2025-08-14 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability in the Amazon ECS agent could allow an introspection server to be accessed off-host. This information disclosure issue, if exploited, could allow another instance in the same security group to access the server's data. The vulnerability does not affect instances where off-host access is set to 'false'. The issue has been patched in version 1.97.1 of the ECS agent.
P0
2025-08-13 22:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
A likely zero-day vulnerability in SonicWall VPNs is being actively exploited to bypass MFA and deploy ransomware. Huntress advises disabling the VPN service immediately or severely restricting access via IP allow-listing. We're seeing threat actors pivot directly to domain controllers within hours of the initial breach.
P40
2025-08-13 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
See how Huntress fits into the updated 2024 CMMC framework. Explore how Sensitive Data Mode helps safeguard CUI and support compliance.
P0
2025-08-13 06:58 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
AI trading scams use deepfake videos, fake reviews, and fraudulent platforms to steal investor money, and learn the signals that expose these online investment scams before you deposit.
P0
2025-08-12 16:00 UTC
Vendor Research
Google Online Security Blog · Edward Fernandez · indexed 2026-08-15 14:33 UTC
Posted by Dave Kleidermacher, VP Engineering, Android Security & Privacy Today marks a watershed moment and new benchmark for open-source security and the future of consumer electronics. Google is proud to announce that protected KVM (pKVM), the hypervisor that powers the Android Virtualization Framework, has officially achieved SESIP Level 5 certification. This makes pKVM the first software security system designed for large-scale deployment in consumer electronics to meet this assurance bar. …
P0
2025-08-11 15:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
From The Social Network to The Matrix Reloaded, we break down the top hacking movie and TV show scenes that made us applaud (and cringe).
P0
2025-08-06 07:32 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Discover how AI voice deepfake vishing exploits trust, drains millions, and learn practical steps to detect and stop voice‑based scams.
P0
2025-08-05 04:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Recruitment scams are on the rise. Learn how to identify common scams and discover how Huntress is actively working to protect job seekers from fraudulent offers and identity theft.
P0
2025-08-05 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
[Mise à jour du 7 août 2025] Le 6 août 2025, SonicWall a remplacé une partie de son communiqué initial pour indiquer que les incidents de sécurité évoqués étaient vraisemblablement corrélés à la vulnérabilité CVE-2024-40766. Celle-ci a fait l'objet d'un bulletin de sécurité, SNWLID-2024-0015 (cf....
P5
2025-08-01 12:00 UTC
Government
NIST Cybersecurity Insights · Ryan Galluzzo, Connie LaSalle, Andrew Regenscheid · indexed 2026-08-15 20:45 UTC
Today is the day! Digital Identity Guidelines, Revision 4 is finally here...it’s been an exciting journey and NIST is honored to be a part of it. What can we expect? Serving as a culmination of a nearly four-year collaborative process that included foundational research, two public drafts, and about 6,000 individual comments from the public, Revision 4 of Special Publication 800-63, Digital Identity Guidelines, intends to respond to the changing digital landscape that has emerged since the last…
P0
2025-07-31 12:00 UTC
Government
NIST Cybersecurity Insights · Katerina Megas, Julie Nethery Snyder , Bronwyn Patrick · indexed 2026-08-15 20:45 UTC
Thank you to everyone who participated in the Cyber AI Profile Workshop NIST hosted this past April! This work intends to support the cybersecurity and AI communities — and the input you provided during this workshop is critical. We are working to publish a Workshop Summary that captures themes and highlights from the event. In the interim, we would like to share a preview of what we heard. Background on the Cyber AI Profile Workshop ( watch the workshop introduction video) As NIST began explor…
P0
2025-07-31 04:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
When a clearly commented script revealed an attacker's tactics, Huntress prevented encryption. Read on to learn more about the evolution of recycled ransomware playbooks used by multiple threat actors.
P15
2025-07-30 07:46 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Deep dive into UNC2891’s multi‑stage bank intrusion: Raspberry Pi ATM implant, bind mount evasion, Dynamic DNS C2, and a CAKETAP move toward HSM manipulation.
