Multistate Water System Attacks Widen, Iran Suspected
Attacks targeting water systems just keep flowing across a dozen states, against ill-secured, Internet-exposed PLCs.
Attacks targeting water systems just keep flowing across a dozen states, against ill-secured, Internet-exposed PLCs.
A maximum-severity zero-day vulnerability in Metabase allows remote attackers to gain administrator access to the business-analytics platform, potentially exposing both the platform itself and its downstream users to compromise. The flaw remains unpatched and has not yet been assigned a CVE identifier, creating immediate risk for organizations using the affected software.
A growing number of UK venues have decided to act against privacy-busting smart glasses. Read more in my article on the Hot for Security blog.
It's time to turn from CVSS-backed patching to choke-point patching focused on breaking chains to critical assets.
Sophisticated iPhone exploit chains that were previously restricted to nation-state actors are now proliferating among organized cybercrime groups globally. The Coruna and DarkSword exploits represent a significant shift in the accessibility of advanced iOS attack capabilities, expanding the threat landscape beyond state-sponsored operations to larger criminal ecosystems.
A public policy expert has developed a five-point framework to address gaps in global cybercrime legislation that currently expose ethical hackers and security researchers to legal risk. The analysis maps existing cybercrime laws across jurisdictions to identify how outdated regulations fail to adequately protect good-faith security research activities. This framework aims to guide policymakers in updating laws to better distinguish between malicious hacking and legitimate security work.
Microsoft has been recognized as a Leader in the 2026 IDC MarketScape for managed detection and response services, reflecting competitive positioning in the enterprise MDR/MXDR market. The company's Defender Experts MDR offering integrates artificial intelligence, threat intelligence, and human security expertise to deliver detection and response capabilities.
The crime solver wore disguises, spied on targets, and built intelligence networks long before modern-day tactics emerged. He has lessons for today's ethical- and unethical hackers.
Researchers discovered a vulnerability in Atlassian's Rovo AI assistant that could allow attackers to exfiltrate company data through a single crafted link. Atlassian has issued a fix for the flaw, which was tracked as RovoBlast. The vulnerability highlights potential risks in AI-assisted tools used for enterprise collaboration and knowledge management.
DeadLock is an emerging financially motivated ransomware operation that leverages Rust-based encryption alongside decentralized infrastructure to manage victim communications, negotiations, and data leak operations. The group employs double extortion tactics to pressure victims into paying ransom demands, combining encryption with threats of public data disclosure.
Poisoned JSON feed let attackers backdoor WordPress sites without changing any plugin files
For the latest discoveries in cyber research for the week of 10th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES North Carolina Ports, the US authority operating the ports of Wilmington, Morehead City and others, has suffered a cyberattack that forced some operations onto manual processes. The authority claims it has contained […] The post 10th August – Threat Intelligence Report appeared first on Check Point Research.
Go inside Huntress and the FBI’s five-year pursuit of Silk Typhoon, from 88,000 Exchange backdoors to an arrest and a wider fight against cybercrime.
Key Takeaways Human-speed compliance is dead. Attackers utilizing modern, autonomous AI tools can chain enterprise misconfigurations and weaponize vulnerabilities in under 25 minutes, rendering manual, periodic audit cycles completely obsolete. The “Configuration Gap” is your biggest blind spot. Organizations take an average of 14 months to remediate basic identity, access control, and logging flaws, leaving […]
Gunra is a ransomware-as-a-service operation leveraging a double-extortion model to target government, critical infrastructure, and other organizations across multiple sectors worldwide, with initial access primarily achieved through exploitation of known vulnerabilities in VPN gateways and firewall appliances. The threat actors employ sophisticated lateral movement techniques, credential theft, and data exfiltration before deploying ChaCha20 + RSA-4096 encryption, while using tools like Impacket and secretsdump.py to move laterally and extract credentials from domain controllers. Organizations should prioritize patching exploited vulnerabilities, implementing offline immutable backups, enforcing multi-factor authentication, and segmenting networks to contain potential lateral movement.
Introducing Architecting the Hunt. Great threat hunting starts with the right questions. This entry-level mini course teaches you a repeatable framework that turns guesswork into a disciplined cycle. You'll learn how to form a hypothesis, acquire the right data, apply core hunting techniques, counter the biases that derail investigations, and communicate your findings. Then practice what you learned in a hands-on lab. No prior experience needed!
Ghostjacking exploits the trusted access of AI agents to bypass firewall controls by feeding them fabricated reports, a technique that Tenet found affects half of Fortune 500 companies. This vulnerability highlights a critical gap in how AI systems validate information sources before executing privileged actions. Security teams must reassess their AI agent configurations to verify data authenticity and restrict unnecessary elevated permissions.
The report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as well as internet of things (IoT) devices, during Q2 2026.