DERUUA

Latest news about information security vulnerabilities, threats, incidents and events

information security incidents

Prevention of security vulnerabilities, threats, and incidents described below is wiser and cheaper than forensic investigations and mitigation of the consequences of a cyber-attack.

You can get evidence of this fact from the news below.

Use our services to find and mitigate your security vulnerabilities before the security threat agents find them.




Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation...
More details.

Posted on Fri, 02 Oct 2026 11:19:50 +0530


Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers

Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid...
More details.

Posted on Thu, 01 Oct 2026 22:25:57 +0530


ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories

This week, the useful words are boring ones: inspect, cache, compile, store, trust. Each sounds harmless. Each can become an attack path when a system does a little more than people expect. A model check can run code...
More details.

Posted on Thu, 01 Oct 2026 22:15:38 +0530


WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again...
More details.

Posted on Thu, 01 Oct 2026 20:07:35 +0530


How Financial Services Companies Can Modernize Their Software Supply Chain

Every security leader at a bank, insurer, or asset manager has had a version of this conversation: Security wants to eliminate a class of vulnerabilities. Engineering explains what it would take to upgrade the platform where they live...
More details.

Posted on Thu, 01 Oct 2026 17:15:00 +0530


OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates

OpenAI on Wednesday said it identified and disrupted a coordinated distillation campaign that was designed to illicitly extract protected reasoning from its artificial intelligence (AI) models. A "core cluster of the activity," going back to the first week of July, has been attributed to individuals associated with Moonshot AI, a Chinese AI company based in Beijing...
More details.

Posted on Thu, 01 Oct 2026 16:12:36 +0530


CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following reports of active exploitation...
More details.

Posted on Thu, 01 Oct 2026 16:03:16 +0530


Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version

Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cyber defenders through its Fairwind Program....
More details.

Posted on Thu, 01 Oct 2026 13:19:36 +0530


Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path

Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs...
More details.

Posted on Thu, 01 Oct 2026 11:24:41 +0530


Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft

Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security products, citing ongoing investigation findings from SlowMist...
More details.

Posted on Thu, 01 Oct 2026 10:51:10 +0530


MetaMask Security Incident Prompts Exit of Affected Ethereum Validators

MetaMask on Thursday said it's responding to what it described as an "ongoing security incident" impacting part of its infrastructure. "We are actively addressing and remediating the issue internally, in coordination with external partners and security advisors," the software cryptocurrency wallet maker said...
More details.

Posted on Thu, 01 Oct 2026 10:40:09 +0530


Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs

Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data...
More details.

Posted on Thu, 01 Oct 2026 10:05:34 +0530


Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team...
More details.

Posted on Wed, 30 Sep 2026 22:16:29 +0530


Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks

Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content...
More details.

Posted on Wed, 30 Sep 2026 22:02:59 +0530


Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager

Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an advisory on September 30. The flaw, CVE-2026-76504, could allow a remote attacker with no login access to use the Manager's API as the admin user...
More details.

Posted on Wed, 30 Sep 2026 20:54:54 +0530


Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures

Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware. Huntress, which observed the activity in late September 2026, said it marks the abuse of yet another feature in trusted artificial intelligence (AI) platforms...
More details.

Posted on Wed, 30 Sep 2026 20:30:15 +0530


Know Your Enemy: Browser-Based Attack Techniques in 2026

Given that the browser is where business apps are accessed and used, it makes sense that attacks are happening there too. Most breaches today begin in a browser session. Often, they never leave it, with the entire attack chain from initial access to exfiltration playing out in the browser...
More details.

Posted on Wed, 30 Sep 2026 17:28:00 +0530


AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub

AI coding agents asked to share screenshots of code changes for review have put internal company images in public GitHub repositories, security company Glow said. Its researchers found more than 13,000 internal images from developers at over 300 organizations, including customer billing records and screens of features not yet released...
More details.

Posted on Wed, 30 Sep 2026 17:00:00 +0530


US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access

ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure...
More details.

Posted on Wed, 30 Sep 2026 16:15:00 +0530


Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT

Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe. The activity,...
More details.

Posted on Wed, 30 Sep 2026 13:54:35 +0530


OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted

A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes. DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires...
More details.

Posted on Wed, 30 Sep 2026 13:39:28 +0530


Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9...
More details.

Posted on Wed, 30 Sep 2026 11:00:30 +0530


French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks

An attacker used stolen passwords of staff at France's tax administration to take tax data on hundreds of thousands of taxpayers and businesses in June and July. Neither the tax administration nor France's national cybersecurity agency saw the data leave...
More details.

