CATEGORIES
Media
DATE
Month
TAGS
- News & Updates
OpenAI disclosed this week what it called an unprecedented cyber incident. An autonomous agent, built on the newly released GPT 5.6 Sol and an unreleased more capable model, broke out of a controlled...
- News & Updates
Security researchers have identified a rapidly expanding distributed denial of service (DDoS) botnet dubbed Dysphoria, which has compromised more than 200,000 internet connected devices worldwide....
- News & Updates
Microsoft's July 2026 Patch Tuesday release, published on July 14, set a new record for the largest security update in the company's history, addressing over 600 vulnerabilities across Windows,...
- News & Updates
Global professional services firm Ernst & Young (EY) disclosed a cybersecurity incident after attackers compromised a third party IT support platform used by the company, potentially exposing...
- News & Updates
Microsoft released its July 2026 Patch Tuesday security updates, marking the largest vulnerability remediation effort in the company's history. The release addresses 570 vulnerabilities across...
- News & Updates
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that threat actors are actively exploiting CVE-2026-45659, a high severity remote code execution vulnerability affecting on...
- Technology & Solutions
Security researchers disclosed what is believed to be the first documented ransomware operation conducted almost entirely by an autonomous AI agent, tracked as JADEPUFFER. According to the...
- News & Updates
Researchers have uncovered new cyber espionage campaigns conducted by the China-aligned threat group Mustang Panda, targeting Indian government agencies and the hydropower sector. The attackers...
- News & Updates
Researchers have confirmed active exploitation of CVE-2026-46817, a critical vulnerability affecting Oracle E-Business Suite's Oracle Payments File Transmission component. The flaw carries a CVSS...
- News & Updates
Researchers have released new details on the exploitation of CVE-2026-20245, a high-severity vulnerability affecting Cisco Catalyst SD-WAN Manager that was actively exploited as a zero-day at least...
- News & Updates
Microsoft confirmed it is developing a security update for a newly disclosed zero-day vulnerability affecting Microsoft Defender, tracked as CVE-2026-50656 and publicly referred to as "RoguePlanet."...
- News & Updates
Security researchers have identified a large-scale credential harvesting campaign dubbed "FortiBleed," which exposed authentication data associated with approximately 73,900 Fortinet and FortiGate...
- News & Updates
Microsoft's June 2026 Patch Tuesday release set a new record as the largest security update inthe company's history, with fixes for approximately 200 vulnerabilities across Windows,...
- News & Updates
In recent weeks, supply chain attacks have become a growing concern, with multiple major repositories suffering from fake updates pushed by malicious actors to spread malware. In particular, recent...
- News & Updates
A recently disclosed security incident exposed significant weaknesses in AI-driven account recovery systems after attackers manipulated an automated support assistant to seize control of Instagram...
- News & Updates
The cybercriminal ecosystem is undergoing a strategic transition away from conventional ransomware operations toward pure extortion campaigns centered on data theft and disclosure threats. Rather...
- News & Updates
Many claims have been made about the effectiveness of Anthropic’s Mythos AI model in the cybersecurity sector both by Anthropic itself and by third parties. Its ability to identify vulnerabilities in...
- Technology & Solutions
A new discovery from the Google Threat Intelligence Group (GTIG) has confirmed a fear that many in the cybersecurity world have been concerned about since the rise of effective LLM-based AI coding...
- News & Updates
While bug bounties remain an essential component of cybersecurity for large software-driven enterprises like Google, shifts in the nature of security research have greatly reshaped the way bug...
- News & Updates
In these days of technologically advanced and network-connected transportation devices, it has become increasingly common for vulnerabilities to exist in the systems of cars that can pose a security...
- News & Updates
In recent weeks, there has been much concern over the impact of Anthropic’s latest AI model, Claude Mythos, and its ability to rapidly uncover previously unidentified vulnerabilities in code...
- News & Updates
U.S. critical infrastructure operators are facing an active and ongoing cyber threat campaign attributed to Iranian state-aligned actors. Recent investigations indicate that thousands of...
- News & Updates
A new wave of cyberattacks has recently been detected by investigators exploiting existing infrastructure to deliver malicious content. This is not an unknown phenomenon, of course, but the new...
- Technology & Solutions
Leak Bazaar is an emerging cybercriminal platform that represents a significant evolution in how stolen corporate data is monetized. First advertised in March 2026 on a Russian-speaking cybercrime...
