Tag: cyber threats
601 articles

Iran-Backed Hackers Infiltrate US Industrial Controls
US cyber and intelligence agencies have sounded the alarm: pro-Iran hackers have infiltrated and disrupted critical US infrastructure, including water and energy systems, posing a pressing threat to national security. These foreign actors have breached government networks and industrial controls, sparking urgent concerns about the vulnerability of America's essential services.

APAC Firms Scramble to Bolster Cloud Security Amid Rising Identity Risks
As APAC firms rush to adopt cloud technology, they're faced with a daunting dilemma: do they risk advancing without a plan, or delay and let identity-related risks leave them vulnerable? With identity issues already causing the majority of cloud breaches in the region, the clock is ticking to get cloud security right.

AI Takes Center Stage at Federal Cybersecurity Summit
At the Federal Cybersecurity Summit, AI is taking center stage as a crucial tool for federal leaders to tackle the daunting challenge of evolving cyber threats and limited resources. The summit aims to spark a practical conversation on harnessing AI-driven defenses to move beyond mere compliance and toward effective, real-world solutions.

Venom Phishing Platform Targets C-Suite Execs in Credential Theft Campaigns
Meet Venom, a sneaky new phishing platform that's putting top executives in its crosshairs, threatening to drain their credentials and wreak havoc on corporate boardrooms. This automated threat is scaling up credential theft like never before, making it a high-risk concern for senior leaders and their organizations.

Residential Proxies Bypass IP Reputation Checks in Most Sessions
Residential proxies are making it increasingly difficult for defenders to block threats, as they bypass IP reputation checks in a staggering 78% of cases, blending in with ordinary home users. This alarming trend is blurring the lines between attackers and legitimate users, making it harder to keep malicious traffic at bay.

Akira Ransomware Executes Attacks in Under 60 Minutes
Akira ransomware has become alarmingly efficient, capable of executing a full-scale attack in under 60 minutes - leaving organizations with an incredibly tight window to detect and respond to threats. This lightning-fast strike highlights the urgent need for robust security measures to counter the rapidly evolving ransomware landscape.

Bugs Chain Into Massive Backdoors, Threats Multiply
When small flaws are linked together, they can create massive backdoors - and the latest ThreatsDay Bulletin is sounding the alarm on this rapidly escalating threat landscape. The result? A multiplying list of active problems demanding attention now.

OT Attacks Threaten £5m Downtime Hit on CNI Firms
A single cyberattack on operational technology systems could cripple critical infrastructure providers, causing up to £5m in downtime losses and days of operational paralysis. For organisations that underpin essential services, the stakes have never been higher.

LLMs Introduce New Vectors for Cyber Threats
Imagine a chatbot designed to streamline your workflow secretly leaking confidential information - a frightening possibility that's no longer just hypothetical. As large language models are rapidly integrated into everyday tools, a new wave of hidden vulnerabilities is emerging, threatening to turn convenience into a security nightmare.

NIST Guidance Offers Critical Framework for Rapid Cyber Incident Response
In today's high-stakes cybersecurity landscape, it's not a question of if you'll be breached, but when - making swift and effective incident response a critical priority. NIST guidance provides a vital framework for responding to cyber incidents quickly and minimizing damage.

TikTok Phishing: Alarming AiTM Campaign Targets Business Accounts
Beware of a sneaky new phishing campaign targeting TikTok Business accounts, using clever AiTM tactics to steal login credentials. Don't get caught out - stay vigilant and protect your account from these cunning cyber threats!

Critical Telecom Threats Resurface in Alarming New Campaigns
Stay vigilant, as the latest telecom threat campaigns are emerging with renewed ferocity, exploiting familiar attack methods in new and sophisticated ways. Are you prepared for the next big threat and equipped to safeguard your digital landscape?

