Cybersecurity
1,758 publications classified by Officially as Cybersecurity, judged from each publication's own title and summary.
Our reading, not the publisher's. An organization that has claimed its profile can say what its own publications are about, and that will take precedence here. See everything published by organizations filed under Cybersecurity instead.
-
Соціальна інженерія у виконанні UAC-0145: компрометація у процесі працевлаштування
CERT-UA отримано інформацію щодо застосування просунутих методів соціальної інженерії кластером кіберзагроз UAC-0145 (субкластер UAC-0002, також відомий як Sandworm, APT44, Seashell Blizzard). …
Announcement Cybersecurity -
From Screen Share to Root Access: Breaking Down CVE-2026-43760 and CVE-2026-65400 on macOS
Apple’s latest macOS update addresses two vulnerabilities in its Screen Sharing server, including one that enables pre-authenticated remote code execution.
-
VU#987105: The nothings stb TrueType library, up to version 1.26, contains a heap buffer overflow vulnerability
Overview A heap buffer overflow vulnerability exists in the stb TrueType library created by nothings. Exploitation of this vulnerability can occur when handling malformed font data and may lead to ...
Advisory Cybersecurity -
Meet the Huntress MCP Server
Access your Huntress data easily with the Huntress MCP Server, connecting your AI assistant directly to your incidents, agents, billing, and more. No portal required.
-
The Good, the Bad and the Ugly in Cybersecurity – Week 32 (2026)
Snowflake hacker's guilty plea covers a 100M-record breach, Mythos 5 spends 34 hours trying to backdoor real code, and ChainDrop's worm spreads via npm.
-
CERT-SE:s veckobrev v.32
CERT-SE:s veckobrev är tillbaka från sommaruppehållet. Sommaren har bestått av flera förändringar, såsom att CERT-SE sedan den 1 juli är en del av Nationellt cybersäkerhetscenter (NCSC) vid Försvar...
Announcement Cybersecurity -
Veeam ONE 13 — Remote Unauthenticated Code Execution: 20260807004
Severity CRITICAL Threat Category Vulnerability (Remote Unauthenticated Code Execution) Affected Platforms Veeam ONE (versions 13.0.2.6723 and earlier Version 13 builds) […] The post Veeam ONE 13 —...
Announcement Cybersecurity -
Incident de cybersécurité affectant le site Internet www.mconcept.lu avec risque limité concernant des données de contact professionnelles
Le ministère de la Mobilité et des Travaux publics informe qu'un incident de cybersécurité a affecté le site Internet www.mconcept.lu.
Announcement Cybersecurity -
What Is Zero Trust Security? A Guide for Businesses
Zero trust security assumes no user or device is trusted by default. See how Huntress enforces the model with Managed EDR and ITDR for lean IT teams.
-
VU#487613: Alinto SOGo v5.12.7 vulnerable to cross-site scripting via malformed ICS calendar invitations
Overview A cross-site scripting (XSS) vulnerability in Alinto SOGo v5.12.7 allows attackers to achieve remote code execution by embedding malicious SVG (Scalable Vector Graphics) objects in ICS (iC...
Advisory Cybersecurity -
How we took malware advisories beyond npm
GitHub malware advisories no longer stop at npm. Here's how we wired OpenSSF's malicious-packages data into the Advisory Database, and why we built the pipeline paranoid. The post How we took malwa...
Security notice Cybersecurity -
Kwetsbaarheden in Adobe Campaign Classic
Organisaties die Adobe Campaign Classic gebruiken, doen er goed aan de nieuwste beveiligingsupdates zo snel mogelijk te installeren. In de software zijn ernstige kwetsbaarheden gevonden die een aan...
-
Mac Malware Drains Crypto Wallets Via Fake CAPTCHA Scam
A ClickFix scam tricked a Mac user into running a Terminal command that installed Go-based malware able to steal Keychain passwords and drain crypto wallets.
-
Nur 1,8 Prozent der Webseitenbetreiber nutzen security.txt – BSI und ACS raten zur Umsetzung
Nur 1,8 Prozent der Webseitenbetreiber in Deutschland stellen bislang eine security.txt bereit. Das zeigen Messungen des Bundesamt für Sicherheit in der Informationstechnik (BSI) im Rahmen des Cybe...
