Cybersecurity
1,758 publications classified by Officially as Cybersecurity, judged from each publication's own title and summary.
Our reading, not the publisher's. An organization that has claimed its profile can say what its own publications are about, and that will take precedence here. See everything published by organizations filed under Cybersecurity instead.
-
Hackers Frequently Target Healthcare and Finance Orgs
Healthcare organizations and banks handle highly personal information. But a new Huntress survey shows many threat actors frequently target these companies.
-
VU#456290: Hugging Face Transformers library writes remote code to disk prior to consent check
A vulnerability in the Hugging Face Transformers library (versions 4.57.0 to 5.16.1) allows remote, attacker‑controlled Python files to be written to the local disk without user authorization. …
-
What’s in the SOSS? Podcast #71 – S3E23 Navigating the New Era: The EU Cyber Resilience Act Explained with Madalin Neag
In this episode of What’s in the SOSS, host Sally Cooper and OpenSSF EU Policy Advisor Madalin Neag demystify the EU Cyber Resilience Act (CRA). Learn how the CRA establishes a new cybersecurity ba...
-
New ECCC call for proposals under the Digital Europe Programme is open for applications
Today, the European Cybersecurity Competence Centre (ECCC) opened a new call for proposals under the Digital Europe Programme (DEP) for a total budget of up to EUR 96 million. The call aims to stre...
Announcement Cybersecurity -
Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
-
Akt o kibernetski odpornosti: 11. septembra 2026 se začnejo uporabljati obveznosti poročanja
Akt o kibernetski odpornosti (Cyber Resilience Act – CRA) določa zahteve kibernetske varnosti za izdelke z digitalnimi elementi na trgu Evropske unije. 11. septembra 2026 se začnejo uporabljati obv...
Announcement Cybersecurity -
RMM Tools for MSPs: Features, Risks & How to Stay Secure
Four years after the Kaseya supply chain attack, a recent incident shows how threat actors still successfully target MSPs’ downstream customers through RMM software.
-
The Crypto Wallet That Never Opened: Tampered Exodus Installer Hides a Modular RAT
Exodus crypto wallet analysis by Huntress uncovered tampered installers hiding a modular RAT focused on stealing credentials, not coins.
-
Peer Pressure: Inside the Sality Botnet Disruption Operation
CrowdStrike collaborated with international law enforcement and industry partners to execute a coordinated disruption of the Sality peer-to-peer botnet.
-
CrowdStrike Falcon Guardian Defines the Next Generation of AI Security
A new flagship AI detection and response solution delivers runtime protection for AI agents, introduces a new AI gateway, and extends expert-led defense.
-
Daisy-Chaining Trust: Investigating Faronics Deploy Abuse
Bad actors are abusing Faronics Deploy in phishing campaigns to run PowerShell, deploy ScreenConnect, and evade detection by using trusted tools.
-
State of the Union 2026
State of the Union 2026 Anonymous (not verified) Mon, 08/31/2026 - 16:11 16 September 2026 The State of the Union (SOTEU) address is an annual speech by the President of the European Commiss...
Announcement Cybersecurity -
Huntress API Update: New Endpoints, Webhooks, and Automation
The Huntress API has grown from six read-only endpoints into a full integration and automation platform. See what’s new, including webhooks and MCP support.
-
Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode
Research by: hasherezade Key Points Introduction JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications (...
-
Introducing Adaptive Intelligence: Undermining the economics of every bot attack
Bot operators have historically had the economic advantage, bypassing static, deterministic detection rules with cheap proxies and retooling. Cloudflare's new Adaptive Intelligence engine flips thi...
-
31st August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 31st August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Manchester Airports Group, the UK operator of Ma...
-
Priporočila za upravljanje tveganj dobavnih verig na področju informacijske in kibernetske varnosti
Urad Vlade Republike Slovenije za informacijsko varnost (URSIV) je pripravil priporočila za upravljanje tveganj dobavnih verig. Namenjena so predvsem zavezancem po Zakonu o informacijski varnosti (...