- Industry & insights
There has been growing pressure in both the public and private sectors to adopt AI-based tools in workflows, and the Security Operations Center (SOC) has been no exception. Enterprise security teams...
- News & Updates
The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) has imposed anctions on Matrix LLC (also known as Operation Zero), its owner Sergey Sergeyevich Zelenyuk, and several associated...
- Industry & insights
Threat actors are already using AI to accelerate malware development, generate phishing content, automate scripting, and assist decision-making during intrusions. Researchers from Check Point...
- Business & Strategy
The United States Cybersecurity and Infrastructure Security Agency (CISA) has issued Binding Operational Directive (BOD) 26-02, titled Mitigating Risk From End-of-Support Edge Devices, to address...
- Technology & Solutions
Despite all the new forms of cyberattack, all the complex vulnerabilities, and all the elaborate social engineering techniques leveraged by threat actors, the perennial bugbear of the security...
- Education & Resources
Over the past decade, online fraud has undergone multiple significant structural transformations. What originally began as the acts of individual criminals has evolved into a large, industrialized...
- Industry & insights
Experts studying the recent military operation in Venezuela resulting in the capture of President Nicolas Maduro have concluded that cyberattack operations may have been an important part of the...
- News & Updates
On December 27–28, 2025, Ubisoft’s popular online shooter TomClancy’s Rainbow Six Siege experienced a major security breach that disrupted game operations and exposed serious vulnerabilities in its...
- Technology & Solutions
Since its disclosure earlier this month, CVE-2025-55182, a vulnerability in React Server Components now commonly referred to as React2Shell, has become an extremely common attack vector. Multiple...
- Industry & insights
A recent blog post published by the UK’s National Cyber Security Centre (NCSC) has exhibited a more profound skepticism about AI security than many security researchers have publicly given credence...
- News & Updates
For many people in the professional world, digital calendars are an essential time-management tool. In many cases, to properly synchronize, multiple people or organizations will share an external...
- News & Updates
Multiple malicious actors are actively using commercial spyware and remote access trojans (RATs) to target users of secure mobile messaging apps, most notably Signal and WhatsApp. Rather than...
- Business & Strategy
With each passing year, cyber threat actors become more sophisticated, more innovative in their attack techniques, and more determined to obtain their ill-gotten gains regardless of law enforcement....
- Industry & insights
Cloud security provider Zscaler has published its annual Mobile, IoT, and OT threat report, compiling findings from a year of monitoring these peripheral devices. Each year, mobile devices grow to...
- News & Updates
It is well known by now that cybercrime can have real world consequences leading to financial losses, but those losses usually come in the form of stolen data rather than more concrete theft....
- Industry & insights
Video games may seem of small importance to the business world at large, but the industry is growing and it can have an outsize effect on business affairs, particularly when it comes to security. The...
- Culture & Commentary
OpenAI has now disrupted and reported over 40 networks that violated usage policies ranging from covert influence operations to scams and malicious cyber activity and provided a set of case studies...
- Education & Resources
New discoveries from network defenders have once again highlighted the ways in which everyday AI agents can be leveraged by threat actors to not just become attack targets, but active threat...
- Education & Resources
2025 has been one of the worst years to be a cryptocurrency investor as far as security is concerned. The first half of 2025 saw more than 3 billion USD worth of crypto assets appropriated by threat...
- Culture & Commentary
Scattered Spider, one of the most notorious ransomware groups of the present era, surprised the cybercrime community this week with the announcement that it was shutting down its operations. In an...
- News & Updates
AI agents have been a frequent subject of discussion on these pages. Many users are delighted at the prospect of an AI assistant to automate work for them, heedless of the potential security dangers....
- Education & Resources
A novel ransomware prototype called PromptLock, first reported publicly in late August 2025 can be described as the first known AI-powered ransomware, although the strain is a proof-of-concept rather...
- Industry & insights
In the last year, cybersecurity researchers have called significant attention to the cyberespionage group tracked as Silk Typhoon, also known as Murky Panda and as HAFNIUM. The group has achieved...
- News & Updates
One of the key tools that helps users distinguish between genuine messages and phishing attacks, especially through email, is the ability to distinguish between real government accounts and malicious...
