A Microsoft whistleblower says that the Active Directory security flaw that led to the SolarWinds breach was ignored because, at the time, the company was preparing a major bid for the government's cloud computing business.
The 2022 ICS Cybersecurity Report sees the majority of organizations recognizing ICS threats as being very serious; 22% ranked them as "critical" and 41% ranked them as "high" priority, representing a slow but steady increase over the past several years.
A zero-day windows vulnerability HiveNightmare leads to local privilege escalation, exposing system files, registry, and SAM database to non-admin users.
A new joint alert from CISA and the FBI seeks to assist private sector software developers in removing XSS vulnerabilities from their products, with a basic overview of best practices aimed primarily at executives and business leaders.
Dark web forum posts indicate that low- or even no-skill threat actors have figured out how to manipulate ChatGPT instructions to get it to produce basic but viable malware.
Big Tech companies have been making billions of dollars from data monetization, it’s time for them to disclose to users how much their data is worth with the proposed DASHBOARD Act.
Official sources say that Chinese hackers combed Japan's military networks over an extended period between 2020 and 2021 in search of military plans, documentation of capabilities, and assessments of vulnerabilities.
Google not sending vital security updates to Android devices running operating system older than version 8 has put them at high risk of malware and other security flaws.
Victoria’s Secret suffered a security incident that forced the lingerie giant to shut down impacted IT systems to prevent the attack from spreading and safeguard data.
Spyware campaign stole sensitive user information through 111 fake Google Chrome extensions which gathered over 32 million downloads on the Chrome Web Store.










