Skip to main content

Topic

Perspectives

CVE-2024-3094: XZ Utils Backdoor Threatens Linux Systems

A look at the recently discovered backdoor hiding in the open source XZ Utils compression service.

How to Prepare for the EU’s AI Act: Start With Your Risk Level

The new EU AI Act, adopted in March, helps firms invest in responsible AI by noting which uses are prohibited, high-risk, or minimal to no risk.

CTI Roundup: Tycoon Phishing-as-a-Service and TheMoon Malware Update

Researchers discover a new version of the Tycoon 2FA AiTM kit, a phishing attack disguises keylogger as bank payment notice, and TheMoon malware targets ASUS routers.

CTI Roundup: Fake Google Sites Pages, Hackers Target Global Governments

Hackers spread malware through fake Google Sites pages, cybercriminals exploit APIs, and an APT campaign targets global government entities.

A photo of glasses of water in a diagonal row and seen from above.

Attacks on water systems by Iran-backed hackers and future threats from Chinese groups have prompted calls for better security. We offer tips and resources.

Two speech bubbles, one red, one turquoise, sit caged behind bars.

The U.S. House just passed a bill to (possibly) ban TikTok. As the Senate weighs in, here’s how business owners, boards, and other enterprise heads must respond.

CTI Roundup: Linux Servers Target of New Malware Campaign

New Linux malware campaign targets misconfigured servers, ransomware actors diversify their exfiltration tools, and Cado reveals its top cloud threat findings report for 2H23.

A closeup of a woman's eyes, open wide, watching something intensely, with a circular graph pattern over one eye.

We salute a handful of standouts from the silver screen – some we love, and some we love to hate – that illuminated hackers and their world in new, powerful, or cringey ways.

CTI Roundup: CVEs on the Rise, TimbreStealer Malware, and a New Phishing Report

Researchers predict a 25% rise in CVEs, TimbreStealer malware spreads through phishing, and Proofpoint releases its 2024 State of the Phish report.

A closeup photo of runners' hands gripping the ground at the starting line of a race.

GenAI adoption is moving fast, so enterprises must set good governance policies first. Here's what you need to know to keep your deployments secure.

A hand and its dark shadow loom over a laptop keyboard.

It’s easier than ever for employees to find their own quick IT solutions—which can exponentially expand an organization’s risk landscape. We highlight four critical steps to help ferret out shadow IT – and its newest iteration, “shadow AI” – to limit the threat.

CTI Roundup: Return of Bumblebee and PikaBot Malware, Spammers Hit AWS SNS

Bumblebee returns from hiatus, PikaBot reappears with optimized code, and threat actors distribute spam via AWS SNS.