2026-05-21 07:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Two recent incidents involving The Gentlemen ransomware show the use of defense evasion tactics, including logs being cleared and attempts to add antivirus exclusions.
P15
2026-05-20 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to trigger BGP peer flaps, resulting in a denial of service (DoS) condition. This vulnerability is due to incorrect parsing of a transitive BGP attribute. An attacker could exploit this vulnerability by sending a crafted BGP update through an established BGP peer session. If…
P5
2026-05-20 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role. This vulnerability is due to insufficient validation and authentication when accessing REST API endpoints. An attacker could exploit this vulnerability if they are able to send a crafted API request to an affected endpoint. A successful exploit could allow the attacker to read sensitive inform…
P5
2026-05-20 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to execute commands on the underlying operating system as the root user. This vulnerability is due to insufficient validation of user-supplied input. An authenticated attacker could exploit this vulnerability by uploading a crafted certificate to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the un…
P20
2026-05-20 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
A vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent could have allowed an authenticated, remote attacker to execute arbitrary commands on Agents on behalf of the BrowserBot synthetics orchestration process. Cisco has addressed this vulnerability in the Cisco ThousandEyes Enterprise Agent, and no customer action is needed. This vulnerability was due to insufficient input validation of command arguments that are supplied by the user. Prior to this vulnerability bein…
P5
2026-05-20 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
The ransomware name on the ransom note doesn't tell the full story. See how RaaS affiliates drive initial access, persistence, and exfiltration and what defenders should watch for.
P15
2026-05-20 08:40 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
ESET researchers describe new tools and techniques that the Webworm APT group recently added to its arsenal
P0
2026-05-20 06:56 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
An increasing number of data brokers active in Chinese-speaking dark web forums and Telegram channels are advertising large volumes of purportedly stolen data from organizations worldwide. But are they credible?
P0
2026-05-19 17:49 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
On April 23, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an update to V1: Emergency Directive (ED) 25-03: Identify and Mitigate Potential Compromise of Cisco Devices related to Cisco Secure Firewall Adaptive Security Appliance (ASA) and Cisco Secure Firewall Threat Defense (FTD) products. According to the update, the ArcaneDoor threat actor has developed a previously unknown persistence mechanism that is preserved across upgrading to the fixed releases that wer…
P20
2026-05-19 09:49 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
A candid conversation on fraud disguised as iGaming growth with Sarah Psaila, Head of Gaming at Group-IB.
P0
2026-05-19 08:50 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
A complete decoupling from US technology is neither realistic nor necessary, but the changing environment does require nations and companies to reassess their relationships and dependencies
P0
2026-05-19 07:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Exposed RDP is still one of the most reliable ways attackers get in and most teams don't know it's open. See real cases where it was caught before it became a catastrophe.
P0
2026-05-18 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Threat actors are actively targeting your security tools. Learn how threat actors disable antivirus and EDR through vulnerable drivers, tampering attacks, and malicious firewall rules, and how Huntress detects.
P0
2026-05-18 09:21 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
How Group-IB is building a cognitive core that anticipates threats before they happen
P0
2026-05-18 06:00 UTC
Vendor Research
Cloudflare Security · Grant Bourzikas · indexed 2026-08-15 18:58 UTC
In recent weeks, we pointed Mythos and other security-focused LLMs at live code across critical parts of our infrastructure. We share what we observed, the models’ strengths and weaknesses, and what the work around them needs to look like before any of it can scale.
P0
2026-05-15 19:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn about some of the most common cloud security challenges facing modern businesses today, plus why it matters for you and your employees.
P0
2026-05-15 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC
Written by: Austin Larsen, Tyler McLellan, Genevieve Stark, Dan Ebreo Introduction Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the "BlackFile" brand, that targets organizations via sophisticated voice phishing (vishing) and single sign-on (SSO) compromise. By leveraging adversary-in-the-middle (AiTM) techniques to bypass traditional perimeter defenses and multi-factor authentication (MFA), UNC6671 gain…
P0
2026-05-15 11:58 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
An incident response retainer gives organizations immediate access to cybersecurity experts when a breach occurs, without losing critical time to legal, procurement, or onboarding delays. This article explains how IR retainers work, the different retainer models available, and why they can significantly reduce downtime, damage, and uncertainty during a cyber incident.
P0
2026-05-15 11:28 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Digital brand protection helps organizations detect and disrupt external threats, such as phishing sites, fake social profiles, counterfeit listings, and leaked credentials, before they become customer-facing fraud or reputational damage.
P0
2026-05-15 08:50 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
Conflict is a boon for opportunistic fraudsters. Look out for their ploys.
P0
2026-05-15 04:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn what single sign-on (SSO) login is, how it’s used in role management and cybersecurity, and how to set it up at your organization.
P0
2026-05-15 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
[Mise à jour du 11 juin 2026] Le 9 juin 2026, Microsoft a publié des versions correctives. [Publication initiale] Le 14 mai 2026, Microsoft a publié un avis de sécurité concernant la vulnérabilité CVE-2026-42897 affectant Exchange Server. Elle permet à un attaquant non authentifié de provoquer...
P5
2026-05-15 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn how to build a resilient security stack and program that cuts alert noise, strengthens identity defense, and helps teams respond faster.
P0
2026-05-14 18:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Discover some of the most common cybersecurity frameworks by what they’re best for, plus tips for choosing the right one for your organization.
P0
2026-05-14 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
Multiple vulnerabilities in Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow a remote attacker to gain access to sensitive information, elevate privileges, or gain unauthorized access to the application. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. Cisco strongly recommends that customers upgrade to…
P5
2026-05-14 15:56 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
Following the initial publication of the Security Advisory about a denial of service (DoS) condition in Cisco Crosswork Network Controller and Cisco Network Services Orchestrator (NSO), additional information has been made available to the Cisco Product Security Incident Response Team (PSIRT). Upon further analysis, the Cisco PSIRT has reclassified this issue as a customer-configurable, resource management issue rather than a security vulnerability. This advisory is available at the following l…
P5
2026-05-14 11:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn how critical Linux kernel flaws in CopyFail, Dirty Frag, and Fragnesia let unprivileged users escalate to root access. See what security teams can do to remediate.
P0
2026-05-14 09:38 UTC
Other
Red Hunt Labs · Sudhanshu Chauhan · indexed 2026-09-07 17:30 UTC
Why Mythos (and other AI models) Make Continuous Exposure Visibility Critical For years, vulnerability discovery was naturally constrained by expertise, time, and scale. Finding meaningful security issues often required experienced researchers spending days or weeks understanding codebases, testing assumptions, reviewing implementations, and validating exploitability. That dynamic is changing rapidly. Recent developments around systems like Anthropic’s Project Glasswing 🔗 and Mythos, OpenAI’s …
P50
2026-05-14 08:50 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
ESET researchers uncovered new activities attributed to FrostyNeighbor, updating its compromise chain to support the group’s continual cyberespionage operations
P0
2026-05-14 04:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
CMMC final rule requires DoD subs meet Level 2 by Nov 2026. Huntress Managed SIEM provides vendor docs and 24/7 monitoring for compliance.
P0