Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
New research shows how attacks against some unprotected TSN protocols could allow attackers to disrupt or manipulate physical processes
Lawmakers say little is known about how recent cuts have impacted CISA and how the knowledge that was lost has been replaced.
Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0. The packages are functional and offer the promised date utility functionality, but beneath that garb of date utilities is code designed to drop a Linux backdoor by framing it as a native math accelerator binary.
A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen.
The Open Worldwide Application Security Project has a brand-new top 10 security list tailored for the modern era, and it debuts a Universal Skill Format to add consistency and security to the AI add-ons.
The bank said there is no evidence that its own systems, networks or data repositories were compromised.