Announcement Cybersecurity -
Inside an Oracle Database SQL Injection Attack | Huntress
See how a SQL injection bug led to full OS-level RCE, as attackers abused Oracle Java Source to deploy the khunt post-exploitation toolkit.
-
July in cyberspace: hacked websites, service disruptions, and phishing emails
The Information System Authority (RIA) registered 1,044 cyber incidents in July. Over the course of the month, several websites experienced disruptions, defacements of Estonian websites became more...
Announcement Cybersecurity -
From Input to Impact: Secure AI Where It Runs
Defend the entire AI agentic stack across endpoints, identities, cloud, and apps with SentinelOne's unified platform.
-
Bank of America Phishing Email Delivers ScreenConnect Malware
A fake Bank of America phishing email kicks off a multi-stage malware infection chain. See how one convincing bank scam unravels.
-
37% of IT Security Teams Hit Burnout From Audit Demands
A Huntress survey of 504 IT leaders found that compliance demands caused burnout at 37% of orgs, delayed security initiatives at 34%, and cost 21% a contract.
-
Cyber Resilience Framework for Nigeria Communication Sector
Cyber Resilience Framework for Nigeria Communication Sector Onuoha Ugochukwu Tue, 04/08/2026 - 12:15 PM Status Published Guideline(s) Download Cyber Resilience Framework for Nigeria Communication S...
Announcement Cybersecurity -
Anti-Vishing Information Sharing via ASAP Available for Financial, Telecom and Investigation Data
The Financial Services Commission announced that the recently revised rules under the Special Act on the Prevention of Loss Caused by Telecommunications-based Financial Fraud and Refund for Loss (t...
-
Why App Control Fails Most Teams and How Managed ESPM Fixes It
App control works, but most solutions are built for enterprise budgets and headcount. See how Huntress Managed ESPM makes proactive endpoint hardening accessible for MSPs and small IT teams.
-
Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums
A malware campaign disguised as an “undetected” version of the Xeno Roblox script executor is directly affecting players looking to download a legitimate tool.
-
Mai Kraft appointed Director of RIA's National Cyber Security Centre
As of 1 August, Mai Kraft has assumed the position of Director of the National Cyber Security Centre of Estonia (NCSC-EE) at the Estonian Information System Authority (RIA), as well as Deputy Direc...
Announcement Cybersecurity -
This month in security with Tony Anscombe – July 2026 edition
OpenAI models going rogue, the first documented agentic ransomware operation, and an emergent AI-driven supply chain threat made for a packed July roundup
-
Kwetsbaarheid in SolarWinds Web Help Desk: update nu
Er is een ernstige kwetsbaarheid, CVE-2026-28323, gevonden in SolarWinds Web Help Desk met een CVSS-score van 9.8. Deze kwetsbaarheid betreft een beveiligingsprobleem in de SAML 2.0 authenticatie, ...
-
The Good, the Bad and the Ugly in Cybersecurity – Week 31 (2026)
Police flag 4,000 URLs to disrupt The Com, theft victims sue Apple over a $1.8M wallet scam, and OpenAI and Anthropic models reach real systems in cyber tests.
-
Device Code Phishing Keeps Evolving. Here’s What to Watch For
Huntress is tracking an evolving wave of device code phishing that abuses trusted Microsoft 365 sign-in flows. Learn the signals defenders should watch for and how to respond.
-
Kritieke kwetsbaarheden in Adobe Campaign Classic
Organisaties die Adobe Campaign Classic gebruiken, doen er goed aan de nieuwste beveiligingsupdates zo snel mogelijk te installeren. In de software zijn twee ernstige kwetsbaarheden gevonden die ee...
-
G7 2026 Cross-Border Coordination Exercise (CBCE)
The G7 Cyber Expert Group (CEG) successfully concluded its 2026 Cross-border coordination exercise (CBCE) on May 18, 2026. This exercise demonstrates the Group’s ongoing commitment to strengthening...
