Cybersecurity
1,758 publications classified by Officially as Cybersecurity, judged from each publication's own title and summary.
Our reading, not the publisher's. An organization that has claimed its profile can say what its own publications are about, and that will take precedence here. See everything published by organizations filed under Cybersecurity instead.
-
Mandatory caller ID is proving effective: Fraudulent calls made in the name of public authorities have fallen by over 75 per cent
Measures to combat fraudulent calls made in the name of public authorities are proving effective. The number of reports fell by over 75 per cent in July following the extension of the mandatory cal...
Announcement Cybersecurity -
Real stories show no one is just a number this Scams Awareness Week
Four courageous Australians share their stories during Scams Awareness Week 2026, and join with the National Anti-Scam Centre in encouraging people to remember three simple steps: Stop. Check. Prot...
Announcement Cybersecurity -
Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain
Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security controls The post Connecting the Dots: Securing the Over...
-
What Is Account Takeover Fraud? A Comprehensive Guide | Huntress
Account takeover (ATO) fraud happens when attackers steal login credentials to access accounts. Learn how to detect and prevent account takeover fraud.
-
RMM Abuse: How Attackers Exploit Remote Access Tools | Huntress
RMM abuse jumped 277% & now shows up nearly 40% of Huntress investigations. See how attackers exploit trusted remote access tools, and how to stop it.
-
VU#756733: Retraction of "Calix GS7 XGS GS5239XG residential router contains missing authentication vulnerability"
Overview The Calix GS7 XGS GS5239XG router running firmware EXOS/6.6.47 contains a missing authentication vulnerability that exposes its UPnP (Universal Plug and Play) WANIPConnection service on th...
-
The Good, the Bad and the Ugly in Cybersecurity – Week 34 (2026)
U.S. indicts Iranian cyber espionage operations, Medusa ransomware breaches 500 organizations, and attackers exploit a critical Windows protocol flaw.
-
CERT-SE:s veckobrev v.34
I veckans brev kan du läsa om ett flertal intrång, störningar i system samt om sårbarheter som utnyttjas aktivt av hotaktörer.
Announcement Cybersecurity -
The invisible passenger in your car
Kaspersky expert has discovered new Android malware designed to serve ads and build a proxy botnet. It's delivered through legitimate software for DoFun head units.
-
NITDA, Budget Office Inaugurate Multi-Agency Technical Committee to advance Sovereign Cloud Implementation
By Inyene Ibanga The National Information Technology Development Agency (NITDA) and the Budget Office of the Federation (BOF), have formally inaugurated the Joint Technical Committee of the Nationa...
Announcement Cybersecurity -
Is Cyber missing the Marque?
In this week's newsletter, new author Mick Baccio introduces himself and explores the operational and security implications of the new White House memorandum regarding private sector participation ...
-
From all-or-nothing to task-based OAuth consent
Cloudflare OAuth now supports optional scopes, giving users more control over what an app can access and helping developers build secure consent flows around the task at hand.
-
BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive
Research by: Jiří Vinopal (@vinopaljiri) Abstract What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation drive...
-
Kritisk sårbarhet i Citrix NetScaler
Citrix publiserte onsdag 19. august detaljer om to nye sårbarheter i NetScaler ADC og NetScaler Gateway. NSM forventer at sårbarhetene vil bli utnyttet.
Announcement Cybersecurity -
Kritisk sårbarhet i Citrix NetScaler ADC och NetScaler Gateway
Citrix har publicerat information om en kritisk sårbarhet som påverkar Citrix NetScaler ADC och NetScaler Gateway. Sårbarheten, CVE-2026-19490, har fått CVSS v.4-klassning på 9.3. [1, 2]
Announcement Cybersecurity -
Podatności w oprogramowaniu ATutor
W oprogramowaniu ATutor wykryto 13 podatności różnego typu (od CVE-2026-64960 do CVE-2026-64972)
Announcement Cybersecurity -
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities
The newly identified SPECTRE implant represents an evolution in commodity intrusion tooling, integrating cross-platform C2 operations, process injection, credential theft, anti-analysis protections...
-
Identity Abuse Through Trusted Communication Channels
Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies. The post Identity Abuse Through Trusted Communicati...
-
Meerdere kwetsbaarheden in Apple macOS Tahoe
Er zijn diverse kwetsbaarheden gevonden in Apple macOS Tahoe, waaronder CVE-2026-65346 met een hoge CVSS-score van 8.8. Deze kwetsbaarheden betreffen geheugenbeheer en verwerking van webcontent wat...
-
Ernstige kwetsbaarheden in Apple iOS en iPadOS
Apple heeft diverse kwetsbaarheden opgelost in iOS en iPadOS, waaronder CVE-2026-3783 en CVE-2026-43757 met CVSS-scores tot 9.8. Deze kwetsbaarheden zijn beoordeeld als middelmatig qua kans op misb...
-
FIRST Unveils VulnOptiCON 2026 to Address the Future of Vulnerability, Threats and Cybersecurity Risk
Global security practitioners convene to advance vulnerability tracking and exploitation predictability, and explore security risks of Artificial Intelligence (AI)
Announcement Cybersecurity -
NSA and Others Release Report on Active Threats of Programmable Logic Controllers
FORT MEADE, Md. — (August 19, 2026) Today, the National Security Agency (NSA) and other co-sealing agencies released the Cybersecurity Advisory (CSA), "Defending Against an Active Threat to Siemens...
