Latest news

  1. AI Security via SpecterOps

    CiliumHound: Graphing Kubernetes Network Policies

    TLDR: CiliumHound is a BloodHound OpenGraph extension for auditing Cilium network policies. It ingests a folder of JSON or YAML policies and creates a searchable…

  2. AI Security via Microsoft Security

    Improving email security outcomes with real-world Microsoft Defender insights

    Every benchmark tells a story. The most valuable ones tell us where to improve next. For five consecutive quarters Microsoft has published email security benchmarking…

  3. Breaches via HIPAA Journal

    Brevard Skin and Cancer Center Settles Class Action Complaint

    The Florida dermatology practice, Brevard Skin and Cancer Center, has agreed to a settlement to resolve class action litigation stemming from a 2025 cyberattack and data…

  4. Breaches via HIPAA Journal

    Hacking Group Claims Attack on Cedar County Memorial Hospital

    A hacking group has claimed responsibility for an August 2026 cyberattack on Cedar County Memorial Hospital in Missouri. Hacking-related data breaches have been reported…

  5. Breaches via DataBreaches.net

    Port of LA Fended Off 120 Million Cyberattacks in August

    PYMNTS reports: The Port of Los Angeles reportedly blocked more than 120 million cyberattacks during August. That’s according to a report Thursday (Sept. 17) by…

  6. Vulnerabilities via The Hacker News

    Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

    Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the…

  7. Vulnerabilities via Canadian Centre for Cyber Security

    Cisco security advisory (AV26-932)

    Serial number: AV26-932 Date: September 17, 2026 As of September 16, 2026, Cisco is affected by vulnerabilities in the following products: Cisco Secure Firewall Threat…

  8. Breaches via The Register

    London property manager breach may have exposed bank details and lockbox codes

    London property management biz City Relay has warned customers that intruders may have stolen financial data, passwords, and codes used to access keys after compromising…

  9. Threat Intel via SANS Internet Storm Center

    LausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)

    At the end of August, a malspam message was caught in the quarantine of a mail gateway operated by one of my customers. The message was not especially remarkable – it…

  10. Vulnerabilities via CERT/CC

    VU#280377: Dokploy is vulnerable to OS command injection

    Overview Dokploy versions 0.29.8 and 0.29.11, as well as commit 24b02f5 on the canary branch, are vulnerable to OS command injection during the backup creation and…

  11. Threat Intel via Infosecurity Magazine

    FamousSparrow Swaps SparrowDoor For New SparroWocky Backdoor

    ESET said FamousSparrow has replaced SparrowDoor with SparroWocky

  12. Vulnerabilities via Cisco PSIRT

    Cisco Secure Email Gateway SQL Injection Vulnerability

    A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary…

  13. Breaches via Graham Cluley

    US Coast Guard and FBI board oil tanker to investigate cyber attack

    An oil tanker bound for Texas was boarded mid-voyage by the US Coast Guard and FBI last month, after its network may have been compromised by malicious hackers…

  14. AI Security via Check Point Research

    AI Threat Landscape Digest: July–August 2026

    The defining development of the period came not from attackers but from the AI labs themselves, whose models broke out of controlled evaluations and reached real…

  15. Vulnerabilities via Wiz

    Exploring the new AWS Sign Up experience

    This post will explore what this new concept does, how it works with the new Account Access capability, and why a strong security posture still requires upgrading out of…

  16. Threat Intel via Security Affairs

    SilkParasite Infrastructure Links SpiceRAT to Central Asian Targets

    Hunt.io links SpiceRAT, NodeEdgeRAT and NomadRAT to a four-year SilkParasite campaign targeting governments and critical sectors in Central Asia. Hunt.io and researcher…

  17. Breaches via Malwarebytes Labs

    Revolut phishing texts appear days after data breach

    Only days after Revolut acknowledged that it disclosed sensitive customer records to an unauthorized party, affected customers are receiving phishing texts. However, we…

  18. AI Security via Wiz

    Building an AI Detection Engine That Understands Agent Intent

    Analyzing model input and output logs in an AI-native detection pipeline to understand and uncover malicious AI agent behavior

  19. Threat Intel via The Hacker News

    Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords

    The Iran-linked "hacktivist" persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility…

  20. Threat Intel via Flashpoint

    Flashpoint Named A Customer Favorite in The Forrester Wave™

    Blogs Blog Flashpoint Named A Customer Favorite in The Forrester Wave In this blog we explore the recently published Forrester Wave: External Threat Intelligence Service…