ASOS Warns Customers of Data Breach Following Credential-Based Account Takeovers
ASOS has started notifying affected customers in the U.S.
ASOS has started notifying affected customers in the U.S.
Kaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices. The post First Malware Built Specifically for Car...
Andy Ellis has a roundup of the security vendors at Black Hat this year. Key Takeaways: We have entered into an AI world.
At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday. Ab...
Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution.
Red Hat has disclosed a critical vulnerability in the Red Hat Build of Keycloak that allows an unauthenticated remote attacker to bypass a key safeguard in t...
Threat actors are using sponsored Google Search ads to place a fake OpenAI Codex download page above the legitimate result, steering macOS users into manuall...
EvilTokens is pushing phishing-as-a-service beyond credential theft by abusing Microsoft’s device authorization flow to obtain valid Microsoft 365 tokens. Vi...
Truffle Security announced TruffleHog AWS Analyze, a new addition to TruffleHog Enterprise. TruffleHog AWS Analyze enriches found AWS credentials to highligh...
The flaw allowed for the redirection of API calls by manipulating the region field within the SDK's hostname template.
The vulnerability, discovered by researcher Alice Cecchetto and detailed by CERT/CC, stemmed from a heap-based buffer overflow in the game's player-removal m...
Software engineer Matt Callaghan discovered that Alibaba's website employed obfuscated audio scripts that generated a waveform and analyzed its output.
Every time you add an extension or plugin to your browser, there's a risk that you might be doing more than managing your cryptocurrency wallet, generating p...
Fake Codex pages used Google Sites, sponsored search and ClickFix to target Mac users
A package gets installed. A login prompt opens.
The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap.
The UK power plant, which was not named due to security concerns, was offline for four days before being restored by staff.
Doubloon Dredger abused Notion and malicious PDFs to harvest Microsoft authentication tokens
ReliaQuest has reported a targeted social engineering attack in which threat actors impersonated company security personnel, used a spoofed domain, and succe...
A newly discovered AI system called Ox Alpha has emerged on OpenRouter, sparking widespread speculation within the AI community regarding its origin, technic...