Red Teamers Infiltrate Network by Posing as Snow Shovelers
A red team exercise demonstrated how a lack of physical security and weak password policies allowed attackers to gain network administrative access after posing as new IT employees.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 3,731 stories synthesized.
A red team exercise demonstrated how a lack of physical security and weak password policies allowed attackers to gain network administrative access after posing as new IT employees.
Microsoft's 2026 Vulnerabilities Report reveals a dramatic 101% increase in critical vulnerabilities in 2025, reversing a decade-long decline and concentrating risk in Azure and Dynamics 365.
Researchers developed a novel method to detect ransomware on shared file servers by analyzing network traffic patterns, offering earlier detection than endpoint-only solutions.
Anthropic's AI identified nearly 1,600 vulnerabilities in open-source code, revealing a significant gap between AI-driven discovery and human remediation capacity.
The FortiBleed credential-harvesting campaign, impacting over 430,000 FortiGate firewalls, has been directly linked to the INC Ransom and Lynx ransomware-as-a-service operations.
GitHub rolls out a new License Compliance tool in public preview to help organizations manage open-source dependencies and prevent costly license violations.
Key findings • 25 malicious npm packages were disclosed simultaneously on July 2, 2026. • All packages share the @marketfront npm scope, indicating a coordinated campaign. • Package names…
Key findings • 23 CVEs disclosed in Linux Kernel between July 1-2, 2026 across multiple subsystems. • Moderate severity vulnerabilities include Use-After-Free flaws in Bluetooth and fhandle c…
Aflac Japan has detected a hacking incident that potentially exposed the personal and financial information of nearly 4.4 million customers and agents, marking the insurance giant's second significant data breach in just over a year.
Key findings • Five Drupal security advisories were disclosed simultaneously on July 1, 2026. • The advisories were released by the Drupal security team. • Specific details on vulnerabili…
Kubota North America disclosed a data breach where hackers accessed employee personal information for over a month, impacting sensitive data including Social Security numbers and bank details.
CISA has added CVE-2026-45659, a deserialization vulnerability in Microsoft SharePoint Server, to its Known Exploited Vulnerabilities (KEV) Catalog, citing active exploitation.
Sophisticated phishing campaigns are now fingerprinting victims' devices and operating systems via user-agent data to deliver tailored, OS-specific malware, significantly boosting their success rates.
A 19-year-old dual citizen of the U.S. and Estonia, allegedly linked to the Scattered Spider cybercrime group, has been extradited from Finland to Chicago to face federal charges.
A new Python-based remote access trojan, ChocoPoc, is being distributed via weaponized proof-of-concept exploits hosted on GitHub, leveraging malicious Python packages to infect unsuspecting users.
A social engineering tactic known as ClickFix has become the leading method for malware delivery, with researchers noting its expansion to macOS and targeting of developers.
A critical vulnerability in Argo CD's repo-server component enables unauthenticated attackers to execute arbitrary code and potentially seize control of Kubernetes clusters.
Canada's Communications Security Establishment has revealed that Russian hackers claimed to have infiltrated a Quebec municipality's water utility, potentially gaining control of critical operational technology systems.
The Department of Homeland Security is investigating a cyberattack that compromised the Homeland Security Information Network (HSIN), a platform used for sharing sensitive data among government and private sector partners.
Pentera Labs researchers demonstrated a novel attack chain where a compromised inbox and Claude Desktop's personalization features were leveraged to achieve remote code execution on a developer's machine.
GitHub Security Lab has released a guide detailing six essential security configurations for project maintainers to bolster their repositories' defenses.
Vensure Employer Solutions' CISO implemented an AI-powered solution to drastically reduce firewall log ingestion, cutting costs and improving security posture by filtering out low-value data.
A new integration between Criminal IP and the OpenCTI platform enriches threat indicators with contextual data, transforming raw data into actionable intelligence for security teams.
Security Operations Centers (SOCs) are drowning in alerts, leading to significant business costs due to delayed threat detection and inefficient resource allocation.