We demonstrate how the open-source Payload CMS was ported to run entirely on Cloudflare's developer platform.
New smishing attacks exploit Milesight routers to send phishing texts targeting Belgian users
Guidance for staff responsible for managing a cyber incident response within their organisation.
Despite Rocket Software's claims of regular security audits and adherence to secure coding practices, our team discovered multiple critical, pre-authentication vulnerabilities in TRUfusion Enterprise—a mission-critical software used for transferring highly sensitive data.
New Android RAT Klopatra is targeting financial institutions using advanced evasion techniques
Written by: Omar ElAhdan, Matthew McWhirt, Michael Rudden, Aswad Robinson, Bhavesh Dhake, Laith Al
Background
Protecting software-as-a-service (SaaS) platforms and applications requires a comprehensive security strategy. Drawing from analysis of UNC6040’s specific attack methodologies, this guide p...
In episode 70 of The AI Fix, our hosts learn that AI makes people more dishonest, Waymo's robo-cars save lives but get outsmarted by a bathroom mirror, a "rescue" bot slurps up victims head-first, and China shows off a fusion robot arm that can lift ten elephants (or 200,000 pigeons, if you’re scien...
Google has launched a new AI-based protection in Drive for desktop that can shut down an attack before it spreads—but its benefits have their limits.
The Trump administration wants CISA to transition to a “new model” for supporting local government agencies’ cyber strategy
Tenable researchers have discovered three vulnerabilities in Google’s Gemini GenAI tool
Google can create and manage passkeys from your browser, but the process is more involved than it suggests.
Two 17-year-olds have been arrested by Dutch authorities on suspicion of spying for pro-Russian hackers.
The teenagers, who are said to have been recruited as "disposable agents" via Telegram, were reportedly arrested last week "on suspicion that are linked to government-sponsored interference."...
On September 29, 2025, Internet connectivity was completely shut down across Afghanistan, impacting business, education, finance, and government services.
Phantom Taurus is a previously undocumented Chinese threat group. Explore how this group's distinctive toolset lead to uncovering their existence.
The post Phantom Taurus: A New Chinese Nexus APT and the Discovery of the NET-STAR Malware Suite appeared first on Unit 42.
Japanese brewery giant Asahi revealed that a cyber-attack had caused a “system failure”, with order and shipment operations suspended in Japan
Most UK cybersecurity professionals tell CIISec that their budgets are stagnating
Updated information to include CVSS scores. This is an informational change only.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Endpoint Manager. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. Alternatively, no user interaction is require...
This vulnerability allows local attackers to escalate privileges on affected installations of Razer Synapse 3. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The followin...