Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
While guardrails are critical, as evidenced by recent high-profile incidents, defenders need help staying ahead of attackers who do not play by the rules.
At least $6 million was stolen from crypto platform Tectonic after an attacker manipulated the price of the Tonic coin over the weekend.
When customers kept pointing us to Upwind, a solution overlapping with parts of our own offering, we had a choice to make. We decided to bring them into AWS Security Hub Extended because customers asked us to simplify adoption and integration of the tools already working for them.
A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal.
OpenAI's Hugging Face attack postmortem shows agents don't care about rules — they need strong controls.
Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected workers employed in sales and marketing and the medical profession. The ongoing insider threat is part of what has been described as the IT worker scheme, where North Korea leverages its network of skilled IT workers, both within and outside the country, to fraudulently land jobs in Fortune 500 companies and private sector firms across the world and remotely perform work under false identities.