Cybersecurity
1,758 publications classified by Officially as Cybersecurity, judged from each publication's own title and summary.
Our reading, not the publisher's. An organization that has claimed its profile can say what its own publications are about, and that will take precedence here. See everything published by organizations filed under Cybersecurity instead.
-
DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
A new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy inst...
Cybersecurity 2 versions -
Ruští aktéři cílí na uživatele Signalu. NÚKIB vydává analýzu a doporučení, jak si aplikaci zabezpečit
Národní úřad pro kybernetickou a informační bezpečnost (NÚKIB) upozorňuje na cílené phishingové kampaně zaměřené na uživatele komunikační aplikace Signal. …
Announcement Cybersecurity -
CERT-SE:s veckobrev v.36
Den 13 september är det val i Sverige och Nationellt cybersäkerhetscenter (NCSC) bevakar hotläget från ett cybersäkerhetsperspektiv. NCSC:s chef John Billow berättar om uppdraget i Sveriges Radios ...
Announcement Cybersecurity -
Angry Birds: Toy Ghouls’ new toys
Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and-control server; the other uses the Matr...
-
Interinfo|DreamMaker - 2 Vulnerabilities
Announcement Cybersecurity -
Managed EDR: What It Is & How to Choose a Provider
Huntress breaks down what managed EDR is, how it differs from unmanaged, and what to look for when choosing a provider for your business.
Cybersecurity 3 versions -
Introducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak models
Use production traffic and security signals to prioritize findings, prepare edge mitigations when safe, and propose code patches. By combining WAF data with OpenAI Daybreak models, Vulnerability Di...
-
The story behind the intelligence
From engaging with cybercriminals to surviving a live Flamin’ Hot Cheetos taste test, Hazel reflects on the latest Beers with Talos with Azim, where they cover the full spectrum of what it takes to...
-
VU#889462: Casdoor authentication server is vulnerable to authorization bypass
Casdoor is an open-source Access Management (IAM) platform used to manage web applications. An authorization bypass vulnerability affects Casdoor versions up to v4.2.0. …
-
Active Exploitation of Vulnerabilities in SonicWall SMA1000 Series
Attackers are exploiting vulnerabilities in SonicWall SMA1000 Series appliances to gain unauthorised access to sensitive functionalities and execute arbitrary operating system (OS) commands.
Announcement Cybersecurity -
How Microsoft’s Physical Security Engineering Team scaled hybrid operations with Azure Arc and Azure Virtual Desktop
Learn how Microsoft used Azure Arc and Azure Virtual Desktop to simplify hybrid security operations, improve visibility, and scale globally. The post How Microsoft’s Physical Security Engineering T...
-
NSA Highlights Cyber Hygiene Best Practices Effective Against AI-Enhanced Targeting
FORT MEADE, Md. — Today, the National Security Agency (NSA) is releasing the Cybersecurity Information Sheet (CSI), “Best Practices for Cyber Hygiene.”
Announcement Cybersecurity -
Podatność w oprogramowaniu OptimiDoc Server (On-Premise)
W oprogramowaniu OptimiDoc Server (On-Premise) wykryto podatność polegającą na przechowywaniu poświadczeń w jawnej formie (CVE-2026-15933).
Announcement Cybersecurity -
Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt operations. The post Attackers Expose Ongoing AI Tool Use ...
-
August in cyberspace: service disruptions, ransomware attacks, and phishing messages
In August, the Information System Authority registered 899 cyber incidents with an impact. Over the course of the month, there were disruptions to several key services, a school in Harju County was...
Announcement Cybersecurity -
La AEMPS informa de un riesgo de acceso no autorizado en el sistema Albert e-motion M25 de accionamiento adicional para sillas de ruedas
Generar PDF Fecha de publicación: 03 de septiembre de 2026 Categoría: productos sanitarios, seguridad Referencia: PS, 38/2026 El fabricante ha recibido dos informes de intentos de piratería informá...
