Cyber Security Badge

CyberNetSec.io

Daily Cybersecurity Threat Briefings

Threat Intelligence Publications

Daily collections of curated cybersecurity intelligence publications. You can search individual articles articles.

📅 Daily Collections

Published every day, each edition bundles all new and updated threat intelligence articles from the past 24 hours.

🔢 Deduplicated Coverage

Related stories are merged into a single evolving article rather than repeated as separate entries, cutting through the noise.

📊 Severity At a Glance

Each publication surfaces critical and high-severity counts upfront so you can triage the most urgent threats first.

🔗 Full Article Access

Every publication links directly to its enriched articles with MITRE mappings, IOCs, and actionable recommendations.

Filter by Month (Last 6 Months)

Zero-Days Exploit, Massive Data Breaches, and AI Theft Dominate Cybersecurity News

**Critical Vulnerabilities Under Active Exploitation**: * **[UPDATE] Clop Group Claims Massive Data Heist from Shell, Philips, GE via PTC Flaw**: The Clop group is reportedly using JSP web shells for persistence after exploiting CVE-2026-12569 in PTC Windchill and FlexPLM systems. Defenders should monitor for new JSP files in web directories, suspicious web server child processes, and web server logs indicating command execution. * **[UPDATE] Adobe Commerce Hit by 'StyleSmuggler' Zero-Day Exploited in the Wild**: CISA has added CVE-2026-75650, a zero-day affecting Adobe Commerce and Magento Open Source, to its Known Exploited Vulnerabilities catalog due to active exploitation. Federal agencies must remediate by September 22, 2026, highlighting the urgency for all organizations to patch. * **[NEW] Microsoft's Record September Patch Tuesday Fixes 974 Flaws, Two Zero-Days**: Microsoft's September update addresses 974 vulnerabilities, including two actively exploited zero-days (CVE-2026-81963 and CVE-2026-85880) that grant SYSTEM-level access. The release also contains fixes for numerous wormable remote code execution vulnerabilities. **New Threats and Advisories**: * **[NEW] US Agencies: China-Based Firms Stealing US AI Models at Scale**: A joint advisory from the NSA, CISA, and FBI accuses six China-based AI companies of stealing U.S. AI models through large-scale querying, potentially violating terms of service and involving government awareness. * **[NEW] LHC Group Discloses Health Data Breach Affecting Over 162,000**: LHC Group reported a data breach impacting 162,578 individuals due to a vishing attack that compromised employee credentials. The stolen credentials were used to access a third-party vendor's platform, leading to the exfiltration of sensitive patient data. * **[NEW] ShinyHunters Demands $55M After Stealing 200M+ Health Records**: The ShinyHunters group claims to have stolen over 200 million health records and is demanding a $55 million ransom. The attack involved vishing, Okta SSO compromise, and subsequent access to Salesforce and Snowflake cloud environments. * **[NEW] CISA Warns of Hard-Coded Credential in CareCam Pro IP Cameras**: CISA issued an ICS advisory for CVE-2026-85083, a hard-coded credential vulnerability in CareCam Pro IP cameras. This flaw could allow an attacker with physical access to gain privileged control of the camera's bootloader and firmware. * **[NEW] Cybercrime Group Uses YouTube Gaming Lures in Massive PPI Scheme**: A Unit 42 investigation identified a cybercrime operation using YouTube gaming lures and SEO poisoning to distribute a malware loader. This loader has been observed delivering various payloads, including new RATs and hijackers, to enterprise and government environments.

Sep 9, 2026
8 articles (6 new, 2 updated)
4 Critical 3 High
Cloud SecurityCyberattackData BreachIndustrial Control SystemsIoT Security +9 more
Zero-Days Exploit, Massive Data Breaches, and AI Theft Dominate Cybersecurity News
Daily Digest