Posted on Tue, 29 Sep 2026 23:17:01 +0530


New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses

A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT) engines present in web browsers, language runtimes, and the operating system kernel, across multiple CPU vendors...
More details.

Posted on Tue, 29 Sep 2026 22:50:17 +0530


Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor

Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft. The campaigns, aimed at people and organizations tied to Ukraine, have affected more than 100 organizations since January, mostly in the U...
More details.

Posted on Tue, 29 Sep 2026 22:50:08 +0530


Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown

Kiteworks on Monday said it worked with federal intelligence authorities over the weekend as it identified and addressed a critical security vulnerability during the scheduled precautionary shutdown. "During...
More details.

Posted on Tue, 29 Sep 2026 19:43:20 +0530


101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent

Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub. "The malicious packages abuse the 'Baileys'...
More details.

Posted on Tue, 29 Sep 2026 19:15:10 +0530


Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation

Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group. "It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters," the Politie Landelijke Opsporing en Interventies said in an X post Monday...
More details.

Posted on Tue, 29 Sep 2026 14:05:10 +0530


Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory...
More details.

Posted on Tue, 29 Sep 2026 11:38:25 +0530


OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions

OpenAI on Monday shelved plans to release GPT-6.1 Astra, a next-generation artificial intelligence (AI) model that was planned for an October launch, after it failed internal safety and alignment audits...
More details.

Posted on Tue, 29 Sep 2026 10:42:32 +0530


OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot

OpenAI said it has made the decision to pause training of its most powerful models after one of its agents during reinforcement learning (RL) training contacted an external chatbot by exploiting a loophole in its internet-access restrictions...
More details.

Posted on Tue, 29 Sep 2026 10:15:20 +0530


Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks

Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file...
More details.

Posted on Tue, 29 Sep 2026 00:48:01 +0530


Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has been seen in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors...
More details.

Posted on Tue, 29 Sep 2026 00:05:42 +0530


IAM for AI agents: A Practical Enterprise Framework

What is IAM for AI agents? AI agents authenticate, invoke tools, and act across enterprise systems with delegated authority. IAM for AI Agents is the identity-control architecture that governs those actors...
More details.

Posted on Mon, 28 Sep 2026 23:50:38 +0530


Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system...
More details.

Posted on Mon, 28 Sep 2026 23:12:18 +0530


RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026...
More details.

Posted on Mon, 28 Sep 2026 23:08:33 +0530


⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats

A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface...
More details.

Posted on Mon, 28 Sep 2026 19:30:53 +0530


Webinar: How to Govern AI Agents, Reduce Excessive Access, and Control Shadow AI

AI agents are moving into production faster than security teams can govern them. They are connecting to apps, handling data, calling APIs, and acting across business systems—often without the same controls applied to human users...
More details.

Posted on Mon, 28 Sep 2026 17:28:00 +0530


Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent...
More details.

Posted on Mon, 28 Sep 2026 17:16:00 +0530


JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources

The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals. Microsoft, which is tracking the activity under the name Storm-3168, has called it an evolution of the threat actor's tradecraft...
More details.

Posted on Mon, 28 Sep 2026 14:38:21 +0530


CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation...
More details.

Posted on Mon, 28 Sep 2026 12:51:49 +0530


Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

Two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that allow remote code execution have been exploited in the wild, Citrix confirmed on September 27. It released fixes for both, along with six other flaws...
More details.

Posted on Sun, 27 Sep 2026 13:17:57 +0530


Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users...
More details.

Posted on Sat, 26 Sep 2026 23:52:52 +0530


Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9...
More details.

Posted on Sat, 26 Sep 2026 17:16:40 +0530


Zero Trust for AI Agents Starts With Fixing Zero Visibility

The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how quickly organizations could stand up agents and...
More details.

Posted on Sat, 26 Sep 2026 16:00:00 +0530


Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link

Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site...
More details.

Posted on Sat, 26 Sep 2026 15:25:22 +0530


SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation...
More details.

Posted on Sat, 26 Sep 2026 14:19:53 +0530


Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack

Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack...
More details.

Posted on Sat, 26 Sep 2026 13:18:33 +0530


Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign...
More details.

Posted on Fri, 25 Sep 2026 20:14:41 +0530


PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method...
More details.

Posted on Fri, 25 Sep 2026 18:48:06 +0530


Student Loan Breach Exposes 2.5M Records

2.5 million people were affected, in a breach that could spell more trouble down the line.
More details.