Announcement Cybersecurity -
VU#874418: RDK-B WebUI contains multiple vulnerabilities
Overview RDK Central RDK-B WebUI version, rdkb-2025q4-kirkstone, contains multiple vulnerabilities involving memory corruption, improper authentication, race conditions, and insufficient input vali...
-
CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
On August 19, 2026, a security advisory was published for CVE-2026-19490, a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carr...
Cybersecurity 2 versions -
2026-010: Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway
On 19 August 2026, Citrix published a security advisory addressing multiple critical vulnerabilities in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). CERT-EU ...
Advisory Cybersecurity -
A revisit of remote Spectre attacks on Cloudflare Workers
In 2024 and 2025, we reassessed remote Spectre attacks on our Workers infrastructure. We share details about the new attack primitives like Spectre gadgets, remote timers, achieving co-location and...
-
Post-DEF CON Phishing Uses Malicious Google Doc to Deliver Malware
Huntress researcher uncovers post-Black Hat & DEF CON phishing campaign using X DMs & malicious documents to deliver AMOS, NetSupport RAT, and other malware.
-
Rapid7 and Licencias OnLine Partner to Accelerate Cybersecurity Maturity across Latin America
Cássio De Alcântara is Director, LATAM Sales at Rapid7. Across Latin America, organizations are embracing cloud, AI, and digital transformation to drive innovation and business growth. These techno...
Cybersecurity 2 versions -
Podatności w oprogramowaniu nnn
W oprogramowaniu nnn wykryto 4 podatności różnego typu (od CVE-2026-65609 do CVE-2026-65612)
Announcement Cybersecurity -
Fake AI, real malware: Attackers impersonating AI brands
A year of MDR casework shows attackers repeatedly exploiting demand for AI tools
-
Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)
In August 2026, the actor TheHatman claimed to have stolen large volume of credentials from organizations' Microsoft Entra tenants. We provide guidance on mitigating large-scale credential attacks....
-
BGP Role model: tracking the adoption of RFC 9234
RFC 9234 lets routers reject route leaks on their own, using BGP Roles and the Only to Customer attribute. We measured who has deployed it, and found two Tier 1 networks unexpectedly stripping OTC.
-
Kritieke SQL-injectie in GeoTools open source Java-bibliotheek: update onmiddellijk
Er is een ernstige kwetsbaarheid ontdekt in GeoTools. Deze kwetsbaarheid betreft een ZeroDay SQL-injectie met een hoge CVSS-score van 9.8. Het NCSC beoordeelt de kans op misbruik als medium en de m...
-
Meerdere kwetsbaarheden in Adobe Commerce: update onmiddellijk
Er zijn meerdere kwetsbaarheden gevonden in Adobe Commerce. Onder de kwetsbaarheden is er één met een CVSS-score van 9.1. Deze heeft het kenmerk CVE-2026-71362. Er is momenteel geen melding van act...
-
Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect
Research by: Jaromír Hořejší (@JaromirHorejsi) Key points Introduction We first noticed a ransomware family called StopAndProtect in the middle of May 2026. Further analysis of the infrastructure r...
-
New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles
You can’t patch everything. So what do you fix first? Findings in Q2 2026 have changed traditional answers. The latest Quarterly Threat Landscape Report from Rapid7 Labs shows vulnerability disclos...
Cybersecurity 2 versions -
ATENȚIE! STISC atenționează despre atacuri phishing!
ATENȚIE! STISC atenționează despre atacuri phishing! ion.buga Mar, 08/18/2026 - 14:37
Announcement Cybersecurity -
Podatność w oprogramowaniu Carbone
W oprogramowaniu Carbone wykryto podatność typu Improper handling of highly compressed data (data amplification) (CVE-2026-18929).
Announcement Cybersecurity -
Charities face increasingly complex attacks, warns regulator
Charity Commission points to structural vulnerabilities in the regulation of some charity services
-
17th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 17th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Colombia’s Ministry of Justice has experien...
-
Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline
Operation ASTERIX overviewRapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation. The server contained raw phone-number datasets, ...
-
Call for evidence on the impact and effectiveness of Sections 1 to 13 of the Telecommunications (Security) Act 2021
Call for evidence to inform the statutory review of the telecommunications security framework.
-
How QR-code phishing can slip past corporate security measures
Quishing has become a popular alternative to traditional phishing. Here’s how businesses can close the gap.
-
Africa’s Cybersecurity Challenge Is Bigger Than Access to Technology
Gopan Sivasankaran is Rapid7's Regional Director, Middle East & Africa.Across Egypt, Nigeria, and Kenya, organizations are expanding their use of cloud infrastructure, artificial intelligence, ...
-
MacSync Stealer: How a Google Search for Claude Led to a macOS Infostealer
Huntress SOC analysts reverse engineer MacSync Stealer, a macOS infostealer spread through fake Claude Code download pages. Watch the full analysis.
-
A heap of overflow in August’s Patch Tuesday haul
421 CVEs, a relatively small set of Edge patches, and two spicy stragglers
-
A New Way to Navigate GreyNoise
Today, we’re introducing a redesigned GreyNoise Visualizer that makes it easier to navigate those capabilities and brings related workflows together in one place.
-
Cyberbeveiligingswet en Wet weerbaarheid kritieke entiteiten vanaf vandaag van kracht
Vanaf vandaag, 15 augustus 2026, gelden de Cyberbeveiligingswet (Cbw) en de Wet weerbaarheid kritieke entiteiten (Wwke). Deze wetten versterken de digitale en fysieke weerbaarheid van organisaties ...
Announcement Cybersecurity