Latest news
-
AI Security via SpecterOps
CiliumHound: Graphing Kubernetes Network Policies
TLDR: CiliumHound is a BloodHound OpenGraph extension for auditing Cilium network policies. It ingests a folder of JSON or YAML policies and creates a searchable…
-
AI Security via Microsoft Security
Improving email security outcomes with real-world Microsoft Defender insights
Every benchmark tells a story. The most valuable ones tell us where to improve next. For five consecutive quarters Microsoft has published email security benchmarking…
-
Breaches via HIPAA Journal
Brevard Skin and Cancer Center Settles Class Action Complaint
The Florida dermatology practice, Brevard Skin and Cancer Center, has agreed to a settlement to resolve class action litigation stemming from a 2025 cyberattack and data…
-
Breaches via HIPAA Journal
Hacking Group Claims Attack on Cedar County Memorial Hospital
A hacking group has claimed responsibility for an August 2026 cyberattack on Cedar County Memorial Hospital in Missouri. Hacking-related data breaches have been reported…
-
Breaches via DataBreaches.net
Port of LA Fended Off 120 Million Cyberattacks in August
PYMNTS reports: The Port of Los Angeles reportedly blocked more than 120 million cyberattacks during August. That’s according to a report Thursday (Sept. 17) by…
-
Vulnerabilities via The Hacker News
Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files
Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the…
-
Vulnerabilities via Canadian Centre for Cyber Security
Cisco security advisory (AV26-932)
Serial number: AV26-932 Date: September 17, 2026 As of September 16, 2026, Cisco is affected by vulnerabilities in the following products: Cisco Secure Firewall Threat…
-
Breaches via The Register
London property manager breach may have exposed bank details and lockbox codes
London property management biz City Relay has warned customers that intruders may have stolen financial data, passwords, and codes used to access keys after compromising…
-
Threat Intel via SANS Internet Storm Center
LausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)
At the end of August, a malspam message was caught in the quarantine of a mail gateway operated by one of my customers. The message was not especially remarkable – it…
-
Vulnerabilities via CERT/CC
VU#280377: Dokploy is vulnerable to OS command injection
Overview Dokploy versions 0.29.8 and 0.29.11, as well as commit 24b02f5 on the canary branch, are vulnerable to OS command injection during the backup creation and…
-
Threat Intel via Infosecurity Magazine
FamousSparrow Swaps SparrowDoor For New SparroWocky Backdoor
ESET said FamousSparrow has replaced SparrowDoor with SparroWocky
-
Vulnerabilities via Cisco PSIRT
Cisco Secure Email Gateway SQL Injection Vulnerability
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary…
-
Breaches via Graham Cluley
US Coast Guard and FBI board oil tanker to investigate cyber attack
An oil tanker bound for Texas was boarded mid-voyage by the US Coast Guard and FBI last month, after its network may have been compromised by malicious hackers…
-
AI Security via Check Point Research
AI Threat Landscape Digest: July–August 2026
The defining development of the period came not from attackers but from the AI labs themselves, whose models broke out of controlled evaluations and reached real…
-
Vulnerabilities via Wiz
Exploring the new AWS Sign Up experience
This post will explore what this new concept does, how it works with the new Account Access capability, and why a strong security posture still requires upgrading out of…
-
Threat Intel via Security Affairs
SilkParasite Infrastructure Links SpiceRAT to Central Asian Targets
Hunt.io links SpiceRAT, NodeEdgeRAT and NomadRAT to a four-year SilkParasite campaign targeting governments and critical sectors in Central Asia. Hunt.io and researcher…
-
Breaches via Malwarebytes Labs
Revolut phishing texts appear days after data breach
Only days after Revolut acknowledged that it disclosed sensitive customer records to an unauthorized party, affected customers are receiving phishing texts. However, we…
-
AI Security via Wiz
Building an AI Detection Engine That Understands Agent Intent
Analyzing model input and output logs in an AI-native detection pipeline to understand and uncover malicious AI agent behavior
-
Threat Intel via The Hacker News
Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords
The Iran-linked "hacktivist" persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility…
-
Threat Intel via Flashpoint
Flashpoint Named A Customer Favorite in The Forrester Wave™
Blogs Blog Flashpoint Named A Customer Favorite in The Forrester Wave In this blog we explore the recently published Forrester Wave: External Threat Intelligence Service…