Posted on Wed, 31 Aug 2022 12:57:48 +0000


Watering Hole Attacks Push ScanBox Keylogger

Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.
More details.

Posted on Tue, 30 Aug 2022 16:00:43 +0000


Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms

Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.
More details.

Posted on Mon, 29 Aug 2022 14:56:19 +0000


Ransomware Attacks are on the Rise

Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.
More details.

Posted on Fri, 26 Aug 2022 16:44:27 +0000


Cybercriminals Are Selling Access to Chinese Surveillance Cameras

Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed.
More details.

Posted on Thu, 25 Aug 2022 18:47:15 +0000


Twitter Whistleblower Complaint: The TL;DR Version

Twitter is blasted for security and privacy lapses by the company’s former head of security who alleges the social media giant’s actions amount to a national security risk.
More details.

Posted on Wed, 24 Aug 2022 14:17:04 +0000


Firewall Bug Under Active Attack Triggers CISA Warning

CISA is warning that Palo Alto Networks’ PAN-OS is under active attack and needs to be patched ASAP.
More details.

Posted on Tue, 23 Aug 2022 13:19:58 +0000


Fake Reservation Links Prey on Weary Travelers

Fake travel reservations are exacting more pain from the travel weary, already dealing with the misery of canceled flights and overbooked hotels.
More details.

Posted on Mon, 22 Aug 2022 13:59:06 +0000


iPhone Users Urged to Update to Patch 2 Zero-Days

Separate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack.
More details.

Posted on Fri, 19 Aug 2022 15:25:56 +0000


Google Patches Chrome’s Fifth Zero-Day of the Year

An insufficient validation input flaw, one of 11 patched in an update this week, could allow for arbitrary code execution and is under active attack.
More details.

Posted on Thu, 18 Aug 2022 14:31:38 +0000


World Password Day 2026: Passwords Still Matter (Whether We Like It or Not)

Passwords remain one of the most common ways attackers gain access. Despite years of awareness, weak credentials, reuse, and exposure continue to drive breaches.
More details.

Posted on Thu, 07 May 2026 14:34:00 +0000


The Mythos Discovery: What It Means for Vulnerability Disclosure

Earlier this month, Anthropic's Claude Mythos Preview AI model discovered 27-year-old bugs that survived decades of human review. The Cloud Security Alliance, SANS, and over 100 CISOs just published emergency guidance...
More details.

Posted on Thu, 23 Apr 2026 14:14:00 +0000


How to Prioritize Vulnerability Remediation (Without Losing Your Mind)

Running a vulnerability scan is easy. Treating every finding as urgent is not. This model helps teams prioritize real risk instead of chasing severity scores.
More details.

Posted on Tue, 10 Feb 2026 03:27:29 +0000


Don't Let Legacy Systems Write Your Headline

What came after a dramatic Louvre heist highlights the risks of leaving legacy technology untreated in your enterprise, and how to mitigate them before they make the news.
More details.

Posted on Tue, 11 Nov 2025 02:07:00 +0000


Venmo Privacy Settings 2026: Make All Payments Private in 60 Seconds

Step-by-step guide to changing your Venmo privacy settings, including how to make past transactions private and hide your public payment history. Updated for 2026.
More details.

Posted on Tue, 28 Oct 2025 14:03:00 +0000


June Is National Internet Safety Month: Where Did It Come From?

National Internet Safety Month was born in 2005 to raise awareness around growing online risks. Nearly 20 years later, its message is more relevant than ever. Here’s how it started—and why it still matters...
More details.

Posted on Thu, 12 Jun 2025 20:49:18 +0000


The 10-Minute Security Checkup Everyone Should Do This Weekend

Skip the cybersecurity overwhelm. This 10-minute weekend checklist covers the essential security tasks that actually matter—from software updates to MFA setup. No jargon, no scare tactics, just practical steps anyone can follow to lock down their digital life...
More details.

Posted on Sun, 01 Jun 2025 19:54:27 +0000


The Spy Who Applied to Code

Think fake job applicants are just awkward interviews and padded resumes? Think again. One North Korean operative nearly infiltrated a U.S. crypto firm by pretending to be a software engineer named “Steven Smith...
More details.

Posted on Mon, 05 May 2025 14:49:00 +0000


World Password Day

Passwords are still the leading cause of breaches, and most of us still treat them like an afterthought. This post breaks down where we’re going wrong, what’s finally getting better, and why passkeys might be our best shot at a password-free future...
More details.

