Cybersecurity
1,765 publications classified by Officially as Cybersecurity, judged from each publication's own title and summary.
Our reading, not the publisher's. An organization that has claimed its profile can say what its own publications are about, and that will take precedence here. See everything published by organizations filed under Cybersecurity instead.
-
Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack
Key Points Introduction Since early 2026, Check Point Research has tracked a wave of the Operation Dream Job campaign. This wave primarily targeted the defense sector worldwide, with a pa...
-
VU#431093: TCG TPM 2.0 reference code found vulnerable to information leakage and timing side-channel attacks
Overview Two vulnerabilities have been identified in the Trusted Platform Module (TPM) 2.0 reference implementation: CVE-2026-6726 – Information leakage via falsified TPM keys. CVE-2026-6727 – A ti...
-
Microsoft 製品の脆弱性対策について(2026年8月)
Announcement Cybersecurity -
Privacy Days Praha 2026: Největší česká konference věnovaná osobním údajům a digitální ekonomice spouští registraci
Jubilejní 10. ročník výroční konference Spolku pro ochranu osobních údajů zabývající se zpracováním osobních údajů, nakládáním s daty a kybernetickou bezpečností se bude konat ve dnech 1. a 2. říjn...
Announcement Cybersecurity -
OSIPTEL ordenará bloqueo de 360 000 celulares en agosto, ¿qué hacer si recibes el mensaje con este anuncio?
Durante este mes de agosto se ordenará un nuevo bloqueo de 360 000 equipos móviles que no figuran en la lista blanca del Registro Nacional de Equipos Terminales Móviles para la Seguridad (Renteseg)...
Announcement Cybersecurity -
Kimwolf v7: An Evolution of the Kimwolf Botnet
Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing. The post Kimwolf v7: An Evolution of the Kimwolf Botnet appea...
-
Guidance: Interception, monitoring and security of prisoner communications policy framework
Rules and guidance for HMPPS staff performing duties relating to the interception and monitoring of prisoner communications, and communication systems security.
-
SECURING UGANDA’S DIGITAL FUTURE: INAUGURAL NATIONAL CYBERSECURITY CONFERENCE SETS THE AGENDA FOR COLLECTIVE ACTION
KAMPALA, August 11, 2026 – Uganda’s digital economy grows, so does the responsibility to ensure that citizens can use digital services safely and with confidence. This was the central message at th...
Announcement Cybersecurity -
NSA Joins FBI and Others in Releasing Guidance to Defend Against Gunra Ransomware
FORT MEADE, Md. — Today, the National Security Agency (NSA) joins the Federal Bureau of Investigation (FBI) and others in releasing a joint Cybersecurity Advisory, “#StopRansomware: Gunra Ransomwar...
Announcement Cybersecurity -
VU#614868: OpenCart ecommerce platform contains directory traversal vulnerability
Overview The OpenCart v4.2.0.0 extension installer contains a directory traversal vulnerability. The extension installation process extracts uploaded .zip files then uses the zip entry filenames as...
Advisory Cybersecurity -
10th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 10th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES North Carolina Ports, the US authority operating...
-
Five Years, 88,000 Backdoors, and a Pair of Handcuffs: Inside the Global Manhunt That Ended in an Arrest
Go inside Huntress and the FBI’s five-year pursuit of Silk Typhoon, from 88,000 Exchange backdoors to an arrest and a wider fight against cybercrime.
-
Соціальна інженерія у виконанні UAC-0145: компрометація у процесі працевлаштування
CERT-UA отримано інформацію щодо застосування просунутих методів соціальної інженерії кластером кіберзагроз UAC-0145 (субкластер UAC-0002, також відомий як Sandworm, APT44, Seashell Blizzard). …
Announcement Cybersecurity -
From Screen Share to Root Access: Breaking Down CVE-2026-43760 and CVE-2026-65400 on macOS
Apple’s latest macOS update addresses two vulnerabilities in its Screen Sharing server, including one that enables pre-authenticated remote code execution.
-
VU#987105: The nothings stb TrueType library, up to version 1.26, contains a heap buffer overflow vulnerability
Overview A heap buffer overflow vulnerability exists in the stb TrueType library created by nothings. Exploitation of this vulnerability can occur when handling malformed font data and may lead to ...