Zero-Days Exploit RMM, E-commerce; Wall Street Targeted by AI Vishing

**Critical Vulnerabilities Under Active Exploitation**: * **N-able N-central Hit by Actively Exploited CVSS 10.0 RCE Flaw**: N-able is urging on-premises customers to immediately apply an emergency hotfix for its N-central RMM platform due to a critical, actively exploited zero-day vulnerability (CVE-2026-86218). This pre-authentication RCE allows unauthenticated attackers to gain full control of N-central servers, posing a significant supply chain risk. * **Unpatched 'StyleSmuggler' RCE Flaw Hits Magento & Adobe Commerce**: An unpatched, unauthenticated RCE zero-day vulnerability named 'StyleSmuggler' is being actively exploited to compromise e-commerce sites running Magento Open Source and Adobe Commerce. The attack leverages the GraphQL endpoint and template system to inject a backdoor, affecting all current versions. * **MikroTik Routers Hijacked via 'MikroTrick' Unauthenticated Exploit**: Attackers are actively exploiting an unauthenticated exploit chain called 'MikroTrick' to gain full administrative control of MikroTik routers with exposed SSH. This attack combines an SSH authentication bypass (CVE-2026-67276) and a privilege escalation flaw (CVE-2026-86060). **New Threats and Advisories**: * **[UPDATE] Wall Street Giants Targeted in Coordinated AI Vishing Campaign**: The vishing campaign, now tracked as PREY-0058, has evolved to include data exfiltration from Microsoft 365 services like SharePoint and OneDrive. Attackers are using residential proxies to evade detection and are using exfiltrated data for extortion. * **[NEW] Researcher 'Nightmare Eclipse' Drops Three LPE Zero-Day Exploits**: A security researcher known as 'Nightmare Eclipse' has publicly released proof-of-concept exploits for three unpatched local privilege escalation (LPE) zero-day vulnerabilities affecting CrowdStrike Falcon Sensor, Avast Antivirus, and Nvidia components. * **[NEW] North Korea's Lazarus Group Operations Decomposed into Six Clusters**: New research reveals that North Korea's state-sponsored cyber operations, attributed to the Lazarus Group, are organized into six distinct clusters. These specialized units focus on missions including espionage, financial theft, and sanctions evasion. **Policy & Industry Notes**: * **CISA Retires Six Free Cybersecurity Assessment Services**: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is retiring six of its free, hands-on cybersecurity assessment services for critical infrastructure operators, shifting organizations towards self-service tools.

Sep 7, 2026
7 articles (6 new, 1 updated)
3 Critical 3 High
CyberattackMalwarePatch ManagementPhishingPolicy and Compliance +6 more
Zero-Days Exploit RMM, E-commerce; Wall Street Targeted by AI Vishing
Daily Digest

Data Breaches at Healthcare, Government, and Retail; Phishing Evasion Technique Detailed

**Healthcare and Government Data Breaches**: * **Baylor Genetics Breach Exposes Medical Data of Over 2.8 Million**: An investigation concluded that the Baylor Genetics breach, initially reported to expose medical data, also included health insurance information, government ID numbers, and employee financial data for a subset of individuals. New cyber observables for hunting include specific command-line patterns and file paths used for data staging. * **Winona County, MN Paid Ransom Before Being Hit a Second Time**: Winona County, Minnesota, confirmed paying a $128,539 ransom after a January 2026 ransomware attack. Despite the payment, the county experienced a second, unrelated ransomware attack in April 2026, highlighting the persistent threat and questions surrounding ransom payment effectiveness. **Retail and Staffing Firm Breaches**: * **See's Candies Hit by Qilin Ransomware, Sparking Investigations**: Confectionery company See's Candies was targeted by the Qilin ransomware group in April 2026, involving file encryption and data exfiltration. Stolen data, potentially including customer and employee PII, has led to investigations into the company's data security practices, with scrutiny on the four-month delay in public disclosure. * **Staffing Firm HumanEdge Discloses Breach Exposing SSNs**: New York-based staffing firm HumanEdge, Inc. disclosed a breach detected in March 2026 that exposed sensitive personal information, including full names and Social Security numbers of employees, job applicants, and clients. The company began notifying affected individuals in September and is facing a class-action law firm investigation. **New Threat Tactics**: * **ASCII Smuggling Phishing Attack Evades Filters with Unicode**: Microsoft detailed a high-volume phishing campaign that utilized 'ASCII smuggling' by inserting invisible Unicode characters into financial keywords. This technique split words at a code level, allowing emails to bypass security filters relying on exact keyword matching while appearing normal to users, linked to an SBA loan-themed operation.