Posted on Thu, 01 May 2025 15:10:56 +0000


10 Ways to Secure Your Laptop

Laptops are magnets for thieves, hackers, and nosy strangers on airplanes. This guide walks you through 10 smart ways to secure your laptop—physically, digitally, and privately—so your files stay safe, your data stays yours, and your webcam isn’t watching you back...
More details.

Posted on Mon, 28 Apr 2025 14:58:00 +0000


Quishing: Phishing Got a Glow-Up

Quishing is phishing’s slicker, sneakier cousin. It hides behind QR codes, shows up on flyers and parking meters, and tricks you into handing over your credentials, often before your coffee kicks in. Here’s how it works, who it’s targeting, and how to stop it...
More details.

Posted on Thu, 24 Apr 2025 14:46:00 +0000


Locking Down My Smart Thermostats Was a Nightmare (and What It Taught Me About IoT Security)

When I tried to lock down my smart thermostats, I discovered how hard it is to control what IoT devices connect to. Here’s what I learned—and why we need NetBOM.
More details.

Posted on Mon, 14 Apr 2025 14:13:00 +0000


Ransomware: Because Who Doesn’t Want to Be Held Hostage by Their Own Files?

Ransomware: Because Who Doesn’t Want to Be Held Hostage by Their Own Files? Ransomware is no longer just a hacker’s side hustle—it’s big business. In this post, we break down what ransomware is, how it works, who it targets (on purpose and by accident), and what you can do to stay safe...
More details.

Posted on Wed, 09 Apr 2025 14:03:00 +0000


A Note on Our Domain Update

Between The Hacks has updated its default domain name to betweenthehacks.com. Everything is still here, but a few links might need attention. Learn more about this update and let us know if you spot any issues...
More details.

Posted on Fri, 04 Apr 2025 14:46:00 +0000


Passkeys: The Beginning of the End for Passwords

Still using passwords? It might be time to move on. Passkeys are a simpler, more secure way to log in—no typing, no phishing, no stress. In this post, I break down how passkeys work, why they matter, and how you can start using them today...
More details.

Posted on Thu, 03 Apr 2025 14:41:00 +0000


I Finally Segmented My Network… by Cutting the Ethernet Cable!

After years of preaching network segmentation, I took it to the next level—by physically disconnecting everything. Scissors, copper mesh, and a rotating SSID script. What could go wrong?
More details.

Posted on Tue, 01 Apr 2025 14:36:55 +0000


Unlimited Access: Every Device on Your Network Can Talk to the Internet

Most home devices can access the entire internet—and often each other. Segmentation helps, but without visibility into what your devices are doing, you’re still exposed.
More details.

Posted on Sun, 30 Mar 2025 20:32:00 +0000


If Troy Hunt Can Fall for Phishing, So Can You

Even cybersecurity experts fall for phishing attacks. When Troy Hunt, creator of Have I Been Pwned, clicked a malicious link and entered his credentials, it was a wake-up call for all of us. In this post, we break down what happened, why today’s phishing is more convincing than ever, and what you can do to protect yourself...
More details.

Posted on Fri, 28 Mar 2025 17:34:13 +0000


AI Magic: My Blog, LinkedIn, and a 7-Minute Podcast!

So, here’s something that blew my mind: I decided to test Google’s NotebookLM AI tool. I casually uploaded the URLs for my LinkedIn page and my blog, not expecting much more than a basic summary. After...
More details.

Posted on Mon, 30 Sep 2024 17:01:00 +0000


A Birthday Party, a Cold War Cipher, and the RSA Stage

If you told me a year ago that I would meet a cold war hero at a birthday party, I wouldn’t have believed you. And I would be even more skeptical if you told me she would be an unintimidating, approachable music professor with an infectious smile...
More details.

Posted on Thu, 30 Jun 2022 00:39:31 +0000


Shocking 12 Recent Major Cyber Attacks 2026 That Are Reshaping Global Security

The year 2026 has already witnessed an alarming rise in cybercrime activity worldwide. From large-scale ransomware incidents to sophisticated nation-state espionage campaigns, the recent major cyber attacks 2026 highlight a rapidly evolving digital threat landscape...
More details.

Posted on Wed, 18 Feb 2026 20:28:47 +0000


Linux Security in 2026: Threat Landscape, Trending Attacks, and How to Harden Your Servers

Linux underpins cloud infrastructure, containers, edge devices, and supercomputers — and while it’s long been regarded as a secure platform, attackers are increasingly focusing on its ubiquitous presence...
More details.

