2026-07-09 14:00 UTC
Vendor Research
Cloudflare Security · Bas Westerbaan · indexed 2026-08-15 18:58 UTC
NIST is advancing nine new post-quantum signature algorithms as potential candidates for future standardization. We take a closer look at all of them, and argue that while they are in the works and show great potential, we should use ML-DSA for now — the best currently available.
P0
2026-07-09 07:01 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB analysts examine this resurfaced Android Remote Access Trojan, demonstrating new, sophisticated and malicious functionalities including autonomous privilege abuse, expanded command-and-control capabilities, and a robust persistence stack.
P0
2026-07-08 15:03 UTC
Other
Black Lantern Security · Paul Mueller · indexed 2026-09-07 17:30 UTC
New Features and Improvements in the Latest BBOT Release
P0
2026-07-08 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Threat actors are now using AI to generate custom PowerShell scripts for Active Directory attacks. Our team analyzed real vibe-coded malware and what it means for defenders.
P0
2026-07-08 12:31 UTC
Independent Research
Krebs on Security · BrianKrebs · indexed 2026-08-15 14:33 UTC
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.
P25
2026-07-08 08:45 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts.
P0
2026-07-08 07:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
LoTL abuse hides in plain sign, using legit tools like PowerShell and RMM software. Learn how to spot the warning signs that separate from routine IT work.
P0
2026-07-07 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-15 18:55 UTC
Written by: Shebin Mathew Introduction The "Golden SAML" technique, first described by CyberArk researchers in 2017, and further detailed by Mandiant researchers in 2021, remains one of the most effective methods for threat actors to forge identity assertions in the Microsoft ecosystem. By obtaining the private key of an ADFS token-signing certificate, an attacker can authenticate as any user to any SAML-federated application, bypassing multifactor authentication (MFA), conditional access, and …
P0
2026-07-07 12:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress is tracking a threat actor group as they evolve a phishing attack that uses a Facebook feature to send the initial spam lure.
P0
2026-07-07 08:26 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
This blog covers Group-IB’s overview of Scattered Spider, backed by Group-IB’s proprietary intelligence, providing additional information to what has already been reported publicly, with added clarification on 0ktapus and how it is related to Scattered Spider.
P0
2026-07-07 07:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
“Long Live” strong security! Taylor Swift & Travis Kelce’s wedding offers real cybersecurity lessons on layered defense, MFA, deception tools, and more.
P0
2026-07-06 19:20 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to achieve remote code execution or conduct information disclosure attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at …
P20
2026-07-06 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Recruiters and candidates are both using AI to game the process. Here's what that means for hiring quality, and what to do about it.
P0
2026-07-06 12:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to read arbitrary files from a restricted container of the affected device. Cisco has released software updates that address this vu…
P5
2026-07-06 04:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Plain text passwords are a critical security risk. See a real attack where exposed credentials led to a breach and how Huntress helps prevent it.
P0
2026-07-03 12:36 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
AI is changing cybercrime, but SMB cyber readiness still largely depends on closing the familiar gaps
P0
2026-07-02 20:52 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations. For more information about these vulnerabilities, see the Details section of this advisory. For additional information on these vulnerabilities in ClamAV, see the ClamAV blog. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. Notes: The Security Impact Rating (SIR) for t…
P5
2026-07-02 19:27 UTC
Independent Research
Krebs on Security · BrianKrebs · indexed 2026-08-15 14:33 UTC
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botnet, a collection of at least two million devices that have been compromised by malicious software w…
P0
2026-07-02 18:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Cloud application security keeps threat actors away from your data. We share practical ways to protect your apps and why it matters for your team today.
P0
2026-07-02 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC
Background Today, in coordination with the FBI, Lumen, and others, Google took action against the NetNut residential proxy network, also known as Popa. This action builds on our disruption of the IPIDEA proxy network that took place in January 2026, and is a continuation of Google’s objective to dismantle malicious residential proxy networks. Actions Taken As a part of this disruption we took the following actions: Disabled Google accounts and associated Google services used by NetNut for malwa…
P0
2026-07-02 12:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress Managed SAT now offers localized phishing simulations for Canada, using familiar, country-specific brands and scenarios to provide more effective security awareness training for your learners.
P0
2026-07-01 21:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress explains lateral movement attacks, how attackers move through networks, common techniques like pass-the-hash, and how Managed EDR stops lateral movement.
P0
2026-07-01 16:01 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
On July 1, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE-ID Security Impact Rating CVSS Base Score Cisco Catalyst Center Arbitrary File Read Vulnerability CVE-2026-20191 High 7.5 ClamAV Vulnerabilities Affecting Cisco Products: July 2026 CVE-2026-20216CVE-2026-20213CVE-2026-20214CVE-2026-20215CVE-2026-20217CVE-2026-20243CVE-2026-20244 High 7.5 To fully remediate the vulnerabilities that were disclosed on July 1, 2…
P5
2026-07-01 15:10 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could all…
P5
2026-07-01 14:00 UTC
Government
CERT-EU Threat Intelligence · indexed 2026-08-15 18:50 UTC
Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
P0
2026-07-01 12:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Ransomware-as-a-Service turned ransomware into a scalable criminal business. Learn how the model works, why it creates so much disruption, and where defenders can shut attacks down before encryption starts.
P15
2026-07-01 08:35 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
This blog documents Group-IB’s research into an SMS phishing campaign targeting Serbian road users through the impersonation of Serbia's state road authority, and how it can be linked to both Darcula and Phoenix PhaaS platforms with victims across the globe.
P0
2026-07-01 06:00 UTC
Vendor Research
Cloudflare Security · Jin-Hee Lee · indexed 2026-08-15 18:58 UTC
Cloudflare’s new Attribution Business Insights dashboard helps website owners understand crawler behavior, appetite, and potential value, fueling business-level conversations around crawl compensation.
P0
2026-06-30 20:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress is seeing an ongoing password spray attack against Microsoft Azure CLI that originates from an IPv6 address range controlled by LSHIY LLC.
P0
2026-06-30 14:39 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
Three-day patching deadlines, exposed fuel-tank systems, scams costing billions of dollars, and social media bans for children all gave Tony plenty to unpack in June 2026
P0