Announcement Cybersecurity -
Lärdomar från Polen: frontlinjen för hybridhot
Erfarenheter från Polen visar hur civila samhällsfunktioner hamnar i frontlinjen för hybridhot. Angrepp mot energi, transporter, sjukvård och digital infrastruktur har kombinerats med otillbörlig i...
Announcement Cybersecurity -
CRPC Informs of a Potential Security Incident in a CRPC Information System
With particular attention to data security, the Consumer Rights Protection Centre (CRPC) informs the public of a recently identified data security incident…
Announcement Cybersecurity -
Critical Authentication Bypass in Proxmox Virtual Environment 7.x and 8.0 (CVE-2023-54391) – 20260902007
Severity CRITICAL Threat Category Vulnerability – Authentication Bypass (CWE-304) Affected Platforms Proxmox Virtual Environment 7.0 – 7.4 and 8.0 with […] The post Critical Authentication Bypass i...
Announcement Cybersecurity -
Temporary Easing of Network Separation Rule Available for More Financial Companies for AI Cybersecurity Purpose
The Financial Services Commission held a meeting on frontier AI and cybersecurity strategy with officials from the Financial Supervisory Service and the Financial Security Institute on September 3....
-
Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
On September 1, 2026, SonicWall disclosed two vulnerabilities affecting SonicWall SMA1000 appliances that the vendor says are being actively exploited in the wild. The vulnerabilities, CVE-2026-835...
Cybersecurity 2 versions -
CMMC Hit Pause, the FAR Council Hit Play
CMMC Phase 2 is paused, but the FAR CUI proposed rule pushes NIST 800-171 obligations past the defense industrial base. Here's what changed, what didn't, and the 32 requirements you can't defer.
Cybersecurity 3 versions -
Anatomy of a Silent Domain Takeover
Key Takeaways Modern AD attacks use legitimate protocols end-to-end, no malware, no exploit, nothing for signature tools to fingerprint. The evidence is already in the logs; what is missing is the ...
-
'Subsidie voor cybermaatregelen kwam op het juiste moment'
Ondernemers kunnen vanaf 7 september 2026 gebruikmaken van de subsidieregeling ‘Mijn Cyberweerbare Zaak’. Hiermee kun je als mkb’er of zzp’er 50% vergoed krijgen voor belangrijke basismaatregelen t...
-
Sveriges cybersäkerhet ska stärkas med AI
(Ny version) Regeringen avser att ge Försvarets radioanstalt (FRA) och Försvarsmakten i uppdrag att utveckla en AI-stödd förmåga att skydda samhällsviktig verksamhet mot cyberhot.
Announcement Cybersecurity -
‘We hebben de subsidie gebruikt voor een cyberbewustwordingstraining’
Kleine ondernemers kunnen vanaf 7 september gebruikmaken van de subsidieregeling ‘Mijn Cyberweerbare Zaak’. Hiermee kunnen mkb’ers en zzp’ers 50% van de kosten van een cybermaatregel, tot een maxim...
-
Inside Knight Office, a New M365 AiTM Phishing Kit
An inside look at Knight Office, a newly discovered AiTM phishing kit featuring custom control panels, Cloudflare Turnstile, and M365 Token theft.
Cybersecurity 3 versions -
Subsidie voor cyberweerbaarheid kleine bedrijven binnenkort van start
De subsidieregeling ‘Mijn Cyberweerbare Zaak’ opent op 7 september opnieuw voor kleine bedrijven, zo heeft staatssecretaris Aerdts van Economische Zaken en Klimaat aangekondigd.
-
Actief misbruikte kwetsbaarheden in SonicWall SMA 1000-apparaten - voer updates uit
SonicWall heeft twee kwetsbaarheden verholpen in de SMA 1000-serie waarvan actief misbruik werd gemaakt. Via de eerste kwetsbaarheid kan een aanvaller zonder inloggegevens ongeautoriseerde handelin...
-
Kwetsbaarheid in JFrog Artifactory Self-Hosted – update direct
Er is een kwetsbaarheid gevonden in JFrog Artifactory Self-Hosted, een product voor het opslaan en beheren van softwarepakketten. De kwetsbaarheid kan aanwezig zijn bij een standaardconfiguratie. E...
