent warning for open-source environments and enterprise Linux deployments utilizing...
Splunk has issued a coordinated batch of security advisories targeting vulnerabilities across Splunk Enterprise, Splunk Cloud Platform,...
Altium Enterprise Server, the backbone platform used by engineering teams globally to manage complex printed circuit board...
PowerDNS has issued a coordinated set of security advisories addressing multiple vulnerabilities discovered within its Authoritative Server...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two newly weaponized security vulnerabilities to its...
Corporate collaboration platforms have officially moved to the top of the initial access broker playbook. A new...
In the annals of cyber warfare, Stuxnet has long been considered the premier example of malware specifically...
The use of steganography—the ancient art of hiding secret messages inside seemingly ordinary files—is experiencing a massive...
Information stealers are no longer just basic, entry-level scripts designed to lift saved passwords from standard browser...
A newly detailed incident response investigation highlights a critical reality for corporate security teams: the perimeter of...
A massive, fast-moving software supply chain attack has struck the global JavaScript development ecosystem. Over the past...
Just when the internet thought it was safe to breathe following the patching of the notorious nginx-rift...