Aggregator
China-Linked Hackers Hit US Tech Firms with BRICKSTORM Malware
俄罗斯卫星带着 75 只老鼠 1500 只果蝇返回地面
QR-код стал трояном, а не ссылкой. Пиксели начали скрывать кражу паролей и обходить защиту NPM-экосистемы
攻防速写|我们在7个厂商的8款手机上恢复了锁屏密码
美国战争部宣布实施新的“网络安全风险管理框架”
疑遭网络攻击,香港数百家便利店支付及会员服务瘫痪
漏洞挖掘-逻辑漏洞挖掘中的一些新思路
Space Bears
You must login to view this content
网络安全信息与动态周报2025年第38期(9月15日-9月21日)
【漏洞通告】Spring Cloud Gateway SpEL表达式注入漏洞(CVE-2025-41243)
Link11 brings on board Marc Lamik as Chief Product Officer (CPO)
Link11, a specialized European IT security provider, is expanding its management team: Marc Lamik is taking on the role of Chief Product Officer (CPO) and the responsibility of the company’s product strategy and development. With his international experience, he will be tasked with future-proofing product development and strategy and driving innovation for AI-based next-generation DDoS […]
The post Link11 brings on board Marc Lamik as Chief Product Officer (CPO) appeared first on Link11.
У вас OnePlus? Поздравляем, хакеры могут свободно читать ваши SMS
Мамонт, который не вымер. Почему самая популярная схема мошенничества в России так и не прижилась в Беларуси?
Career Spotlight: White Hat Hackers in an Automated World
Automated pentesting tools offer faster visibility and robust integration with daily security operations, but automation doesn't eliminate the need for humans in the loop. Automation raises the baseline for vulnerability management and changes what white hat hackers need to know to stay relevant.
Vendors Veradigm and ApolloMD Report Health Data Hacks
Vendor security risk has long been a source of pain for many healthcare providers. Veradigm - formerly Allscripts - and ApolloMD are among the latest software and services vendors reporting hacking incidents potentially triggering headaches for customers and their patients.
Mandiant: Chinese Espionage Tool Embedded in US Systems
Mandiant said it has tracked a Chinese-linked espionage campaign using BRICKSTORM malware to quietly embed within U.S. infrastructure and service providers for over a year, exploiting appliance-level blind spots to maintain persistence, evade detection and potentially develop zero-day exploits.
Unmasking the Insider Seller: Dark Web Attribution
Nisos
Unmasking the Insider Seller: Dark Web Attribution
Most insider threat teams know what to watch for inside the network: unusual access requests, suspicious file movement, or behavior changes that trip internal tools...
The post Unmasking the Insider Seller: Dark Web Attribution appeared first on Nisos by Nisos
The post Unmasking the Insider Seller: Dark Web Attribution appeared first on Security Boulevard.
North Korean IT workers use fake profiles to steal crypto
ESET Research has published new findings on DeceptiveDevelopment, also called Contagious Interview. This North Korea-aligned group has become more active in recent years and focuses on stealing cryptocurrency. It targets freelance developers working on Windows, Linux, and macOS systems. A growing threat to developers The group’s campaigns use social engineering tricks, including fake job interviews and a method known as ClickFix, to spread malware and steal cryptocurrency. ESET also reviewed open-source intelligence data about North … More →
The post North Korean IT workers use fake profiles to steal crypto appeared first on Help Net Security.