Announcement Cybersecurity -
Kritiska ievainojamība Red Hat Keycloak
Red Hat izstrādātajā identitātes piekļuves pārvaldības risinājumā KeyCloak (Red Hat Build of Keycloak) ir atklāta kritiska ievainojamība CVE-2026-18963 (CVSS vērtējums - 9.1), kas ļauj neautentific...
Announcement Cybersecurity -
Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers. The post Spring Ring: An Inside Look at Voice Phishing Campa...
-
ValleyRAT masquerading as adware
Threat actors are distributing the ValleyRAT backdoor disguised as adware. We analyze the infection chain, from the malicious installer to the final payload.
-
Kehtima hakkavad uued infoturbenõuded - riik sekkub vähem, et ettevõtted ja asutused saaksid keskenduda päriselt küberturvalisuse tagamisele
Homme jõustuv uus Eesti infoturbestandard vähendab oluliselt riigi sekkumist asutuste ja ettevõtete küberkaitsenõuete täitmisse ja usaldab enam nende endi tegevust andmete ja süsteemide kaitsel.
Announcement Cybersecurity -
This month in security with Tony Anscombe – August 2026 edition
Details about the Hugging Face hack, critical infrastructure under attack, a spoofed in-flight Wi-Fi network, and more of this month's cybersecurity news
-
GreyNoise + CrowdStrike: Real-Time Edge Intelligence in Falcon Next-Gen SIEM and Charlotte Agentic SOAR
Today we’re announcing an expanded integration between GreyNoise and the CrowdStrike Falcon® platform, with new content for CrowdStrike Falcon® Next-Gen SIEM and CrowdStrike Charlotte Agentic SOAR. …
-
Boardroom Battles 2026: ASD’s Cyber Priorities & AI Risk
The Australian Signals Directorate’s 2026 board priorities and frontier AI guidance show why speed alone won’t stop AI-era cyber threats.
-
The Good, the Bad and the Ugly in Cybersecurity – Week 35 (2026)
Authorities disrupt global cybercrime rings, attackers abuse DocuSign in NovaCookies phishing, and Spark RAT targets Cambodia with vulnerable drivers.
-
A Beginner’s Guide to Phishing Simulation Training for Employees | Huntress
Learn the essentials of phishing simulation training with our beginner's guide. Protect your organization by simulating real phishing attacks.
-
Teach Yourself to Phish | Huntress
Get ready for a phishing trip! Learn about the strategy behind phishing simulations and how it can help your organization build resilience against real phishing threats.
-
Next-Gen Phishing Tactics Users Aren’t Ready For | Huntress
Move past basic credential harvesting. Discover how modern attackers use ClickFix, BitB, and OAuth consent phishing—and how to train your users with Huntress SAT.
-
Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!
This release has something for everyone: scanner modules, payloads, and exploits. This release’s scanners cover Drupal, PanOS, WordPress, and SCADA; this release’s exploits cover Tenable, Flowise, ...
-
Why a cryptographic inventory is key for addressing the quantum computing threat
When quantum computers become generally available, they’ll be able to crack current public-key cryptographic algorithms, putting digitally stored and transmitted data at risk. But the threat alread...
Cybersecurity 2 versions -
Kwetsbaarheden in PaperCut MF en NG met actief misbruik: update onmiddellijk
Er zijn twee actief misbruikte kwetsbaarheden aangetroffen in PaperCut MF en PaperCut NG, bekend als CVE-2026-82078 en CVE-2026-81578. Deze kwetsbaarheden worden beoordeeld met een kans op misbruik...
-
Huntress Employee Spotlight: Meet Ben Bernstein
Meet Ben Bernstein, cybersecurity advisor and security badass, in this employee spotlight. See how he makes a difference every day.
-
Ernstige kwetsbaarheden in Microsoft Exchange Server
Er zijn meerdere ernstige kwetsbaarheden gevonden in Microsoft Exchange Server. Een van deze kwetsbaarheden is CVE-2026-62911, met een CVSS-score van 8.0. Voor deze kwetsbaarheid is exploitcode onl...