Advisory Cybersecurity -
Meet the Huntress MCP Server
Access your Huntress data easily with the Huntress MCP Server, connecting your AI assistant directly to your incidents, agents, billing, and more. No portal required.
-
The Good, the Bad and the Ugly in Cybersecurity – Week 32 (2026)
Snowflake hacker's guilty plea covers a 100M-record breach, Mythos 5 spends 34 hours trying to backdoor real code, and ChainDrop's worm spreads via npm.
-
CERT-SE:s veckobrev v.32
CERT-SE:s veckobrev är tillbaka från sommaruppehållet. Sommaren har bestått av flera förändringar, såsom att CERT-SE sedan den 1 juli är en del av Nationellt cybersäkerhetscenter (NCSC) vid Försvar...
Announcement Cybersecurity -
Veeam ONE 13 — Remote Unauthenticated Code Execution: 20260807004
Severity CRITICAL Threat Category Vulnerability (Remote Unauthenticated Code Execution) Affected Platforms Veeam ONE (versions 13.0.2.6723 and earlier Version 13 builds) […] The post Veeam ONE 13 —...
Announcement Cybersecurity -
Incident de cybersécurité affectant le site Internet www.mconcept.lu avec risque limité concernant des données de contact professionnelles
Le ministère de la Mobilité et des Travaux publics informe qu'un incident de cybersécurité a affecté le site Internet www.mconcept.lu.
Announcement Cybersecurity -
What Is Zero Trust Security? A Guide for Businesses
Zero trust security assumes no user or device is trusted by default. See how Huntress enforces the model with Managed EDR and ITDR for lean IT teams.
-
VU#487613: Alinto SOGo v5.12.7 vulnerable to cross-site scripting via malformed ICS calendar invitations
Overview A cross-site scripting (XSS) vulnerability in Alinto SOGo v5.12.7 allows attackers to achieve remote code execution by embedding malicious SVG (Scalable Vector Graphics) objects in ICS (iC...
Advisory Cybersecurity -
How we took malware advisories beyond npm
GitHub malware advisories no longer stop at npm. Here's how we wired OpenSSF's malicious-packages data into the Advisory Database, and why we built the pipeline paranoid. The post How we took malwa...
Security notice Cybersecurity -
Kwetsbaarheden in Adobe Campaign Classic
Organisaties die Adobe Campaign Classic gebruiken, doen er goed aan de nieuwste beveiligingsupdates zo snel mogelijk te installeren. In de software zijn ernstige kwetsbaarheden gevonden die een aan...
-
Mac Malware Drains Crypto Wallets Via Fake CAPTCHA Scam
A ClickFix scam tricked a Mac user into running a Terminal command that installed Go-based malware able to steal Keychain passwords and drain crypto wallets.
-
Nur 1,8 Prozent der Webseitenbetreiber nutzen security.txt – BSI und ACS raten zur Umsetzung
Nur 1,8 Prozent der Webseitenbetreiber in Deutschland stellen bislang eine security.txt bereit. Das zeigen Messungen des Bundesamt für Sicherheit in der Informationstechnik (BSI) im Rahmen des Cybe...
Announcement Cybersecurity -
Inside an Oracle Database SQL Injection Attack | Huntress
See how a SQL injection bug led to full OS-level RCE, as attackers abused Oracle Java Source to deploy the khunt post-exploitation toolkit.
-
July in cyberspace: hacked websites, service disruptions, and phishing emails
The Information System Authority (RIA) registered 1,044 cyber incidents in July. Over the course of the month, several websites experienced disruptions, defacements of Estonian websites became more...
Announcement Cybersecurity -
From Input to Impact: Secure AI Where It Runs
Defend the entire AI agentic stack across endpoints, identities, cloud, and apps with SentinelOne's unified platform.
-
Bank of America Phishing Email Delivers ScreenConnect Malware
A fake Bank of America phishing email kicks off a multi-stage malware infection chain. See how one convincing bank scam unravels.
