Turla Hackers Exploit SharePoint Flaw to Compromise French Organizations
The Russian-linked Turla group leveraged a Microsoft SharePoint vulnerability to gain access to thousands of French user accounts and sensitive data.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 3,725 stories synthesized.
The Russian-linked Turla group leveraged a Microsoft SharePoint vulnerability to gain access to thousands of French user accounts and sensitive data.
Generative AI is empowering fraudsters with advanced deepfakes and voice cloning, escalating identity fraud and challenging traditional security measures.
The UK and EU have officially attributed a December 2025 cyberattack on Poland's power grid to Russia's FSB Centre 16, warning of potential lethal consequences and urging critical infrastructure to implement new security measures.
A misconfigured server inadvertently revealed the tools and tactics of three distinct phishing operations using the Evilginx man-in-the-middle proxy.
A CISA postmortem details lessons learned from a contractor's exposure of internal credentials, including AWS Govcloud keys, on GitHub for six months.
Key findings • 12 malicious npm packages were disclosed on July 13, 2026. • All advisories were published within a tight 23-minute window. • A cluster of packages impersonated 'markable-t…
Discount supermarket chain Lidl has disclosed a data breach affecting its online shops in Germany, Belgium, and the Netherlands, resulting from a hack at a service provider.
Varonis Threat Labs has released a free, hands-on Capture the Flag event designed to teach cybersecurity professionals how attackers exploit Microsoft Entra ID and its growing non-human identities.
Tenable emphasizes that cloud security is no longer just an IT compliance issue for federal agencies but a critical mission requirement for national security and operational readiness.
A new 'MemGhost' attack allows adversaries to subtly alter AI agent memories with a single email, potentially steering future responses and actions without user detection.
British authorities have charged five individuals in connection with Russian Coms, a sophisticated platform used to facilitate over 1.8 million fraudulent calls worldwide.
Check Point Research's latest threat intelligence report covers a wide array of cyber incidents, including a massive data breach at AssuranceAmerica, ransomware attacks, supply chain compromises, and novel AI-powered threats.
Cloudflare launches Precursor, a new bot management engine that analyzes user behavior within browsers in real-time to detect sophisticated automated traffic.
Researchers propose a theoretical 'Intelligent Worm' that uses AI to dynamically regenerate exploits and adapt to defenses in real-time, posing a significant evolution beyond traditional self-spreading malware.
Threat actors are exploiting a gap in Microsoft Entra ID's logging by spoofing OAuth client IDs, allowing them to perform account enumeration without generating successful sign-in events.
The Argentine Football Association (AFA) may have been compromised by attackers who exploited an infostealer infection dating back to September 2025, leading to stolen credentials and administrative access.
A critical vulnerability in RabbitMQ enables unauthenticated attackers to steal the broker's OAuth client secret, granting them full control over the message broker.
A digital forensics investigation leveraging Belkasoft X and AweClone software has led to the conviction of Jason Cunningham for defrauding landlords and investors of over £113,000.
Scammers are crafting increasingly convincing fake cryptocurrency gift card websites, designed to trick users into irreversible crypto payments with promises of discounts and ease of use.
Trail of Bits has published a new chapter for its Testing Handbook, offering in-depth guidance on security testing Rust applications, tools, and techniques.
A critical authentication bypass vulnerability (CVE-2026-57807) in the miniOrange WordPress OAuth SSO plugin allows unauthenticated attackers to gain full control of websites.
Researchers have developed VEXAIoT, an AI multi-agent framework that automates the identification and exploitation of vulnerabilities in Internet of Things (IoT) environments.
UK's NCSC and international partners issue alert on Russian state-backed actors targeting critical infrastructure via vulnerable routers.
FastNetMon introduces Netomics, a self-hosted platform offering comprehensive BGP routing visibility, integrating live data, RPKI validation, and AI-assisted querying without third-party dependencies.