Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Researchers at Hudson Rock found that cybercriminals hijacked HBO Max’s verified Reddit account and used it to run 108 malicious ads over roughly 48 hours. The ads used HBO Maxs trusted corporate account to promote fake AI tools, developer software, and macOS utilities, lowering potential victims’ guards.
The article argues that security teams have become proficient at testing individual detection techniques — whether an EDR catches a payload, a phishing simulation succeeds, or a SIEM rule fires — but this isolated testing misses the broader attack chain picture. Real adversaries do not test techniques one at a time; they chain multiple tactics together in coordinated attack sequences.
CISA released new guidance on open source software security principles and practices, covering risk management, trust assessment, vulnerability management, SBOMs, and secure development. The guidance helps agencies securely use, evaluate, and publish open source software.
Five alleged leaders of the Black Axe cybercrime syndicate, known for its involvement in global-scale cyber-enabled financial fraud, have been extradited to the United States to face wire fraud and money laundering charges.
If youre still OK with posting pictures of your kids on social media, take a minute to hear from mother of two Kalie Robins. At the start of September, she did something that hundreds of thousands of parents do every day.
Bitrefill is a legitimate company that sells gift cards for popular stores like Amazon, Deliveroo, Apple, Nintendo, and thousands of others. They also sell eSIMs, and mobile top-ups.