Cybersecurity researchers have identified a renewed wave of attacks attributed to a China-linked threat group tracked as UAT-8099, targeting vulnerable Microsoft Internet Information Services (IIS) servers...
Ivanti has released emergency security updates to fix two critical zero-day vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) that are being actively exploited in the wild....
A steady stream of cybersecurity developments this week underscores a growing reality: many of today’s most consequential digital threats emerge quietly, through incremental changes rather than...
Cybersecurity researchers at CTM360 have uncovered an extensive online fraud operation involving thousands of counterfeit banking websites designed to deceive users across the United States and...
Operational Technology (OT) incidents rarely begin with a dramatic, highly targeted attack on industrial systems. Instead, they almost always originate from familiar enterprise weaknesses: reused credentials,...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Broadcom VMware vCenter Server to its Known Exploited Vulnerabilities (KEV) catalog, following...
This week’s cybersecurity landscape highlights how familiar systems can become powerful tools in the wrong hands. From zero-click smartphone exploits to large-scale crypto scams, attackers continue...
Palo Alto Networks has issued security updates to address a high-severity denial-of-service (DoS) vulnerability affecting its GlobalProtect Gateway and Portal products, warning that the flaw can...
A high-severity security vulnerability in the WordPress plugin Modular DS is currently being exploited in the wild, according to cybersecurity firm Patchstack. The flaw, identified as...
A critical misconfiguration in AWS CodeBuild exposed several high-profile GitHub repositories to potential supply chain attacks, according to cloud security researchers at Wiz. The vulnerability, dubbed...