P0
2025-07-30 04:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Transform raw Windows event data into actionable insights. Learn expert methodologies for intrusion analysis, authentication events, credential dumping, and RDP activity to stay ahead of threats.
P0
2025-07-25 07:51 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Think threat actors are unpredictable? The rise of intelligence-driven defense and the push for incident predictions might just give us the edge to know their next moves…long before they make it.
P0
2025-07-23 07:48 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Uncovering the validity of a PDF by utilizing some of the tools and methods to detect changes made to a PDF, and understand the limitations in proving PDF integrity.
P0
2025-07-22 09:45 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Enable real-time, token-based account security that stops withdrawal fraud before your brand, players, and their revenue are compromised.
P0
2025-07-21 21:34 UTC
Vendor Research
Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC
Posted by Matthew Suozzo, Google Open Source Security Team (GOSST)Today we're excited to announce OSS Rebuild, a new project to strengthen trust in open source package ecosystems by reproducing upstream artifacts. As supply chain attacks continue to target widely-used dependencies, OSS Rebuild gives security teams powerful data to avoid compromise without burden on upstream maintainers.The project comprises:Automation to derive declarative build definitions for existing PyPI (Python), npm (JS/T…
P0
2025-07-21 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
**[Mise à jour du 23 juillet 2025]** Le 20 juillet 2025, Microsoft a publié des correctifs pour une vulnérabilité de type limitation insuffisante d'un chemin d'accès à un répertoire restreint, aussi appelé *path traversal*, affectant SharePoint Enterprise Server 2016, SharePoint Server 2019 et...
P0
2025-07-18 04:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress has observed a new ransomware variant, Crux, being used in multiple incidents.
P15
2025-07-17 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn top cybercrime trends from Huntress’ 2025 survey of more than 500 American IT professionals. Plus, learn tips for improving your cybersecurity.
P0
2025-07-17 06:27 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Scammers are using tools like MaisonReceipts to create fake receipts and exploit brands. Uncover how this growing fraud ecosystem works behind the scenes.
P0
2025-07-17 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
When a threat actor exploited an MSP's RMM tool to target businesses, Huntress investigated and uncovered another eerily similar incident with key differences that reveal evolving tactics
P0
2025-07-14 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress is collaborating with Microsoft to help your business get the most out of your Microsoft security investments.
P0
2025-07-10 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress discovered active exploitation of Wing FTP Server RCE (CVE-2025-47812). Learn more about the injection flaw, attack timeline, forensic artifacts, and how to protect your organization.
P40
2025-07-08 17:36 UTC
Vendor Research
Google Online Security Blog · Google · indexed 2026-08-15 14:33 UTC
Posted by David Adrian, Javier Castro & Peter Kotwicz, Chrome Security Team Android recently announced Advanced Protection, which extends Google’s Advanced Protection Program to a device-level security setting for Android users that need heightened security—such as journalists, elected officials, and public figures. Advanced Protection gives you the ability to activate Google’s strongest security for mobile devices, providing greater peace of mind that you’re better protected against the most s…
P0
2025-07-08 08:07 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Combolists and ULP files circulate on the dark web as new leaks, but most of what they contain was stolen years earlier and recycled many times over.
P0
2025-07-07 12:00 UTC
Government
NIST Cybersecurity Insights · Michael Prebil · indexed 2026-08-15 20:45 UTC
A lot has changed in America’s cybersecurity workforce development ecosystem since 2016: employment in cybersecurity occupations has grown by more than 300,000 [1]; the number of information security degrees awarded annually has more than tripled to nearly 35,000 [2]; and a wide array of new technologies and risks have emerged. Five regional cybersecurity workforce partnerships supported by the 2016 RAMPS program pilot, administered by NIST’s NICE Program Office, have weathered the changes in c…
P0
2025-07-07 07:03 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Introducing BioConfirm - Enable real-time, token-based user account security that stops withdrawal fraud before your brand, customers’ trust, and revenue are compromised.
P0
2025-07-04 10:59 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Discover how attackers leverage Windows Kernel loaders and abuse digitally signed drivers to gain privileged access, disable security tools, and stealthily maintain control — bypassing traditional defenses and enabling advanced threat operations.
P0