-
37% of IT Security Teams Hit Burnout From Audit Demands
A Huntress survey of 504 IT leaders found that compliance demands caused burnout at 37% of orgs, delayed security initiatives at 34%, and cost 21% a contract.
-
Cyber Resilience Framework for Nigeria Communication Sector
Cyber Resilience Framework for Nigeria Communication Sector Onuoha Ugochukwu Tue, 04/08/2026 - 12:15 PM Status Published Guideline(s) Download Cyber Resilience Framework for Nigeria Communication S...
Announcement Cybersecurity -
Anti-Vishing Information Sharing via ASAP Available for Financial, Telecom and Investigation Data
The Financial Services Commission announced that the recently revised rules under the Special Act on the Prevention of Loss Caused by Telecommunications-based Financial Fraud and Refund for Loss (t...
-
Why App Control Fails Most Teams and How Managed ESPM Fixes It
App control works, but most solutions are built for enterprise budgets and headcount. See how Huntress Managed ESPM makes proactive endpoint hardening accessible for MSPs and small IT teams.
-
Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums
A malware campaign disguised as an “undetected” version of the Xeno Roblox script executor is directly affecting players looking to download a legitimate tool.
-
Mai Kraft appointed Director of RIA's National Cyber Security Centre
As of 1 August, Mai Kraft has assumed the position of Director of the National Cyber Security Centre of Estonia (NCSC-EE) at the Estonian Information System Authority (RIA), as well as Deputy Direc...
Announcement Cybersecurity -
This month in security with Tony Anscombe – July 2026 edition
OpenAI models going rogue, the first documented agentic ransomware operation, and an emergent AI-driven supply chain threat made for a packed July roundup
-
Kwetsbaarheid in SolarWinds Web Help Desk: update nu
Er is een ernstige kwetsbaarheid, CVE-2026-28323, gevonden in SolarWinds Web Help Desk met een CVSS-score van 9.8. Deze kwetsbaarheid betreft een beveiligingsprobleem in de SAML 2.0 authenticatie, ...
-
The Good, the Bad and the Ugly in Cybersecurity – Week 31 (2026)
Police flag 4,000 URLs to disrupt The Com, theft victims sue Apple over a $1.8M wallet scam, and OpenAI and Anthropic models reach real systems in cyber tests.
-
Device Code Phishing Keeps Evolving. Here’s What to Watch For
Huntress is tracking an evolving wave of device code phishing that abuses trusted Microsoft 365 sign-in flows. Learn the signals defenders should watch for and how to respond.
-
Kritieke kwetsbaarheden in Adobe Campaign Classic
Organisaties die Adobe Campaign Classic gebruiken, doen er goed aan de nieuwste beveiligingsupdates zo snel mogelijk te installeren. In de software zijn twee ernstige kwetsbaarheden gevonden die ee...
-
G7 2026 Cross-Border Coordination Exercise (CBCE)
The G7 Cyber Expert Group (CEG) successfully concluded its 2026 Cross-border coordination exercise (CBCE) on May 18, 2026. This exercise demonstrates the Group’s ongoing commitment to strengthening...
-
Neue e-dec Systemzertifikate zur verschlüsselten Übermittlung von Zollanmeldungen (Reminder)
Am 24.08.2026 laufen diverse e-dec Systemzertifikate auf der Produktion- und Abnahmeumgebung aus. Es handelt sich um Zertifikate, welche Zollkunden benutzen, um Zollanmeldungen per Mail elektronisc...
Announcement Cybersecurity -
Introducing Tactics: See What Adversaries Do After They’re Inside
GreyNoise Tactics gives anyone running a Deception Sensor visibility into what adversaries do after initial compromise, automatically mapping qualifying sessions to the MITRE ATT&CK framework.
-
EBA, EIOPA and ESMA call for enhanced governance and consistent supervision to mitigate ICT risks from frontier AI models in the EU financial sector
EBA, EIOPA and ESMA call for enhanced governance and consistent supervision to mitigate ICT risks from frontier AI models in the EU financial sector 31 July 2026 Digital Finance and Innovation Join...
-
Incident Response Plans: What to Include & Why They Matter
An incident response plan is your organization's playbook for surviving a cyberattack. Learn what to include and how Huntress helps you stay ready