Sep 6, 2026
5 articles (4 new, 1 updated)
4 High
CyberattackData BreachIncident ResponsePhishingPolicy and Compliance +2 more
Data Breaches at Healthcare, Government, and Retail; Phishing Evasion Technique Detailed
Daily Digest

CISA Adds Exploited Flaws, Ransomware Hits Credit Union, Zero-Days Disclosed

**Critical Vulnerabilities Under Active Exploitation**: * **CISA Adds Seven Actively Exploited Flaws to KEV Catalog**: CISA has updated its Known Exploited Vulnerabilities (KEV) catalog with seven new flaws, some requiring patching by September 5 and others by September 16, 2026. The update includes detailed technical analysis of AI infrastructure vulnerabilities used to steal API keys and deploy crypto miners, along with new detection and mitigation strategies. * **Google Patches Actively Exploited Chrome V8 Zero-Day Flaw**: The Chrome V8 zero-day, CVE-2026-85046, has been added to CISA's KEV catalog, mandating federal agencies to patch by September 18, 2026. This vulnerability also impacts other Chromium-based browsers, requiring users to update their respective browsers. **New Threats and Advisories**: * **Ransomware Groups Target Healthcare, Finance, and Government**: The Akira ransomware group exfiltrated approximately 50GB of sensitive data from Gale Credit Union, including customer and employee personal information. The credit union is offering identity monitoring services to affected individuals. * **Broadcom Patches Critical VMware VM Escape Vulnerabilities**: Broadcom has released updates for VMware Workstation and Fusion to address two vulnerabilities, including a critical integer overflow flaw (CVE-2026-59346) that could allow code execution on the host system. Users are urged to update as no workarounds are available. * **LockBit 5.0 Ransomware Claims Attack on Dutch Firm KALA Health**: The LockBit 5.0 ransomware group has claimed responsibility for an attack on KALA Health, a Netherlands-based nutraceutical manufacturer. The group is threatening to release stolen data unless the company makes contact. * **Cisco Patches Three Critical Flaws in IOS XR Network Software**: Cisco has released patches for eight vulnerabilities in its IOS XR software, including three critical flaws (CVE-2026-20274, CVE-2026-20279, CVE-2026-20212) that could permit remote code execution or device reloads. While no active exploitation has been observed, immediate patching is recommended. * **Researcher Drops 'FalconFlank' Zero-Day for CrowdStrike Falcon**: A security researcher has publicly disclosed 'FalconFlank,' a zero-day exploit targeting the CrowdStrike Falcon endpoint security platform. This local privilege escalation exploit could allow a local attacker to gain SYSTEM-level privileges on fully updated Windows 11 and Windows Server systems.

Sep 5, 2026
7 articles (4 new, 3 updated)
4 Critical 3 High
Cloud SecurityCyberattackData BreachIndustrial Control SystemsPatch Management +5 more
CISA Adds Exploited Flaws, Ransomware Hits Credit Union, Zero-Days Disclosed
Daily Digest

AI Risks, Critical Infrastructure Attacks, and Zero-Days Dominate Cybersecurity News

**Critical Vulnerabilities Under Active Exploitation**: * **CISA Adds Seven Actively Exploited Flaws to KEV Catalog**: CISA has updated its Known Exploited Vulnerabilities (KEV) catalog with seven new flaws, notably including CVE-2026-82329 (JFrog Artifactory), CVE-2026-59822 (LiteLLM), and CVE-2026-48710 (Starlette), which directly impact AI/ML infrastructure. This highlights emerging risks such as supply chain attacks, data poisoning, and model theft targeting the MLOps pipeline. * **SonicWall Patches Two Actively Exploited SMA 1000 Zero-Days**: CISA has added CVE-2026-83548 and CVE-2026-83549 to its KEV catalog, mandating patches for Federal agencies by September 5, 2026, due to active exploitation. The Cyber Security Agency of Singapore also confirmed these vulnerabilities are being exploited, underscoring the urgent need for all affected SonicWall SMA 1000 users to update. * **Google Patches Actively Exploited Chrome V8 Zero-Day Flaw**: Google has released an emergency update for Chrome to address CVE-2026-85046, a high-severity zero-day vulnerability in the V8 JavaScript engine that allows for arbitrary code execution. Users are strongly advised to apply the patch immediately for Windows, macOS, and Linux. **New Threats and Advisories**: * **12-Year-Old "PostGREShell" Flaw Threatens PostgreSQL Servers**: A long-standing vulnerability, CVE-2026-6471 or "PostGREShell," affecting PostgreSQL versions since 9.4, allows users with 'Replication' privileges to execute arbitrary code and escalate privileges. Patches are available, and administrators should update systems and audit replication accounts. * **Settra Ransomware Claims Attack on Medical Firm MedEvolve**: The Settra ransomware group has claimed responsibility for an attack on MedEvolve, a medical billing company, alleging the theft of 820GB of internal documents. This incident underscores the ongoing targeting of the healthcare sector by ransomware operations. * **CISA Warns of High-Severity Flaw in Ignition ICS Platform**: CISA has issued an advisory for CVE-2026-77393, a high-severity vulnerability in Inductive Automation's Ignition ICS platform. An incorrect default permission setting allows authenticated users to create new projects, potentially leading to unauthorized modifications in industrial environments. Users should upgrade to version 8.1.54. **Critical Infrastructure and Industry Initiatives**: * **[UPDATE] CISA: Over 100 U.S. Water Systems Targeted in July Cyber Campaign**: Iranian state-sponsored actors have expanded their cyber operations beyond U.S. water systems to include telecommunications and energy providers. While recent attempts have not yet caused disruption, they indicate reconnaissance and intent for future disruptive attacks on critical infrastructure. * **OpenAI Commits $1B to Boost AI Defenses for Critical Infrastructure**: OpenAI has launched the "Daybreak for Frontline Defenders" program, a $1 billion initiative to provide under-resourced cybersecurity teams at critical infrastructure entities with advanced AI tools and training. A pilot program will focus on water utilities and other public sector entities.

