Risk & Resilience

The Uncomfortable Truth About More Visibility In Cybersecurity

Rising cyber attacks, shrinking time to exploitation, and ransomware volatility reveal why more visibility is not enough. Exposure Management is emerging as an operational model focused on reducing exposure and accelerating safe remediation.

First Malicious Microsoft Outlook Add In Found Stealing Over 4,000 Credentials In Supply Chain Attack

Cybersecurity researchers uncover the first known malicious Microsoft Outlook add in used to steal more than 4,000 Microsoft credentials through an abandoned domain takeover supply chain attack.

83 Percent Of Ivanti EPMM Exploits Traced To Single IP On Bulletproof Hosting Infrastructure

GreyNoise reports that 83 percent of Ivanti EPMM exploitation attempts are linked to a single IP on PROSPERO bulletproof hosting, targeting critical CVE-2026-1281 and CVE-2026-1340 vulnerabilities.

North Korea Linked UNC1069 Uses AI Lures And Fake Zoom Meetings To Target Cryptocurrency Firms

Google Mandiant uncovers North Korea linked UNC1069 using AI generated lures, fake Zoom meetings, and multiple malware families to target cryptocurrency organizations on Windows and macOS.

Three Questions To Ask Before Your Next Secure Service Edge POC

Security leaders are rethinking Secure Service Edge deployments as real world risks emerge. Key questions highlight gaps around SaaS visibility, deployment friction, and operational cost.

Warlock Ransomware Breach Exploits Unpatched SmarterMail Server At SmarterTools

SmarterTools confirms a Warlock ransomware breach caused by an unpatched SmarterMail server, impacting internal systems and hosted SmarterTrack customers while core services remained secure.

Weekly Recap Highlights AI Skill Malware, Record 31 Tbps DDoS, Notepad++ Supply Chain Abuse, And LLM Backdoors

This weekly cyber security recap covers AI skill malware abuse, a 31.4 Tbps DDoS attack, Notepad++ update compromise, LLM backdoor detection, and growing risks across trusted ecosystems.

Compromised dYdX npm And PyPI Packages Spread Wallet Stealers And Remote Access Malware

Cybersecurity researchers uncover a supply chain attack where compromised dYdX npm and PyPI packages distributed wallet-stealing malware and remote access trojans, exposing developers and crypto users to major risks.

Cisco Patches Zero-Day RCE Exploited By China-Linked APT In Secure Email Gateways

Cisco fixes a critical zero-day RCE vulnerability in AsyncOS Software for Secure Email Gateway and Secure Email and Web Manager exploited by China-linked APT UAT-9686, urging customers to apply updates and follow hardening guidelines.

AWS CodeBuild Misconfiguration Exposed GitHub Repositories To Potential Supply Chain Attacks

A misconfiguration in AWS CodeBuild allowed potential takeover of GitHub repositories including aws-sdk-js-v3, exposing cloud environments to supply chain risks. AWS has since remediated the issue.

Five Malicious Chrome Extensions Impersonate Workday And NetSuite To Hijack User Accounts

Security researchers uncover five malicious Chrome extensions impersonating Workday and NetSuite, enabling account hijacking, credential theft and unauthorized access to enterprise systems.

Anthropic Expands Claude Platform With Healthcare Features For Medical Records

Anthropic introduces Claude for Healthcare, enabling Pro and Max subscribers to connect lab results and health records for summaries, insights, and appointment guidance while maintaining privacy and security.

Recent articles

spot_img