Cybersecurity
General cybersecurity news and analysis

NIST NCCoE Workshop Tackles Cybersecurity and Privacy in Genomics
What happens when cutting-edge genomics meets the digital age? At the NIST NCCoE workshop, experts gathered to tackle the critical challenge of safeguarding your most personal data—your DNA—while fueling innovation in healthcare and beyond.

5th High-Performance Computing Security Workshop Advances Cyber Defense
As cyber threats evolve, securing the powerful computing systems driving scientific and economic breakthroughs is more crucial than ever—discover how experts at the 5th HPC Security Workshop are shaping the future of cyber defense.

NCCoE Cybersecurity Insights for National Small Business Week
Wondering how to protect your small business from cyber threats that could shut you down overnight? Discover practical, easy-to-follow cybersecurity strategies from the experts at NCCoE to keep your business safe and thriving.

NCCoE Cybersecurity Connections for National Small Business Week
Discover how small businesses can confidently defend against cyber threats with practical, budget-friendly strategies shared at NCCoE’s empowering Cybersecurity Connections event during National Small Business Week.

Key Insights from the 5th High-Performance Computing Security Workshop
Discover how leading experts are tackling the unique security challenges of high-performance computing to protect the breakthroughs that power our future.

IoT Open House: Navigating SP 1800-36 Implementation and Future
Join industry leaders at the forefront of IoT security as they tackle the challenge of protecting network credentials from interception, ensuring our connected devices stay safe and trustworthy from the very first connection.

IoT Open House: Implementing SP 1800-36 and Future Trends
Curious how secure the smart devices in your home or workplace really are? Discover how NIST’s SP 1800-36 is revolutionizing IoT security by tackling the hidden risks of network credential provisioning and paving the way for safer, smarter connections.

Master Cyber AI Profiles: Workshop Insights and Strategies
Discover how cutting-edge AI is transforming cybersecurity by staying one step ahead of evolving threats—join us as experts unveil strategies from the groundbreaking Master Cyber AI profiles workshop.

Inside the Sixth PQC Standardization Conference Advancing Security
Discover how the global cryptography community is racing to protect our digital world from the quantum threat at the 6th PQC Standardization Conference—where cutting-edge algorithms meet real-world security.

Four Arrested in £440M Cyber Attack Targeting UK Retail Giants
Four individuals have been arrested for orchestrating a sophisticated cyber attack that compromised payment systems at major UK retailers, inflicting £440 million in damages and exposing critical vulnerabilities in national digital security. This alarming breach underscores the urgent need for retailers to modernize defenses against rapidly evolving cyber threats.

AI Governance for SaaS Security Leaders: Essential Insights
As generative AI seamlessly integrates into SaaS platforms, security leaders face a pivotal challenge: balancing transformative efficiency gains with the urgent need for robust AI governance to protect sensitive data and manage emerging risks.

ZuRu Malware Targets Developers Through Trojanized Termius macOS App
Cybercriminals have compromised the trusted macOS SSH client Termius, deploying the ZuRu malware through trojanized installers that stealthily infiltrate developers’ systems and threaten critical infrastructure access. This targeted attack underscores the urgent need for heightened vigilance as adversaries exploit trusted tools to gain strategic footholds in high-value environments.

AI Governance Essentials for SaaS Security Leaders in 2024
As AI quietly integrates into everyday SaaS tools, security leaders must navigate a complex landscape where enhanced efficiency meets heightened risks—demanding agile governance frameworks that safeguard data, ensure transparency, and mitigate emerging vulnerabilities.

AMD Alerts on New Transient Scheduler Attacks Threatening Many CPUs
AMD has unveiled a new class of Transient Scheduler Attacks that exploit speculative execution vulnerabilities, putting a broad spectrum of CPUs—from desktops to servers—at risk of exposing sensitive data. This emerging threat highlights the escalating complexity of hardware security, urging swift implementation of mitigations as full patches remain underway.

ServiceNow Flaw CVE-2025-3648 Risks Data Exposure via ACLs
A critical vulnerability in ServiceNow’s Now Platform, CVE-2025-3648, exploits conditional ACLs to indirectly expose sensitive data, underscoring a sophisticated risk that demands immediate patching to safeguard enterprise confidentiality.

Gold Melody IAB Exploits ASP.NET Keys for Unauthorized Access
Gold Melody, an Initial Access Broker tracked as TGR-CRI-0045 by Palo Alto Networks’ Unit 42, exploits leaked ASP.NET machine keys to forge authentication tokens, enabling stealthy, unauthorized access that bypasses traditional security measures and threatens organizational networks at their core.

Automate Ticketing, Device ID, and Threat Triage with Tines
Tines revolutionizes cybersecurity by automating ticketing, device identification, and threat triage through over 1,000 pre-built workflows—empowering security teams to accelerate response times, reduce human error, and cut through alert fatigue with AI-driven orchestration across leading platforms.

Chinese Hacker Xu Zewei Arrested for Silk Typhoon Cyber Attacks
The arrest of Xu Zewei, linked to the state-sponsored Silk Typhoon hacking group, highlights the escalating global challenge of cyber warfare and the critical need for coordinated international efforts to safeguard national security. This case underscores that combating sophisticated cyber threats demands not only law enforcement action but also sustained diplomatic and technological collaboration.

Microsoft Urgently Patches 130 Vulnerabilities Including Critical SQL Flaws
Microsoft has urgently released patches for 130 vulnerabilities—including 10 critical flaws affecting SQL Server—that pose significant risks to enterprise data security, underscoring the urgent need for organizations to strengthen their defenses against evolving cyber threats.

Hackers Exploit Leaked Shellter License to Spread Lumma and SectopRAT
Hackers have exploited leaked Shellter licenses to weaponize this trusted red teaming tool, enabling the stealthy spread of Lumma and SectopRAT malware that evades detection by masquerading as legitimate penetration testing activity. This incident highlights a growing challenge in cybersecurity: safeguarding offensive security tools from misuse without hindering their essential role in strengthening defenses.

Anatsa Android Trojan Infects 90,000 via Fake PDF App on Google Play
Cybersecurity experts have uncovered Anatsa, a sophisticated Android banking trojan infecting 90,000 users via a fake “PDF Update” app on Google Play, exploiting the platform’s trust to steal sensitive banking credentials through convincing overlay attacks. This alarming campaign underscores the evolving threat landscape targeting mobile banking users in North America.

Malicious Pull Request Hits 6,000 Developers Through Ethcode Extension
A sophisticated supply chain attack compromised the Ethcode extension for VS Code, silently infecting over 6,000 developers with malicious code and exposing critical blockchain projects to severe security risks. This breach highlights the urgent need for vigilant verification in software supply chains, where trust can be weaponized to devastating effect.

Ransomware Disrupts Power Meter Readings in Nova Scotia
Ransomware attack disrupts power meter readings in Nova Scotia, impacting utility operations and customer services. Urgent response underway.

New Vulnerability in ServiceNow Allows Attackers to Access Restricted Data
New vulnerability in ServiceNow exposes restricted data, allowing attackers potential access to sensitive information and raising security concerns.