For decades, Network Address Translation (NAT) has been the default way IP addresses are provided inside larger networks, as a means to deal with the challenges of IPv4 address availability.
The basic premise behind NAT is that private addresses stay private, but that assum...
Switzerland's federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts. [...]
Maksim Silnikau participated in cybercrime since at least 2005. He ran Ransom Cartel from 2021 until his arrest in 2023.
The post Ransom Cartel creator sentenced to 16 years in prison appeared first on CyberScoop.
Researchers found a way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks and developed an exploit to leak secrets from Linux machines. [...]
In this week's newsletter, Martin looks at how the metaphors we use to describe AI "escaping" its sandbox can completely change how we react to the threat.
Debian has addressed multiple vulnerabilities in the Linux kernel, which could cause privilege escalation, denial of service, or information leaks, advising users to upgrade their packages.
Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests.
The flaw is tracked as CVE-2026-64561 ...
Round two from Black Hat USA 2026. This set covers the parts of the show floor that did not make the first gallery. Scroll through below. Featured vendors: BlackCloak, Teleport, GitGuardian, Oak, Hexnode, Picus Security, Featured speaker: Kate Silverstein (Mozilla) discussing crowd-sourcing protecti...
North Carolina Ports is recovering from a cyberattack after its IT system was “hacked by an outside actor or group,” requiring a switch to manual processing of operations.
Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal security review.
The security issues affect Cisco Catalyst SD-WAN Software, regardless of device configuration, and Cisco IOS XE Softw...
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka, of Kitchener, Ontar...
You wouldn't let Claude Code cat your AWS credentials or Kubernetes config on request, would you?
An exposed SISVISA database leaked 102,215 Brazilian health records, exposing IDs, tax data, and regulatory documents without authentication. Researcher Jeremiah Fowler found a publicly accessible database that turned out to belong to SISVISA, Brazil’s Health Surveillance Information System, and ale...
Connor Moucka pled guilty to hacking and stealing data from more than 165 Snowflake customers, which net him and his accomplices more than $2.5 million in ransom payments.
A local privilege escalation vulnerability in udisks2 (CVE-2026-7867) allows unprivileged users to influence mount execution paths, necessitating an upgrade to version 2.10.1-12.1+deb13u2.
Learn what vishing is, why AI voice cloning makes voice phishing harder to spot, and get vishing attack prevention tips for your business.
L'autorité espagnole de protection des données (AEPD) a publié une décision de classement d'une plainte contre Meta Platforms Ireland Limited, concernant l'utilisation de données personnelles pour l'entraînement de modèles d'intelligence artificielle. La plainte a été rejetée car l'entreprise a volo...
Sanction pour un défaut de gouvernance interne ayant permis un accès non autorisé à des données, une collecte excessive de données sensibles, un manquement à l'information et des communications commerciales illicites.Faits et contexteL'Autorité Nationale de Surveillance du Traitement des Données à C...
An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel using it, re-poisoning the predictor after the defense has run.
MIT CSAIL researchers Daniël Trujillo and Mengjia Yan named the technique INTERRUPT INJEC...
This post assumes familiarity with envelope encryption and the AWS Encryption SDK. When your encryption system generates millions of duplicate API calls per hour, costs spiral and performance degrades. That’s exactly the challenge NICE Actimize faced while operating their global-scale, event-driven...