Researchers discovered hackers-for-hire performing cyber espionage and financially motivated heists from the same Web panel.
The trust framework underlying Belgium's electronic ID system was fully compromised by severe vulnerabilities in a key browser extension, showcasing bigger problems with extensions in general.
The "City-Forum" campaign has been active since at least March 2025 and has targeted organizations across multiple sectors with custom tooling.
Walmart co-locates red and blue teams to build trust and improve security through collaborative purple teaming exercises
Attackers continue to target critical infrastructure and government-linked organizations in the country, mirroring the increased activity across Latin America.
The big-box giant has scaled its defenses by encouraging trust and innovation. Good communications, transparency and team spirit are key factors.
Security experts say prioritization should be the main focus for the August updates, not the massive CVE volume.
The ransomware-as-a-service operation is finding success against critical infrastructure targets with leaked Conti code and old flaws in firewalls and VPN appliances.
New research shows how attackers can use security alerts and blocked events to manipulate and hijack AI agents.
Attacks targeting water systems just keep flowing across a dozen states, against ill-secured, Internet-exposed PLCs.
The maximum-severity vulnerability, which still has no CVE, allows malicious, remote administrator access to the business-analytics platform and its downstream users.
It's time to turn from CVSS-backed patching to choke-point patching focused on breaking chains to critical assets.
Sophisticated iPhone exploit chains previously limited to nation-states are spreading far and wide to organized cybercrime groups.
A public policy expert mapped global cybercrime laws to develop a five-point framework for protecting ethical hackers and good-faith security research.
The crime solver wore disguises, spied on targets, and built intelligence networks long before modern-day tactics emerged. He has lessons for today’s ethical- and nonethical-hat hackers.
A study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open to bypass.
The fight against cybercrime continues because threat actors have adapted their strategies to avoid deterrents, but law enforcement still operates in silos.
In the span of three weeks, OpenAI, Anthropic, and Meta have all disclosed AI agent sandbox escape events affecting real organizations.
A researcher demonstrated a proof-of-concept attack chain that provided C2-style influence over ChatGPT's isolated sandbox during a session at Black Hat USA 2026.
Former chief security officers of the Democratic National Committee explain that a strong security-first mindset requires executive support – and a dose of absurdity.
Attackers can take control of agents through malicious instructions hidden in content supplied to AI browsers, and there's no simple fix for the threat.
AI browsers from top vendors remain vulnerable to prompt injection attacks despite multiple security guardrails, according to new research.
CSS was once just about design. Now researchers warn it's powerful enough to exfiltrate data from webmail — and some vendors aren't prepared.
Researchers are calling attention to the risks inherent in automated network device provisioning, using a world-leading device manufacturer as a case study.
Google has fixed the issues, which exploited a trust boundary between two AI agents with different privilege levels to trigger automation that could compromise the supply chain.
Organized crime is convincingly scamming at scale, making billions thanks to AI-enabled voice cloning, deepfake real-time video overlays, LLM-driven persona management, and automated translation.
Unitel, Angola's dominant mobile operator, continues to recover from a cyberattack that caused outages the day of the government-owned telco's public offering.
The attacks use diverse social engineering lures and rotating payloads to deliver ScreenConnect for persistent remote access to compromised networks.
A Google Firebase misconfiguration lets users of tl;dv, an AI meeting tool, query any other users' meeting information and potentially join calls.
Newer social engineering techniques help attackers ignore entrenched security controls and limit the evidence they leave behind.