Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Infoblox's report reveals that expired domains—re-registered via services like DropCatch.com—account for nearly 20% of all new daily domain registrations. These domains inherit the previous owner's reputation and traffic, making them attractive to threat actors who use them to host scams, illegal streams, and malware, often bypassing security products that trust the domain's history.
Authorities have arrested four cybercriminals in Brazil and charged three others in Europe for their involvement in a €30 million bank fraud. The attack exploited a vulnerability at a service provider, which allowed the hackers to access and withdraw funds from Commerzbank customer accounts.
The rapid adoption of AI in cybersecurity research and scanning has led to a dramatic increase in the number of detected software vulnerabilities. This surge is straining existing vulnerability management processes, as human analysts struggle to keep pace with the sheer volume of incoming reports.
IAM compliance is the practice of demonstrating that identity and access controls are enforced across users, applications, and infrastructure, not merely documented. The critical gap between policy intent and runtime execution often leads to compliance failures, as quarterly access reviews may miss application-local accounts or legacy systems.
The Scottish government has disclosed a data breach at its prosecutor's office, caused by a third-party vendor. The breach may extend beyond the initial agency, as the vendor reportedly provided services to other government bodies.
In a significant legal victory for cybersecurity, a UK court sentenced Justin Swaddle, a member of the decentralized cybercrime collective known as The Com, to two years in prison. Swaddle operated under the digital aliases Epstein, Rugen, and Moscow across platforms like Discord, Snapchat, and Telegram, and pleaded guilty to multiple charges of blackmail and child abuse.