LinkedIn introduces new tools to combat AI-generated fake identities
The platform is rolling out several new features, including the ability for members to vouch for the professional experience of their colleagues and classmat...
The platform is rolling out several new features, including the ability for members to vouch for the professional experience of their colleagues and classmat...
North Korea-linked threat actor Konni has launched a targeted cyberespionage operation against Ukraine-focused entities using malicious Windows shortcut file...
Microsoft disrupted EvilTokens after the AI-powered phishing service compromised 12,000 inboxes across 10,000 organisations and enabled complex financial fraud.
Network Solutions has launched Dark Web Monitoring, a new security capability that alerts small businesses when information associated with their domain appe...
A threat actor linked to the ongoing Graphalgo software supply-chain campaign has expanded beyond npm and PyPI, using malicious Terraform providers and Go mo...
The cybercriminal group ShinyHunters has claimed to have breached systems linked to the FBI, obtaining highly sensitive information on “almost all” FBI emplo...
Microsoft has hailed its success in disrupting EvilTokens, an AI-powered a phishing-as-a-service (PhaaS) platform linked to more than 12,000 compromised Micr...
Master of Malt reported a customer data breach after attackers allegedly compromised an application key linked to Ribon, a third-party BigCommerce app manage...
A third Chinese threat actor has been linked to phishing campaigns that cloned trusted websites and chained Chrome and Windows zero-day exploits to deploy a ...
North Korea-linked WaterPlum runs the Contagious Interview campaign, infecting over 30,000 devices using a fake job interview. On September 18, Japan’s Natio...
A Pakistan-aligned threat group, known as Transparent Tribe or APT36, has been linked to a new wave of cyberattacks targeting government and defense organiza...
Ecommerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and...
HEAVYGRAM is a versatile tool capable of remote command execution, system and network information discovery, data exfiltration, screenshot capture, and estab...
CloudSEK linked GHAPPIER to a compromised npm package with valid trusted-publishing provenance
The agreement between LinkedIn, ProAPIs and joint business operator Netswift also requires the firms to stop selling and transferring the data, no longer acc...
A sophisticated npm supply-chain campaign has been linked to 10 malicious JavaScript packages that collectively recorded millions of downloads while bypassin...
FamousSparrow is targeting Latin American governments with SparroWocky, a new C++ backdoor that exfiltrates files, takes screenshots and evades security tools.
North Korea’s Hangro VPN and mail platform has deployed a new certificate hierarchy that exposes an apparent cross-border management environment spanning sys...
North Korea-linked threat actor TraderTraitor has expanded its developer-focused intrusion activity beyond cryptocurrency targets, using weaponized Terraform...
The North Korean threat actor known as Jade Sleet has been attributed to the compromise of an India-based "much smaller organization" in the information tech...