- Education & Resources
For better or worse, Agentic AI systems, meaning programs that utilize large language models to interpret natural language instructions and perform automated tasks, have steadily increased their...
- Business & Strategy
Open-source software is the backbone of the digital ecosystem. Benevolent programmers who develop valuable tools and then share those tools with others are some of the most valuable contributors to...
- News & Updates
Tools based on large language models, colloquially termed AI, have become an important part of the workflow of many individuals and enterprises in the tech sector. One such area where enthusiasts...
- Industry & insights
Firmware is the foundation of nearly all activity performed on computers, whether locally or over the cloud. If the firmware computers use presents security flaws, then any security precautions taken...
- News & Updates
Google Gemini for Workspace is an automation tool that allows Google's Gemini LLM to interact directly with various workplace tasks, including user inboxes. Because Gemini is a Google product being...
- Industry & insights
The ClickFix attack tactic represents something of an anomaly among social engineering methods. To some extent or another, all social engineering tactics depend on user ignorance, but perhaps none...
- Education & Resources
It is a truism among security personnel that the weakest link in any cybersecurity strategy is always the human element. However, a report from browser cybersecurity firm SquareX has put forward the...
- News & Updates
This past week, tensions between the United States and Iran have escalated into full scale conflict as the United States and Israel conducted air strikes against Iran's nuclear testing facilities. As...
- Education & Resources
At Blackwired, we have repeatedly stressed the dangers faced by network edge devices, including routers, firewalls, VPN gateways, IoT devices, internet-facing servers, and industrial operational...
- News & Updates
In cybersecurity, we tend to classify threat actors along strict boundaries. One such boundary is that between politically motivated hacktivists and financially motivated cybercriminals. In...
- Education & Resources
Investigators studying common internet browsers looking for security flaws have uncovered a new potential weapon in the arsenal of phishing-based threat actors that is especially dangerous because it...
- Technology & Solutions
Passwords are the first line of defense against threat actors, and as the years have passed, it has become increasingly clear that they are a rather shoddy and failure-prone line of defense. Although...
- Education & Resources
Hackers often look for new ways to deliver their attacks, especially in the sector of phishing. Most conventional phishing pages are hosted on a server with an IP address somewhere, and once the...
- News & Updates
AI agents are growing increasingly effective at operating within public digital space, and perhaps no one example demonstrates this as well as the Claude chatbot, created by the company Anthropic....
- Industry & insights
The ransomware industry is currently in a state of severe flux. As law enforcement has taken a more proactive role in shutting ransomware operations down and security personnel have improved their...
- Education & Resources
Since 2022, prompt injection, a vulnerability where malicious instructions override AI system behavior, has plagued large language models (LLMs). No reliable solution existed until Google DeepMind...
- Technology & Solutions
A new evolution in the realm of phishing is taking the precision tactics of spear-phishing to new heights. Email-based phishing attacks generally have two major stumbling blocks that can reduce their...
- Business & Strategy
Secure Sockets Layer or (SSL) plays a critical role in configurations within organizational cybersecurity, these misconfigurations can amplify an external attack surface thus adding to an...
- News & Updates
Business Email Compromise (BEC) is one of the most common forms of cyberattack targeting the modern organization. At its most basic level, the technique is simply one of impersonation, attempting to...
- Technology & Solutions
Generative AI has provided great benefits to a number of industries, however, as we have discussed in previous commentaries, AI agents come with security risks. Threat actors can potentially induce...
- Industry & insights
Since its debut in January, the large language model (colloquially referred to as an AI) DeepSeek-R1 has been a sensation, providing the same utility as OpenAI's o1 model at a fraction of the cost in...
- Culture & Commentary
When the subject of online security on online marketplaces comes up, it usually focused on risk towards buyers. However, sellers in these marketplaces are equally vulnerable to fraud schemes, not...
- News & Updates
In recent months, hiring scams involving fake job interviews have been in the public eye. In such scams, threat actors induce the target to download malicious programs under the pretext of giving...
- News & Updates
Phishing has always been a multifaceted threat, but in the public perception, phishing is usually tied up with email. The process, as stereotyped, is clear: a fraudster sends an email with a bogus...
- News & Updates
The cybersecurity realm is known as a constantly evolving paradigm with a future so vast it can be hard to predict where it will go. One of the most common apparatuses that companies use to interact...