-
Neue e-dec Systemzertifikate zur verschlüsselten Übermittlung von Zollanmeldungen (Reminder)
Am 24.08.2026 laufen diverse e-dec Systemzertifikate auf der Produktion- und Abnahmeumgebung aus. Es handelt sich um Zertifikate, welche Zollkunden benutzen, um Zollanmeldungen per Mail elektronisc...
Announcement Cybersecurity -
Introducing Tactics: See What Adversaries Do After They’re Inside
GreyNoise Tactics gives anyone running a Deception Sensor visibility into what adversaries do after initial compromise, automatically mapping qualifying sessions to the MITRE ATT&CK framework.
-
EBA, EIOPA and ESMA call for enhanced governance and consistent supervision to mitigate ICT risks from frontier AI models in the EU financial sector
EBA, EIOPA and ESMA call for enhanced governance and consistent supervision to mitigate ICT risks from frontier AI models in the EU financial sector 31 July 2026 Digital Finance and Innovation Join...
-
Incident Response Plans: What to Include & Why They Matter
An incident response plan is your organization's playbook for surviving a cyberattack. Learn what to include and how Huntress helps you stay ready
-
Huntress hits an inflection point
CEO Kyle Hanslovan outlines how Huntress is evolving its research-led strategy, adopting AI with human oversight, and expanding its partner network to protect businesses against rapid, automated cy...
-
$250M ARR Was Never the Goal. It Came From Staying True to Our Mission.
Hitting $250M ARR is a milestone, but it wasn't the goal. CEO Kyle Hanslovan reflects on Huntress' mission to protect the 99% and why staying true to it remains his top priority."
-
Het nieuwe Trojaanse paard zit in je dependencies
Wanneer je als ontwikkelaar code, configuratie of tooling uit een externe bron haalt, dan vertrouw je die bron. Doe je dat zonder te verifiëren wie erachter zit en wat je binnenhaalt, dan zet je on...
-
Hacker Summer Camp: What First-Timers Actually Need to Know | Huntress
Heading to Vegas for Hacker Summer Camp? Here are some insider tips for first-timers on navigating DEF CON, Black Hat, and BSides like a pro.
-
UNODC and the EU warn of rising human trafficking for criminal activities in scam centres
Human trafficking for forced criminality is increasing across the world, with authorities raising particular concern about a rapidly growing form of exploitation: trafficking to commit cyber-enable...
Announcement Cybersecurity -
Enhanced Detection Engineering at Scale in the Agentic Era
Check out GreyNoise's new Head of Adversary Engagement, Mark Mager, on why traditional detection engineering can't keep pace with CVE growth — and the agentic pipeline replacing it.
-
Kritieke kwetsbaarheden in VMware vCenter en ESX-producten: update onmiddellijk
Er zijn meerdere kwetsbaarheden gevonden in VMware vCenter en ESX-producten, waaronder CVE-2026-59309 en CVE-2026-59310 met een CVSS-score van 9.8. Deze kwetsbaarheden zijn beoordeeld als ernstig m...
-
NSA collaborates with CISA to co-author the updated Software Bill of Materials (SBOM)
FORT MEADE, Md. — Today, the National Security Agency (NSA), and others join with Cybersecurity and Infrastructure Security Agency (CISA) to release the joint Cybersecurity Information Sheet, “2026...
Announcement Cybersecurity -
Introducing Huntress Webhooks. Get Real-Time Security Alerts.
Huntress Webhooks push incidents and escalations straight to Slack, your PSA, or SIEM in real time with no polling. See how you can set them up in minutes.
-
Reverse Engineering the Six Stages of MacSync Stealer and RAT
We reverse-engineered MacSync, a six-stage macOS stealer and RAT, recovered from attacker infrastructure after the victim’s host was taken offline.
-
Critical vulnerability in WordPress Core : 20260729003
Critical “wp2shell” REST API Route Confusion and SQL Injection Vulnerabilities in WordPress Core Severity CRITICAL (CVSS 10.0) Threat Category Vulnerability […] The post Critical vulnerability in W...
Announcement Cybersecurity