Sep 4, 2026
8 articles (5 new, 3 updated)
4 Critical 3 High
CyberattackData BreachIndustrial Control SystemsPatch ManagementPolicy and Compliance +5 more
AI Risks, Critical Infrastructure Attacks, and Zero-Days Dominate Cybersecurity News
Daily Digest

Critical Exploits, Data Leaks, and AI-Driven Attacks Highlight Cybersecurity Landscape

**Critical Vulnerabilities Under Active Exploitation**: * **PaperCut Zero-Day RCE Actively Exploited (CVE-2026-81578, CVE-2026-82078)**: New reports indicate escalating exploitation of PaperCut NG/MF zero-day vulnerabilities. Attacks have progressed to 'hands-on-keyboard' intrusions, with compromised print servers used as beachheads for deeper network movement. Approximately 1,000 exposed PaperCut instances increase the potential attack surface, urging immediate patching and configuration review. * **SonicWall SMA1000 Zero-Days Added to CISA KEV Catalog (CVE-2026-83548, CVE-2026-83549)**: CISA has added two actively exploited SonicWall SMA1000 zero-day vulnerabilities to its Known Exploited Vulnerabilities catalog. This mandates immediate patching for federal agencies and strongly advises all other organizations to remediate due to the severe risk to network integrity. * **Google Patches Critical Use-After-Free Flaws in Chrome; Firefox Updates Address 29 Vulnerabilities**: Google has released updates for Chrome to address critical use-after-free flaws. Concurrently, Mozilla has released Firefox version 155, patching 29 security vulnerabilities, including 13 high-severity issues related to memory corruption and sandbox escapes, urging users to update promptly. **New Threats and Advisories**: * **FBI Investigates Massive Leak of 170M+ North American ID Scans**: The FBI is investigating a large data breach involving a dark web marketplace selling over 170 million digital identity document scans, primarily from the U.S. and Canada. The database, reportedly updated in real-time, poses a severe and continuous threat of identity theft and fraud. * **Ransomware Groups Target Healthcare, Finance, and Government**: Multiple ransomware groups, including Akira, Qilin, and Direwolf, are actively targeting organizations in the healthcare, finance, government, and manufacturing sectors. Attacks employ double extortion tactics, exfiltrating sensitive data before encryption and demanding ransoms. * **AI-Powered Cyberattacks Target Financial and Government Sectors in Latin America**: Researchers have identified two cyberattack campaigns leveraging commercial Large Language Models (LLMs) like Claude and GPT-4 for script generation and data exfiltration tasks. These campaigns target Mexican federal government and transportation entities, as well as the Brazilian financial sector, using job-themed phishing for initial access. **Policy & Industry Notes**: * **CISA to Finalize CIRCIA Cyber Incident Reporting Rule in Sept 2026**: CISA is expected to finalize its Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) rule in September 2026. This regulation will require covered entities to report substantial cyber incidents within 72 hours and ransomware payments within 24 hours, aiming to improve national threat visibility.