- Business & Strategy
DataProtection Day is a time where many reflect on the evolving role of artificialintelligence and data protection. Oftentimes AI is seen as a potential riskwhen it comes to privacy, however, it's...
- Education & Resources
Although now considered to be insufficient for reliable security, passwords have historically been of great importance. Even now, passwords are the foundation of the security strategies of many major...
- News & Updates
One of the most prolific ransomware-as-a-service (RaaS) groups of the past couple of years has renounced the ransomware label and says it will focus solely on data exfiltration and extortion going...
- Industry & insights
INTERPOL is calling on the global cybersecurity community to stop using the term "pig butchering" when it comes to online fraud, as this language "dehumanizes and shames victims of such frauds,...
- Culture & Commentary
There's something wrong with the way we think about threat actors. Speaking at the NCC Group's Security Summit in Cheltenham, England, this week, security experts took turns challenging the...
- Industry & insights
A growing number of CISOs are looking for their roles to be split up due to the mounting regulatory responsibilities of the position, according to new research from ISACA. The industry body's CISO...
- Business & Strategy
In 2024, organizations around the Middle East continued the arduous work of improving cyber resiliency while facing an increasingly hostile threat environment. Fueled by ongoing conflicts and...
- Education & Resources
Originally coined in 2010, the term zero trust has become a common phrase in security jargon, but the principle is much less commonly applied to its full meaning. Zero trust is more than a simple...
- Industry & insights
As we come into the new year, changes in technology and policy will affect how cybersecurity is handled. Security professionals and end users alike need to be aware of these coming changes, because...
- News & Updates
Clickjacking, also known as UI redressing, is a known social engineering technique. By tricking users into clicking on a seemingly innocuous UI element, such as a button, on an attacker-controlled...
- Technology & Solutions
CAPTCHA is an important anti-fraud tool that usually protects websites from bot-based attacks such as brute forces and password sprays. In this capacity, they are not only useful, but essential....
- Culture & Commentary
One of the growing trends in cybersecurity enforcement in the past few years is for Chief Information Security Officers to be held personally liable for cybersecurity incidents, and to face...
- Education & Resources
It is not an uncommon phenomenon for developers working for major enterprises to inadvertently expose their AWS access keys, and it is not uncommon for threat actors to discover this and take...
- Education & Resources
The holiday season is a boon time for e-commerce worldwide, with Black Friday and Cyber Monday driving sales on every major e-commerce platform, with further waves of traffic continuing up until the...
- News & Updates
IoT devices have become a known attack vector in recent years, largely due to the fact that they lack many of the security protections internet-facing devices are meant to have. However, even with...
- Technology & Solutions
Telecom network breaches have been big news for the past few weeks following the public disclosure of a high-profile breach of Verizon by threat actors alleged to be affiliated with China. The big...
- Education & Resources
In many ways, the job of the Chief Information Security Officer is divided between two radically different areas of expertise. On one hand, there are the daily technical responsibilities that go into...
- Industry & insights
Many security operations center (SOC) analysts struggle to do their jobs effectively, citing problems with the tools they use, alert fatigue, and the time they waste chasing after erroneous...
- Industry & insights
Whether it's a local clinical pharmacy, a hospital, or a health insurance company — all healthcare organizations are prime targets for cyber attacks. This is partly due to the sensitivity of the data...
- News & Updates
A research team has discovered that many satellite communications are not encrypted, potentially exposing sensitive data to interception. The findings highlight the need for improved security in the...
- News & Updates
The threat group known as Scattered Spider, which recently targeted retailers in the UK and US, had previously honed its skills attacking financial institutions and cryptocurrency exchanges.The group...
- Industry & insights
The password is the foundation on which all computer security rests. In the decades since its introduction, there have been many debates over how to form the best password, how often to change it,...
- Technology & Solutions
Today's subject will be a little bit different from the usual discussions of security flaws. This is a security flaw, to be sure, but it works along different angles. Generative AI is a current...
- Technology & Solutions
The increasing prevalence of generative AI in the tech community has given certain individuals in the security community hopes of cutting down on the need for professionals to work long, overnight...
- Technology & Solutions
In many enterprises, cybersecurity and fraud protection are operated as separate teams. Cybersecurity is generally focused on the protection of information systems, whereas fraud prevention is...
How 2 Missing Characters Nearly Compromised AWS