Subscribe
Sign in
Home
Threat Intelligence
AI Research
Darknet and Hacking Forums
Data Breaches
Latest
Top
Four Days Offline Inside a Resilient Grid
A cyberattack reportedly shut a small UK generator for four days without threatening the wider grid. Local operational loss still counts.
24 mins ago
•
Tom
The Lock Screen Was the Credential Phish.
SynkLoader turns a Teams help-desk lure into a local Windows password prompt, reverse proxy, and remote-control stack. The useful detection point is the…
Aug 22
•
Tom
Patch the Server. Then Audit Every Installer It Served.
CISA added two exploited TrueConf flaws to KEV. Researchers found attackers replaced a client installer with a trojanized copy carrying PhantomCore…
Aug 21
•
Tom
The Charges Are New. The Credential Playbook Is Not.
DOJ's expanded Mabna Institute case describes personalized phishing, password spraying, and valid-account abuse. Credential dumps can feed the same…
Aug 20
•
Tom
The Extension ID Stayed Put. The Payload Changed.
A 77-extension Firefox corpus tied stable add-on identities, cloned code, shared infrastructure, and version histories to wallet and credential…
Aug 20
•
Tom
A Web Page Should Not Reach Your AI Control Plane
CISA's active-exploitation warning for Ray CVE-2025-62593 exposes a broader weakness: local and private compute services can still be reachable through…
Aug 18
•
Tom
Put Private Cyber Power Under Public Command
The White House is right to mobilize vetted U.S. companies against foreign cybercriminal networks—as long as target selection, legal authority, and…
Aug 13
•
Tom
The Router Was Waiting for Whoever Answered
Researchers found a root-running phone-home component embedded across 20 router models. It needs no inbound exposure, trusts any answering endpoint, and…
Aug 6
•
Tom
The Malware Arrived With Valid Provenance
A fast-moving npm compromise used a maintainer's own release workflows to ship verifiably sourced malicious builds. The attestation was valid; the…
Aug 5
•
Tom
The Patch Closed One Door. The Bypass Took Another.
CISA says CVE-2026-18577 is actively exploited. The incomplete fix for CVE-2026-18556 makes patch lineage, exact-build proof, and preserved artifacts…
Aug 4
•
Tom
No Passwords Reported. Plenty of Pretext.
PNLD reports no evidence of credential compromise. Exposed police and justice identities—and the names of some Ask the Police users—still give…
Aug 3
•
Tom
July 2026
The Firewall Manager Had a Password Defenders Never Chose
Cisco says attackers are exploiting a static low-privilege account in Secure FMC; a concrete log artifact and an August 1 federal deadline turn patching…
Jul 30
•
Tom
This site requires JavaScript to run correctly. Please
turn on JavaScript
or unblock scripts