-
BotBase for Operators: A clearer path to joining Cloudflare's directory of bots and agents
Bot operators now have a home in the Cloudflare dashboard to manage submissions. This update adds submission status tracking, submission editing, and a behavior model so operators can accurately de...
-
PaperCut NG/MF Critical Zero-Day Exploited in the Wild
On August 27, 2026, PaperCut Software published an urgent security advisory stating that it is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. PaperCut h...
Cybersecurity 2 versions -
Critical Keycloak Account Takeover Vulnerability (CVE-2026-18963) – 20260828006
Severity CRITICAL Threat Category Vulnerability – Authentication Bypass/ Account Takeover Affected Platforms Keycloak 26.4.x (before 26.4.15), 26.6.x (before 26.6.6), 26.7.x […] The post Crit...
Announcement Cybersecurity -
Manufacturers – prepare in advance for reporting vulnerabilities and incidents under the Cyber Resilience Act
Before the CRA reporting obligations start to apply, organisations should prepare internally for submitting notifications. The reporting deadlines are short, so it is important to agree on responsi...
Announcement Cybersecurity -
CERT-SE:s veckobrev v.35
I veckans brev kan du ta del av ett axplock av händelser inom cybersäkerhetsområdet. Dessutom hittar du en utvärdering av organisationers cyberförsvar som CISA gjort, som innehåller rekommendatione...
Announcement Cybersecurity -
PaperCut Zero-Day: Active Exploitation and Pre-Auth RCE
UPDATED: PaperCut NG and PaperCut MF are under active exploitation. Huntress reproduced a pre-auth RCE chain and shares urgent patching, exposure, and detection guidance.
-
Threat Actors Are Posing as OpenAI, Anthropic and DeepSeek to Target Credentials and Secrets
GreyNoise is observing automated scanners posing as the web crawlers of OpenAI, Anthropic, DeepSeek, and Fortune 500 companies, using forged user agents while requesting the files where misconfigur...
-
Post-Quantum Authentication: Up Next
Post-quantum key establishment has moved from standards into deployment. Post-quantum authentication has not moved nearly as far, and specification work is no longer the only constraint. The IAB is...
Announcement Cybersecurity -
“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend
In his first Threat Source newsletter, David Bianco explores the critical need for operational sovereignty in customizing AI guardrails to maintain the defender’s advantage.
-
Active Exploitation of Vulnerabilities in Microsoft SharePoint
Attackers are exploiting multiple vulnerabilities in Microsoft SharePoint Server to bypass a security feature and run code over a network. Patch immediately.
Announcement Cybersecurity -
Advies van de AP aan WordPress-gebruikers die getroffen zijn door datalek
Recent zijn kwetsbaarheden ontdekt in de WordPress-software. WordPress wordt relatief veel gebruikt in Nederland. De kwetsbaarheden in WordPress worden momenteel actief misbruikt, met datalekken to...
Announcement Cybersecurity -
How to build an exposure management program the business trusts: Lessons from Tenable’s CSO
Discover how Tenable’s shift to an AI-driven exposure management program helped Tenable’s CSO, Robert Huber, overcome tool sprawl, unify data silos, mitigate the risk of rapid AI adoption, and shif...
Cybersecurity 2 versions -
New Huntress Managed ITDR Dashboard: Faster Identity Investigations
Huntress’ redesigned Managed ITDR dashboard adds Rapid Identity Triage, Failed Login Characterization, and Quick SIEM search for faster investigations.
-
Podatności w oprogramowaniu dool
W oprogramowaniu dool wykryto 2 podatności różnego typu (CVE-2026-56651 oraz CVE-2026-56652)
Announcement Cybersecurity -
Identity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNs
Despite modern verification controls, identity theft remains one of the most pervasive threats to both individuals and enterprise organizations. U.S. Federal Trade Commission statistics show over 1...
Cybersecurity 2 versions