-
Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon
Research by: Amit Yardeni Key Points Introduction Since mid-2025, Check Point Research has tracked a sustained campaign against Brazilian organizations. The tradecraft points to a Chinese-speaking ...
-
An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation
Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks. The post An AI-Assisted Cyber Attack: Insi...
-
Nowości od CERT Polska - premiera wiedza.cert.pl i nowa funkcja w moje.cert.pl
W CERT Polska stale rozwijamy dostępne narzędzia i tworzymy nowe rozwiązania, które pomagają zapobiegać incydentom, a kiedy już do nich dojdzie - skutecznie reagować. Dziś swoją premierę ma serwis ...
Announcement Cybersecurity -
Global public-private operation disrupts Sality botnet active for two decades
An international operation supported by Europol has disrupted the Sality peer-to-peer (P2P) botnet, a long-running criminal infrastructure used to distribute malicious payloads to thousands of infe...
Announcement Cybersecurity -
Kritische Sicherheitslücken in SonicWall SMA1000 Series - aktiv ausgenutzt - Updates verfügbar
In SonicWalls SMA1000 Series Appliances existieren zwei schwerwiegende Sicherheitslücken. Die schwerwiegendere der beiden Schwachstellen ermöglicht es Angreifer:innen aus der Ferne und ohne Au...
Announcement Cybersecurity -
La AEPD participará en las XX Jornadas STIC con una jornada dedicada a la protección de datos
La AEPD participará en las XX Jornadas STIC con una jornada dedicada a la protección de datos AEPD Mié, 02/09/2026 La Agencia contará el 24 de noviembre con un espacio propio en un encuentro que ce...
Announcement Cybersecurity -
Savjeti Nacionalnog CERT-a za siguran početak školske godine – što učiniti ako nešto pođe po krivu?
Koliko god se pridržavali svih sigurnosnih preporuka, ponekad se dogodi da nešto ipak pođe po krivu, bilo da je riječ o sumnjivoj poruci na koju smo kliknuli, kompromitiranom računu ili neugod...
Announcement Cybersecurity -
Microsoft Exchange Server ievainojamība CVE-2026-62911
Konstatēta augstas bīstamības Microsoft Exchange Server ievainojamība (CVE-2026-62911). Ievainojamību izraisa autentifikācijas apiešanas nepilnība, kas ļauj atkārtoti izmantot iepriekš pārtvertus a...
Announcement Cybersecurity -
CrowdStrike Announces Agentic Identity Provider
CrowdStrike gives every AI agent a trusted identity and controls their access based on real-time context, and expands modern privileged access.
-
CrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks
Real-Time Supply Chain Attack Protection, embedded into the Falcon sensor, blocks malicious open-source packages at download to protect the endpoint.
-
CrowdStrike Delivers the Next Evolution of the Agentic SOC
Expert agents that reason together, learn your environment, and run on data CrowdStrike owns. See how we deliver the agentic SOC. Learn more!
-
NVIDIA and CrowdStrike Strengthen Agentic Cybersecurity Frontier
“We’re at an inflection point in cybersecurity,” Jensen Huang told a sold-out crowd at CrowdStrike’s Fal.Con 2026 in Las Vegas Tuesday. Attacks are now automated. Defense has to be, too. The ...
-
Meerdere kwetsbaarheden in WatchGuard Fireware OS Mobile Security
Er zijn meerdere kwetsbaarheden gevonden in WatchGuard Fireware OS, waaronder het onderdeel Mobile Security. Een aanvaller kan deze kwetsbaarheden misbruiken om schadelijke code uit te voeren. De k...
-
Zimbra Collaboration Suite ievainojamības aktīva izmantošana uzbrukumos
Konstatēta Zimbra Collaboration Suite (ZCS) augstas bīstamības ievainojamības CVE-2026-73570 aktīva izmantošana uzbrukumos. Tā ļauj neautentificētam uzbrucējam attālināti izpildīt patvaļīgu kodu (R...
Announcement Cybersecurity