Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature.
Attackers can exploit a security bug in NVIDIA's tool to gain unauthenticated access to the local model server through the Ollama API, paving the way for persistent AI agent corruption.
The benefits management firm Paylogix told regulators that hackers stole sensitive information on tens of thousands of people from its systems.
The U.S. Treasury imposed new sanctions on Iranian cyber actors linked to the Islamic Revolutionary Guard Corps (IRGC) as part of an intensified economic campaign against the nation. The sanctions specifically target individuals and entities involved in cyber operations against critical infrastructure.
For decades, cybersecurity defenders have relied on a relatively straightforward model: a vulnerability is disclosed, security teams assess exposure, test available fixes, deploy patches into production, and ultimately close the risk before attackers can exploit it at scale. That model increasingly reflects a world that no longer exists.
A large distributed denial-of-service (DDoS) attack has disrupted Norway's shared government digital infrastructure since Monday, affecting services used by the public sector.