Sep 3, 2026
7 articles (4 new, 3 updated)
2 Critical 4 High
CyberattackData BreachMalwarePatch ManagementPolicy and Compliance +5 more
Critical Exploits, Data Leaks, and AI-Driven Attacks Highlight Cybersecurity Landscape
Daily Digest

Critical Exploits, AI Threats, and New EU Reporting Mandate Dominate Cybersecurity News

**Critical Vulnerabilities Under Active Exploitation**: - **SonicWall SMA1000 Zero-Days (CVE-2026-83548, CVE-2026-83549)**: SonicWall has released urgent patches for two zero-day vulnerabilities in its SMA 1000 series, a critical SSRF and a command injection flaw, which are being actively chained for unauthenticated remote code execution. This is the second such attack chain targeting the product line in seven weeks, indicating a persistent architectural weakness. - **Critical JFrog Artifactory Auth Bypass (CVE-2026-82329)**: JFrog Artifactory has a critical authentication bypass flaw with a CVSS score of 9.8, allowing unauthenticated attackers to forge admin tokens. Affected versions are 7.161.0 through 7.161.19, with remediation in 7.161.20 and newer. A mitigation involves configuring a unique join key if immediate patching is not feasible. - **Google Chrome 152 Patches Critical Bugs**: Google Chrome 152 has received an update (152.0.7977.75/.76) addressing 26 vulnerabilities, including two new critical use-after-free flaws (CVE-2026-84353, CVE-2026-84352) that could enable remote code execution via malicious websites. Users are advised to update immediately. **Emerging Threats and Evolving Tactics**: - **Ransomware Targets Healthcare Sector**: U.S. healthcare provider Nutex Health disclosed a significant data breach, with the 'The Gentlemen' ransomware gang claiming responsibility and threatening to publish stolen patient, employee, and business data. This incident highlights the growing threat of RaaS operations targeting healthcare with double-extortion tactics. - **Sophisticated OAuth Consent Phishing Campaign**: The FBI has warned of a sophisticated phishing campaign active since late 2025, using OAuth consent phishing to gain persistent, password-independent access to cloud accounts. Attackers impersonate officials or journalists to trick targets into granting malicious applications access to their Microsoft or Google accounts. - **AI-Driven Ransomware Attack**: Unit 42 detailed the first ransomware attack leveraging frontier AI models and autonomous agents, compressing weeks of intrusion activities into less than ten hours. The AI agents autonomously mapped networks, exfiltrated code, seized credentials, and compromised cloud AI infrastructure. - **AI Research Firm API Key Theft**: AI research firm METR experienced an API key theft incident where attackers tricked an AI agent, leading to the consumption of $600,000 in AI credits (provided for free). Attackers also established persistence via SSH keys, and a subsequent incident involved attackers using AI agents for automated vulnerability discovery, credential stuffing, and phishing. **Policy and Industry Insights**: - **EU Cyber Resilience Act Reporting Mandate**: The EU Cyber Resilience Act's 24-hour reporting obligation for products with digital elements, effective September 11, 2026, now explicitly applies to manufacturers, importers, and distributors of products already on the market, creating a retroactive compliance burden. The final reporting timeline for severe incidents is one month. - **Education Sector Faces Highest Cyberattack Intensity**: A SonicWall report indicates the education sector experienced the highest per-device attack intensity in the first half of 2026, with a single VoIP exploitation signature accounting for over half of all intrusion events. Open networks and unpatched systems contribute to its vulnerability.

Sep 2, 2026
9 articles (5 new, 4 updated)
2 Critical 6 High
Cloud SecurityCyberattackData BreachPatch ManagementPhishing +7 more
Critical Exploits, AI Threats, and New EU Reporting Mandate Dominate Cybersecurity News
Daily Digest

