Global Intelligence Search
Query the entire database for vulnerabilities, news articles, open-source security tools, and known threat actors.
How an Emerging Industrial Protocol Family Could Put OT at Risk
In operational technology (OT) networking, the reliability and availability of industrial processes trumps everything, even cybersecurity. But what happens when an OT networking protocol designed to ensure speedy...
Postal Service moves to finalize mail ballot regs before SCOTUS ruling
In a late Friday night posting to the Federal Register, the U.S. Postal Service said it is finalizing new regulations that would give the federal government potentially vast powers to control mail-in ballots for voters....
Apollo discloses data breach from ongoing wave of attacks hitting financial sector
Apollo Global Management confirmed it was among several financial institutions impacted by a string of social engineering attacks that hit the sector last month, the company said Friday. Attackers gained unauthorized...
Lawmakers seek watchdog review of federal hacking of Americans
A pair of lawmakers wants a watchdog agency to probe how the federal government hacks Americans, including with the use of spyware, and deliver a report to the public. Sen. Ron Wyden, D-Ore., and Rep. Greg Casar,...
Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind
Two industry surveys released this week paint a consistent picture of the defense industrial base: contractors say they’re more confident in their cybersecurity compliance than ever, even as their ability to prove that...
Microsoft Patches Exploited Entra ID Vulnerability
Microsoft on Thursday announced the rollout of 22 new security updates that resolve severe vulnerabilities across multiple products, including a critical Entra ID zero-day exploited in attacks. The exploited Entra ID...
CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities
The US cybersecurity agency CISA on Thursday warned federal agencies that threat actors have been exploiting two vulnerabilities in TrueConf. A secure on-premises video conferencing platform, TrueConf relies on Scalable...
New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets
iAuthFlow V2 is a new phishing toolkit demonstrating the rapidly improving sophistication of phishing techniques. iAuthFlow V2 is a malware toolkit first seen on a Russian-language cybercrime forum. It is an advanced...
Critical Isolated-vm Vulnerability Leads to RCE on Host
A critical-severity type confusion in the isolated-vm Node.js library could allow threat actors to achieve remote code execution (RCE) on the host system. Through isolated-vm, developers can access the V8 JavaScript...
Rust Supply Chain Attack Linked to North Korean Hackers
North Korean hackers are responsible for a new open source software (OSS) supply chain attack targeting the Rust ecosystem, cybersecurity firm Wiz reports. The attack occurred on August 20 and involved one of the most...
Former NSA Director Paul Nakasone Launches National Security Advisory Firm
Retired U.S. Army General Paul M. Nakasone, former director of the National Security Agency and commander of U.S. Cyber Command, has launched a boutique national security advisory firm. The newly-formed Nakasone Group...
In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug
SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape. This curated...