BeaverTail and OtterCookie: Stunning Critical Threat
Cisco Talos warns a North Korean group is fusing BeaverTail’s credential-theft with OtterCookie’s browser persistence into single, stealthier JavaScript malware that’s harder to spot — defenders should start hunting for blended behaviors and tighten basics like MFA, patching, and anomaly detection now.

board-level readiness: Must-Have Critical Wake-Up
The NCSC and ministers have warned FTSE 350 chiefs that many boards are leaving the digital front door wide open—it’s time for executives to treat cyber as a strategic priority, not an IT problem. Stronger board-level accountability, realistic testing and smarter supplier checks can stop breaches from becoming boardroom crises.

Boyd Gaming Corporation Exclusive: Risky Breach
Boyd Gaming has confirmed an unauthorized actor removed data from its systems — a worrying development for employees and guests that raises urgent questions about what types of information were exposed and how many people were affected. The company says it’s working with forensic experts and law enforcement, but clearer, timely disclosures and concrete protections will be crucial to restore trust.

CVE program: Must-Have Global Control Sparks Risky Debate
CISA wants a bigger role running the CVE vulnerability list — promising more stability and coordination but sparking worries that government control could politicize a vital global standard.

GhostRedirector: Exclusive Dangerous China-Aligned Threat
A newly discovered group called GhostRedirector quietly breached 65 Windows servers using custom tools and stealthy redirection techniques, and its infrastructure and tradecraft point to China-aligned objectives. Treat this as a wake-up call to move beyond signature-based detection, hunt for anomalous behavior, and harden your systems now.

cybersecurity legislation: Must-Have Rules, Risky Tradeoffs
A new CIISec poll shows most security professionals want tougher, clearer cybersecurity laws—urging policymakers to create practical, enforceable rules that boost defenses without stifling innovation. If lawmakers listen and invest in enforcement and workforce skills, stronger regulation could deliver real protection for businesses and citizens.

letters of marque: Risky Must-Have Cyber Tool
A new bill would revive the old idea of “letters of marque” for the digital age, letting the President commission vetted “white hat” hackers to pursue and seize foreign cyber threats. It promises faster, private‑sector firepower against attackers — but brings big legal, ethical and escalation risks that lawmakers will have to reckon with.

helmet-mounted displays: Exclusive, Best Tactical Edge
Helmet‑mounted displays are no longer niche pilot toys but powerful force multipliers that merge sensors, targeting, and comms into a pilot’s line of sight—while also creating new vulnerabilities to jamming, spoofing, and human error. Keeping the tactical edge means hardening systems, training for degraded conditions, and designing HMDs pilots can trust.

phishing campaign: Stunning Risk to UK Sponsors
A slick phishing campaign is targeting Home Office sponsor licence holders, risking fraud, extortion and even licence revocation by stealing the credentials used to manage migrant sponsorships. If you manage a sponsor account, verify any Home Office contact, enable MFA, and treat unexpected emails with extreme caution to protect your organisation and the people you sponsor.

AI Cybersecurity Threats: Must-Have Best Practices
AI can be both defender and threat—and NIST’s NCCoE is leading virtual sessions to shape the Cyber AI Profile, offering practical guidance to spot AI-enabled risks and harden defenses. Whether you’re a technologist, policymaker, or business leader, this essential guide shows how to harness AI safely and stay ahead of evolving cyber threats.

Secure Software Development: Must-Have Best Practices
Worried about the security of the software we all depend on? Join NIST NCCoE’s interactive DevSecOps virtual event on August 27, 2025, to hear experts, learn practical secure development practices, and help turn security from an afterthought into a foundation for every project.

AI Cyber Defense: Must-Have Strategies for Best Security
Join NIST NCCoE’s virtual working sessions to explore how the Cyber AI Profile can harness AI to sharpen threat detection, cut alert fatigue, and strengthen defenses—while tackling the ethical and security risks that come with it. Technologists, policymakers, and practitioners are invited to collaborate and shape trustworthy, practical AI-driven cybersecurity solutions.