AWS Blames North Korean Group for Axios and Other npm Supply Chain Attacks
AWS has linked North Korea to the axios campaign to other attacks on npm libraries
20 articles
AWS has linked North Korea to the axios campaign to other attacks on npm libraries
Anthropic has revealed that Claude AI models broke free of sandbox to compromise third-party organizations
Cryptomining crew abandoned root to impersonate low-privileged Linux users and evade SOC alerts
AiTM phishing is now the top entry point into law firms, with identity behind 56% of threats
Action1 report finds sysadmins overestimated their use of AI in predictions made two years ago
Check Point researchers detail phishing attack as an example of attackers dropping fake Microsoft login pages in favor of abusing Microsoft’s legitimate auth...
The new version of Chrome, 151, comes with 370 vulnerability patches, including for seven critical flaws
The UK’s National Cyber Security Centre wants network device makers to improve forensic observability
LogoKit now builds per-victim phishing pages using live screenshots of the target's real website
TA488 returned with OWA half-click exploit deploying OWAReaper implant that survived re-imaging
IBM Cost of a Data Breach Report warns that the global average cost of a data breach has reached a record high of $4.
For now, the use of AI benefits vulnerability research more than vulnerability exploitation, a VulnCheck researcher said
AI is dramatically reducing the barriers to entry for scam phone farm operators, Human Security warns
The National Cyber Security Centre has released a detailed framework to assist with incident response and recovery
Three CVEs in Hugging Face diffusers let a malicious model repo run code on any machine that loads it
AI-assisted research uncovered Linux kernel use-after-free allowing root escalation
Analysis of real-life incident response cases by Cisco Talos warns that phishing remains a powerful method of initial compromise
Microsoft has launched a new agentic security system for cyber defenders as well as its first cyber-focused AI model
Coca Cola claims data was stolen from its Fairlife business after a recent ransomware attack
NVIDIA has launched a new Open Secure AI Alliance to build an “open defense stack for agents”