Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Unlimited Technology Systems reported a data breach that impacted over 3.8 million individuals, which occurred in October 2025. The incident highlights security vulnerabilities in healthcare software companies.
The National Rural Water Association has partnered with cybersecurity experts to launch the Water Watch Center, a program designed to help financially constrained water utilities combat growing cyber threats. The initiative aims to give smaller utilities access to needed security support.
This article reports on a campaign that published nearly 800 malicious npm packages capable of infecting Windows, macOS, and Linux systems with a RAT and infostealer. The attack chain starts with a README instructing developers to use require(), which triggers the WEL1DROPPER downloader.
This article from Broadcom explains why native telemetry correlation is essential for effective XDR. It argues that the best XDR does not just collect signals but connects them, highlighting 11 reasons this integration matters for security operations.
This article details a ClickFix-style attack chain delivering a macOS stealer written in Go. The malware steals passwords, iCloud Keychain data, and cached credentials, and includes a DRAIN routine that depletes cryptocurrency wallets.
This article describes UNC6671, a data extortion group that targets financial services, private equity, and professional services firms through vishing. The attackers call employees on personal phones, impersonate IT help desk staff, and use spoofed portals to steal credentials and MFA tokens.