Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Ernst & Young disclosed a data breach involving a compromised third-party IT support platform, potentially exposing client documents, tax details, and employee information. Jscrambler, a JavaScript protection tool, suffered a supply chain attack via stolen npm credentials, distributing malware targeting developer credentials.
CrowdStrike discusses how frontier AI models are being harnessed to deliver stronger cyber defense capabilities. These advanced models improve detection accuracy while reducing false positive rates.
The article explores how cutting-edge AI models can enhance cybersecurity defenses beyond traditional approaches. It discusses integrating AI into threat detection and response workflows to improve efficiency and accuracy.
HKCERT warns of multiple vulnerabilities in Microsoft Edge that could be exploited by attackers, urging users to apply the latest security updates to protect their systems.
This article from HKCERT alerts about multiple vulnerabilities in WordPress. The content lacks specific details, but it emphasizes the need for users to apply security patches and updates to protect their installations.
The Inc ransomware operation exploited two zero-day vulnerabilities in SonicWall SMA (Secure Mobile Access) appliances, chaining them together to gain root-level access to affected devices. The two vulnerabilities — one providing initial access and the other enabling privilege escalation — allowed the threat actors to bypass authentication, execute arbitrary code, and establish persistence at the highest privilege level on the SMA appliances.