Malware used by North Korea's Lazarus group negotiated its command channel using a post-quantum key exchange before pulling down a Windows zero-day exploit, in a campaign against defense and aerospace ...
A previously unseen NFC relay malware family has been deployed alongside a remote access trojan in a single 13-minute phone call, letting a fraudster take out a loan in the victim's name and relay ...
The US National Institute for Standards and Technology wants to modernize its National Vulnerability Database to embrace AI-powered vulnerability research ...
Gunra actors are using stealth to exfiltrate vast volumes of data from Microsoft services, US and Korean agencies have warned ...
The Polish CERT (CERT.PL) has published details of another attack on its energy infrastructure which took place during a suspected Russian cyber campaign in December 2025.
Microsoft turned up the heat on sysadmins for the second month in a row on August 11 with a Patch Tuesday comprising 400 CVEs, including one actively exploited zero-day vulnerability.
The Middle East conflict has significantly ramped up the volume of cyber threats firms across the Western world are facing both directly and through their supply chain partners. In response, ...
Daybreak Blue removes some OpenAI-made guardrails while Daybreak Red grants the use of cyber-focused frontier AI models ...
Manifold Security said it reported the issue to Cursor on July 20 and published its findings on August 10. Cursor shipped a ...
A data breach at one of the world’s biggest logistics companies appears to have had a significant impact on its wider supply chain ecosystem of customers. Ceva Logistics is a subsidiary of the French ...
Varonis Threat Labs disclosed the flaw, which it named RovoBlast, to Atlassian and published its analysis on August 7 after ...
The US authorities have sanctioned an Iranian firm accused of moving over $6bn in illegal blockchain flows over the past two ...