AI API Key Hijacking, Critical Exploits, and EU Reporting Mandate

**Critical Vulnerabilities Under Active Exploitation**: * **CVE-2026-82329 (JFrog Artifactory Auth Bypass)**: A critical authentication bypass vulnerability in self-hosted JFrog Artifactory instances is being actively exploited, allowing unauthenticated attackers to gain administrative privileges. Patches were released on August 28, 2026, and immediate updates are recommended. * **CVE-2026-0768 (Langflow AI RCE)**: A critical remote code execution vulnerability (CVSS 9.8) in the Langflow AI low-code platform is under active exploitation. Unauthenticated attackers can execute arbitrary code with root privileges, leading to reconnaissance and credential theft. Attacks have been observed originating from Russia. * **CVE-2026-78319 (SAUTER Building Controllers RCE)**: A critical remote code execution vulnerability (CVSS 9.8) affects SAUTER building automation controllers due to a TOCTOU race condition. This flaw could allow unauthenticated attackers to gain full control of devices managing essential building systems. Patches are available. **Threat Landscape Updates and Emerging Risks**: * **[UPDATE] Attackers Hijack AI API Keys**: AI safety non-profit METR disclosed two security incidents demonstrating 'token jacking' threats. A March 2026 incident resulted in approximately $600,000 in fraudulent AI credit consumption, and a May 2026 campaign involved automated probing and credential stuffing. These incidents highlight the need for robust AI resource security. * **[UPDATE] AI Scripts Target Siemens PLCs**: Forescout's Vedere Labs demonstrated AI's ability to accelerate exploit development against industrial control systems, porting an RCE exploit between PLC models in under 8 hours. This research supports warnings about AI-driven threats to critical infrastructure, indicating increased attack speed and a lower barrier to entry for sophisticated OT exploits. * **[UPDATE] McKesson Breach and Ransom Demand**: The ShinyHunters group has issued a $55 million ransom demand to McKesson following a data breach. The attack targeted both Snowflake and Salesforce instances, impacting customer data across multiple business units and confirming a double-extortion tactic. * **Phishing Campaign Targets 9,000+ Orgs**: A large-scale phishing campaign has targeted over 9,000 organizations with debt-relief-themed emails. The campaign uses social engineering to lure victims into vishing calls, aiming to steal financial and personal information. **Policy and Industry Notes**: * **EU Cyber Resilience Act Reporting Mandate**: Manufacturers of connected products sold in the EU must comply with the Cyber Resilience Act's (CRA) new reporting obligations starting September 11, 2026. The rules mandate reporting actively exploited vulnerabilities and severe incidents to ENISA within 24 hours.

Sep 1, 2026
8 articles (5 new, 3 updated)
3 Critical 3 High
Cloud SecurityCyberattackData BreachIndustrial Control SystemsPatch Management +7 more
AI API Key Hijacking, Critical Exploits, and EU Reporting Mandate
Daily Digest

Ransomware, Data Breaches, and New APT Tactics Dominate Cybersecurity News

This daily summary highlights significant cybersecurity incidents and emerging threats. Updates on the Qilin ransomware attack on the ATF reveal new technical indicators, including specific commands for disabling recovery and clearing logs, and the `.agenda` file extension for encrypted data. McKesson disclosed a $55 million ransom demand from ShinyHunters following a vishing campaign that compromised Okta credentials, leading to the theft of sensitive employee, physician, and patient data from Salesforce and Snowflake. The Manchester Airports Group breach is now understood to involve potential phishing and valid account exploitation, with data exfiltration over C2 channels; new detection strategies include D3FEND URL Analysis and Database Activity Monitoring. Boston Scientific operations remain impacted by a global cyberattack, confirmed to be limited to on-premise systems, with no new malicious activity observed since August 25, 2026. The inability to perform remote activations for cardiac monitors poses a direct risk to patient care. In new threats, 19 malicious Chrome and Edge extensions under the 'Superior' campaign have been identified, designed to steal cryptocurrency wallet secrets and exchange credentials. The Silver Fox Group is distributing the ValleyRAT backdoor via signed adware ('QN Wallpaper'), primarily targeting China and India through DLL sideloading. An operational security failure by a Blind Eagle APT operator exposed their malware production pipeline, including research into crypters and infrastructure services. Finally, the 'Spring Ring' campaign has been observed abusing Microsoft Teams for voice phishing (vishing) attacks, aiming to deploy remote management tools or conduct NTLM relay attacks against domain controllers.

Aug 31, 2026
8 articles (4 new, 4 updated)
4 High
Cloud SecurityCyberattackData BreachIndustrial Control SystemsRansomware +2 more
Ransomware, Data Breaches, and New APT Tactics Dominate Cybersecurity News
Daily Digest
Showing 1 - 10 of 333 publications
1 / 34