Zero Trust
The Build Pipeline Becomes the Attack Surface as an Unauthenticated Flaw Puts Every TeamCity Server at Risk
Cloud Security
One Signing Key Nearly Exposed Every Azure Cosmos DB Tenant, and Microsoft Needed Eight Months to Kill It
Threat Intelligence
Credential Rotation No Longer Evicts Attackers as Void Blizzard’s OWAReaper Persists Inside Exchange Mailboxes
Threat Intelligence
A Five-Year-Old Firmware Gap Turns Cold Storage Into the Attack Surface as Coinkite Confirms a Coldcard Entropy Flaw
Threat Intelligence
A Single Ad-Tech Script Becomes a Multi-Site Crypto-Theft Vector as Adform Confirms a Supply-Chain Compromise
Threat Intelligence
The Third-Party Cloud Becomes the Breach Point as Amgen Discloses Stolen Patient and Proprietary Data
Cloud Security
The Hypervisor Becomes the Perimeter as Broadcom Rushes Emergency Fixes for Three Critical VMware Flaws
Threat Intelligence
Amazon Ties a String of Popular npm Package Hijacks to a Single North Korean Crew
Threat Intelligence
A Critical Rails Flaw Turns Ordinary Image Uploads Into a Path to Full Server Compromise
Threat Intelligence
CISA Widens Its Iranian PLC Warning as Minnesota Water Utilities Lose Automated Control
Zero Trust
Cisco’s Firewall Management Center Joins the Exploited List Over a Hardcoded Password
Sponsored
When the Source Code Leaks: A Vendor Playbook from the Trellix Incident
This content was produced by the advertiser. It does not reflect the editorial opinions of the newsroom.