SecurityWeek
Threat actors have been using long-dormant GitHub accounts to automate reconnaissance against organizations, according to research from Datadog. The activity has continued for months and involves effo...
11 Jul 20262 min read
Read article →Dark Reading
Jen Ellis has been recognized as a Member of the Order of the British Empire, highlighting her work on behalf of the cybersecurity community and the security researchers whose findings help protect us...
11 Jul 20262 min read
Read article →The Register - Security
Microsoft has analyzed a Windows backdoor that combines disk wiping, irreversible file encryption, surveillance and remote-control features in a single modular package. The company calls the Golang-ba...
11 Jul 20262 min read
Read article →BleepingComputer
Security researchers have disclosed six vulnerabilities in U-Boot, the widely used open-source bootloader found in embedded Linux systems, enterprise server management controllers, networking gear, in...
10 Jul 20262 min read
Read article →The Hacker News
Progress Software is urging ShareFile customers to shut down Windows servers running Storage Zone Controllers after the company said it was responding to a credible external security threat. The vendo...
10 Jul 20262 min read
Read article →NCSC (UK)
The UK’s National Cyber Security Centre (NCSC) says its Cyber Essentials Pathways proof of concept has shown that some organisations can meet the scheme’s security goals through alternative controls,...
10 Jul 20262 min read
Read article →SecurityWeek
Israeli startup QIZ Security said it has secured $17 million in seed funding to support its cryptographic posture management and post-quantum cryptography (PQC) platform. The round was led by Bessemer...
9 Jul 20262 min read
Read article →Dark Reading
Security analysts say organizations should not assume they are safe simply because they are not part of a critical infrastructure sector. Recent guidance tied to Iranian cyber activity suggests that a...
9 Jul 20262 min read
Read article →The Register - Security
A leaked transcript and supporting artifacts suggest that an unidentified US county paid $1 million to an extortion group after criminals claimed to have taken more than 2 TB of data. The episode, des...
9 Jul 20262 min read
Read article →Krebs on Security
A cybersecurity startup called IRIS C2 is advertising large payments for zero-day exploits and other offensive capabilities, according to its website and social media accounts. Public records and corp...
8 Jul 20262 min read
Read article →BleepingComputer
Mount Royal University in Calgary has confirmed that it suffered a cyberattack in June that led to unauthorized access to some data and disruption across several campus systems.In a notice posted on i...
8 Jul 20262 min read
Read article →The Hacker News
Sophos has reported that several popular AI coding assistants are generating endpoint activity that resembles attacker behavior closely enough to trigger security controls designed for intrusion detec...
8 Jul 20262 min read
Read article →