Learn how the Next.js middleware authorization bypass vulnerability works, and how to detect and remediate it.
Une cyberattaque a frappé l'Institut de recherche nucléaire brésilien (IPEN/CNEN) le 28 mars, entraînant la suspension temporaire de la production et de la livraison de six radiofármacos. Les mesures correctives ont été mises en œuvre immédiatement, mais la sécurité physique, radiologique et nucléai...
Qilin. Non revendiqué à date, mais données volées déjà divulguées.
Posted by Chrome Root Program, Chrome Security Team
The Chrome Root Program launched in 2022 as part of Google’s ongoing commitment to upholding secure and reliable network connections in Chrome. We previously described how the Chrome Root Program keeps users safe, and described how the program is...
Newly identified CoffeeLoader uses multiple evasion techniques and persistence mechanisms to deploy payloads and bypass endpoint security
PJobRAT malware targets Taiwan Android users, stealing data through fake messaging platforms
ESET researchers also examine the growing threat posed by tools that ransomware affiliates deploy in an attempt to disrupt EDR security solutions
The ICO’s Deputy Commissioner told Infosecurity that organizations that fail to implement MFA and suffer a breach can expect heavy penalties
Once considered inactive, the Chinese cyber espionage group FamousSparrow has reemerged, targeting organizations across the US, Mexico and Honduras
Once thought to be dormant, the China-aligned group has also been observed using the privately-sold ShadowPad backdoor for the first time
The UK’s National Crime Agency is warning of a growing cyber and physical threat from homegrown teens
The UK’s National Cyber Security Centre has released new guidance to help domain registrars enhance security
Posted by Christiaan Brand, Group Product ManagerWe’re excited to announce that starting today, Titan Security Keys are available for purchase in more than 10 new countries:IrelandPortugalThe NetherlandsDenmarkNorwaySwedenFinlandAustraliaNew ZealandSingaporePuerto RicoThis expansion means Titan Secu...
In its 2025 Global Third-Party Breach Report, SecurityScorecard has found that 35.5% of all cyber breaches in 2024 were third-party related, up from 29% in 2023
ESET researchers discover new ties between affiliates of RansomHub and of rival gangs Medusa, BianLian, and Play
ESET researchers uncover the toolset used by the FamousSparrow APT group, including two undocumented versions of the group’s signature backdoor, SparrowDoor
Threat actors are exploiting cloud platforms like Adobe and Dropbox to evade email gateways and steal credentials
A newly discovered malware campaign uses malicious npm packages to deploy reverse shells, compromising development environments
Australian Cyber Incident - Court Data Breach, 26 March 2025: NSW court website involved in major data breach, 9,000 documents downloaded. Man charged in connection with court document data breach.
The post Incident: NSW court website involved in major data breach, 9,000 documents downloaded | ABC...
Standards body ETSI has defined a scheme for key encapsulation mechanisms with access control (KEMAC), enabling quantum-secure encryption