A recent study from Security Compass found just 25% of organizations surveyed conduct threat modeling during the early phases of software development—requirements gathering and design—before proceeding with application...
Italian web hosting firm Aruba.it has admitted a recent data breach amid complaints from some customers that it was slow in notifying them about a problem. In an...
Umbraco, a content management system (CMS) vendor, has given users of its form-building package a “heads-up” about an imminent software update addressing a remote code execution (RCE) vulnerability....
Today, the US Department of Justice (DOJ) indicted four members of the Chinese state-sponsored hacking group known as APT40 for hacking various companies, universities, and government...
Attackers have stolen 1 TB of proprietary data belonging to Saudi Aramco and are offering it for sale on the darknet. The Saudi Arabian Oil Company, better known as...
US and allies, including the European Union, the United Kingdom, and NATO, are officially blaming China for this year’s widespread Microsoft Exchange hacking campaign. These early...
Human rights non-governmental organization Amnesty International and non-profit project Forbidden Stories revealed in a recent report that they found spyware made by Israeli surveillance firm NSO...
Campbell Conroy & O’Neil, P.C. (Campbell), a US law firm counseling dozens of Fortune 500 and Global 500 companies, has disclosed a data breach following a...
Trickbot malware was recently observed adding Zeus flavor to its modules. It was recently seen plugging new Virtual Network Computing (VNC) module that helps an actor monitor high-profile...
A massive ongoing attack campaign has been discovered that already targeted hundreds of victims in Southeast Asia. The campaign is being operated by the LuminousMoth APT,...