Real cyber-threats unfolding around the world right now — ransomware, phishing, malware, breaches and zero-day exploits. Click any threat to see what happened and exactly how to stay protected.
One Caledonian government agency reported a breach, thanks to a third party that may have serviced other agencies as we…
The Netherlands' National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authenti…
Google Workspace attacks do not always begin with phishing. Stolen OAuth tokens can provide another path into Gmail, Dr…
Why do so many boards underestimate technology risk until it becomes a crisis?
A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targe…
The $1 billion deal aims to converge data security and identity into a single control plane for agents, with privileged…
Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed …
It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data fr…
The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the com…
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious process…
A former data analyst contractor for Brightly Software has been sentenced to two years in prison for targeting his empl…
You're not alone if you just received an "Apple Threat Notification" saying it detected a "mercenary spyware attack tar…
Authorities in Ukraine shut down 94 fraudulent call centers across the country that lured people into investment scams …
An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by re…
Exploitation against CVE-2026–59310 began earlier this month, and patching the vulnerability may not be enough to fully…
View CSAF Summary Parasolid is affected by an out of bounds read vulnerability that could be triggered when the applica…
View CSAF Summary Siemens License Server is affected by multiple vulnerabilities which could allow an attacker to eleva…
View CSAF Summary A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to…
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to decrypt sensitive data, b…
View CSAF Summary Successful exploitation of this vulnerability could allow a low-privilege user or attacker to inject …
View CSAF Summary Siveillance Video Management Servers contains a vulnerability that could allow a Remote Code Executio…
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker within Bluetooth range to manip…
View CSAF Summary Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and passw…
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to read data from the device…
Researchers discovered hackers-for-hire performing cyber espionage and financially motivated heists from the same Web p…
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still …
The trust framework underlying Belgium's electronic ID system was fully compromised by severe vulnerabilities in a key …
Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a pro…
The "City-Forum" campaign has been active since at least March 2025 and has targeted organizations across multiple sect…
The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patche…
Walmart colocates red and blue teams to build trust and improve security through collaborative purple teaming exercises
A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking acce…
Attackers continue to target critical infrastructure and government-linked organizations in the country, mirroring the …
A newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let resea…
Enterprise defenses are tuned to catch the attacks that make noise. This year's data shows attackers winning by making …
Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Cam…
Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, acco…
Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of h…
SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that c…
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and s…
Kaspersky experts have discovered malicious TrueConf software installers. The Head Mare APT group uses them to deliver …
Project CAV3RN targets Israel with Google Apps Script C2 relays and DNS-based routing. Modular .NET NativeAOT framework…
The report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as…
This report contains mobile threat statistics for Q2 2026, along with noteworthy discoveries and quarterly trends: the …
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded…
We cover a cloud-based AitM attack scenario leveraging service workers and Ultraviolet, and provide detailed phishing h…
Kaspersky expert provides statistics and details on several incident response cases at educational institutions in Braz…
An analysis of how Network Anomaly Detection (NAD) rules work within Kaspersky Anti Targeted Attack, using Kerberoastin…
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimite…
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that tu…
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems an…
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contracto…
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software i…
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains asso…