Tag: supply chain attacks
44 articles

Adobe Reader Zero-Day Exploits PDFs to Profile Targets
Malicious PDFs are being used to secretly profile targets, leveraging legitimate features to harvest system data and decide which victims are worthy of a second, more invasive attack. This sneaky tactic uses booby-trapped PDFs to quietly gather intel and determine if you're a high-value target.

Cybersecurity Demands Critical Unified Defense Against Alarming Threats
As our digital dependence grows, so do the alarming cyber threats that can cripple even the strongest organizations - making a unified defense strategy more crucial than ever. With ransomware, AI-driven threats, and supply chain attacks on the rise, it's time to fortify your defenses and safeguard your future.

North Korean Lazarus Group Exclusive: Dangerous Medusa Surge
When hospitals open their doors, their networks shouldnt open to extortion — but a surge in Medusa ransomware tied to North Koreas Lazarus Group is forcing technologists, health‑care leaders and policymakers to decide how to lock them. These attacks — a blend of state‑grade tools and criminal tactics — risk disrupted care, delayed diagnoses and real harm to patients.

DISA’s New Mobile Device STIGs: Must-Have Best Practices
Phones now carry mission plans — and adversaries know it. DISA’s new mobile device STIGs offer a practical, modern playbook — enforced encryption, hardware-backed MFA, stricter app controls, and mandatory Mobile Threat Defense — to secure smartphones without sacrificing soldier mobility.

Ransomware Exclusive: Stunning Worst Surge of 2025
Think ransomware was fading? The 2025 ransomware surge proves otherwise—smarter, faster attacks (retail incidents jumped 58% in Q2) are crippling stores, exposing data and stretching insurers and regulators to the breaking point.

FCC Ends Telecom Cyber Rules in Stunning Security Setback
The FCC’s sudden rollback of the telecom cyber rules born from the Salt Typhoon crisis has industry and security experts asking whether we just pulled the rug out from under a critical line of defense. Can voluntary standards and federal guidance really fill the gap, or did we trade stronger protections for regulatory convenience?

State-Sponsored Cyber Attacks: Exclusive Critical Threat
State-sponsored cyber attacks are escalating — learn how nation-backed hackers target organizations and practical steps you can take to stay one step ahead.

Fraud Fears: Exclusive Reassuring Outlook for Holidays
Worried about holiday fraud? ICO data shows no Q4 2024 spike in reported data breaches — a reassuring sign, but one that forces us to ask whether criminals have gone stealthier or our reporting systems are missing the real threat.

ThreatsDay Exclusive: Critical Cyber Threats Unveiled
Think clicking a browser add-on or plugging in a smart camera is harmless? This ThreatsDay roundup exposes how weaponized everyday tools — from extensions and smart gadgets to satellite feeds and SMS — turn convenience into a covert battleground of surveillance, social engineering, and supply‑chain attacks.

New Attacks Against Secure Enclaves: Stunning, Severe Flaws
Think your data’s safe while it’s being processed? New, surprisingly low-cost attacks against secure enclaves prove otherwise, exposing severe weaknesses that demand urgent fixes like authenticated memory and continuous attestation.

Google Forecasts Stunning 2026 EU Cyber-Physical Threats
Google warns Europe is likely to face a surge of cyber-physical attacks in 2026 — digital intrusions paired with disinformation that could disrupt power, transport and industry. With legacy control systems, rushed digitization and weak third-party security widening the attack surface, now’s the time to shore up defenses.

Collaboration and AI: Exclusive Best Defense for Agencies
Federal agencies face a stark choice: embrace collaboration and AI to outpace adversaries, or watch attackers scale their impact with automation. Sharing telemetry, interoperable tools, and AI-driven detection lets agencies multiply scarce resources and turn fragmented defenses into a resilient, machine-speed shield.

Collaboration and AI: Must-Have for Best Cyber Resilience
Collaboration and AI are now mission-critical: combining shared threat intelligence with AI-powered detection and response lets federal agencies move faster and smarter against increasingly automated, sophisticated attacks. Together they turn scattered defenses into a coordinated, scalable shield for mission-critical data.

60% of Security Leaders: Stunning, Critical Threat Shift
Sixty percent of security leaders warn that threat actors are evolving too quickly for organizations to keep up. Commodified cybercrime, automation and an expanding attack surface are squeezing defenders’ time to detect, respond and contain — and the consequences are real.

Cybersecurity Awareness Month Must-Have Best Practices
Treat Cybersecurity Awareness Month as a springboard—use October to roll out MFA and least-privilege access, formalize patching and harden systems, and run realistic, measurable phishing simulations. Turn short-term attention into year‑round security gains that actually reduce risk.

Threat Actors: Exclusive Surge in Dangerous App Exploits
Exclusive: Threat actors are unleashing a dangerous surge in app exploits—here’s what’s driving the spike and quick, practical steps to keep your apps and users safe.

Lazarus Group Exclusive: Dire Threat to European Defense
Who watches the watchers? Researchers say North Korea’s Lazarus Group—behind Operation “DreamJob”—has quietly infiltrated European drone and counter‑UAS R&D to steal designs, credentials and test data, putting the continent’s push for a layered “drone wall” at real risk of espionage, sabotage and costly setbacks.

malicious npm code: Critical Risk, Must-Have Defenses
Think supply chain attacks are theoretical? Wiz found malicious npm code in about 10% of cloud environments — proof a single tainted dependency can ripple across services. Treat dependencies like security controls: use SBOMs, provenance checks, and runtime defenses to keep builds safe without slowing teams down.

SBOM minimums Must-Have Best Practices
CISA is revisiting its 2021 SBOM minimums and asking stakeholders for input to strike the right balance between useful, machine-readable inventories that speed vulnerability response and safeguards that prevent sensitive detail from aiding attackers. The update could nudge industry toward interoperable, automatable SBOMs while building practical options for protecting proprietary or security-sensitive information.

supply chain attacks: Risky npm compromise – Must-Have alert
When a trusted npm package—eslint-config-prettier—was hijacked to deliver the Scavenger RAT, it turned the open-source supply chain into an attack highway. Developers and teams must treat dependencies as potential threats: pin versions, enable 2FA, rotate secrets, and hunt for compromises before convenience becomes a vulnerability.