Posted on Wed, 28 Jan 2026 05:24:13 +0000


Safeguarding the Backbone of the Global Economy: OT/ICS Security in the Oil and Gas Industry

The oil and gas industry is an essential pillar of the global economy, enabling energy production, transportation, and storage that fuel every aspect of modern life. At the core of these operations lie Operational Technology (OT) and Industrial Control Systems (ICS), critical systems responsible for monitoring and controlling key industrial processes...
More details.

Posted on Sun, 12 Jan 2025 09:37:30 +0000


Detailed Guide to SOAR and SIEM

What Is SOAR? SOAR stands for Security Orchestration, Automation, and Response. It’s a cybersecurity tool designed to simplify and enhance the efficiency of IT teams by automating responses to various security threats...
More details.

Posted on Sun, 12 Jan 2025 09:20:49 +0000


What is a cyberattack?

What is a cyberattack? Cyberattacks aim to damage or gain control or access to important documents and systems within a business or personal computer network. Cyberattacks are distributed by individuals or organizations for political, criminal, or personal intentions to destroy or gain access to classified information...
More details.

Posted on Wed, 30 Oct 2024 04:02:41 +0000


What is SIEM ?

Security information and event management, SIEM for short, is a solution that helps organizations detect, analyze, and respond to security threats before they harm business operations. SIEM, pronounced “sim,” combines both security information management (SIM) and security event management (SEM) into one security management system...
More details.

Posted on Tue, 29 Oct 2024 08:06:47 +0000


Cyber Security Operation Center Guidelines for best practices SOC Design

Cyber Security is become most needed services for all business and industries in 2024. Every business is concerned about Cyber Security. Security operations (SecOps) leaders face a multifaceted challenge:...
More details.

Posted on Tue, 30 Jan 2024 16:32:57 +0000


HOW TO BECOME CERTIFIED LEAD IMPLEMENTER – ISO 27001

ABOUT CERTIFIED LEAD IMPLEMENTER TRAINING AND EXAMINATION FOR INFORMATION SECURITY MANAGEMENT SYSTEM ISO / IEC 27001 Learn and get certified as a professional in implementation of ISO 27001 standard through our self-paced E-learning interactive course which comprises of 4 modules...
More details.

Posted on Thu, 26 Jan 2023 11:21:59 +0000


YouTube disrupted in Pakistan as former PM Imran Khan streams speech

NetBlocks metrics confirm the disruption of YouTube on multiple internet providers in Pakistan on Sunday 21 August 2022. The disruption comes as former Prime Minister Imran Khan makes a live broadcast to the public, despite a ban issued by the Pakistan Electronic Media Regulatory Authority (PEMRA)...
More details.

Posted on Mon, 22 Aug 2022 05:04:16 +0000


Recommendations for Parents about Cyber Bullying

Here are some dedicated tips for keeping younger children safe online. One of these training tips goes into the risks of young children on the Internet, covers cyber bullying and other risky Internet behavior...
More details.

Posted on Wed, 20 Oct 2021 06:36:27 +0000


Cybersecurity Professional Standards

Discover how unified cybersecurity professional standards and the UK Cyber Security Council are redefining trust, talent, and resilience in finance.
More details.

Posted on Tue, 29 Jul 2025 11:41:52 +0000


TLPT: Threat Led Penetration Testing Explained

Discover how TLPT (threat led penetration testing) helps organizations validate defenses against real-world cyber threats. Learn who needs threat led pentesting, what drives demand, and how it differs from red teaming and classic pentesting...
More details.

Posted on Fri, 20 Jun 2025 08:00:00 +0000


EUVD Vulnerability Database: Europe’s Answer to CVE Instability

The EUVD marks a strategic shift in vulnerability management, offering a transparent and sovereign alternative to the U.S.-centric CVE system—backed by EU law.
More details.

Posted on Wed, 14 May 2025 09:11:06 +0000


Cyber Incident Response Tips for Small Businesses

Learn how small businesses can build cyber incident response plans by adapting practical strategies from the UK’s “Cyber Incident Grab Bag.”
More details.

Posted on Sat, 03 May 2025 14:06:58 +0000


CVE Under Threat: What You Need to Know

MITRE’s CVE contract expired on April 16, putting global vulnerability tracking at risk. Learn what’s happening and how the security community is responding.
More details.

Posted on Wed, 16 Apr 2025 15:01:36 +0000


Unforgivable Software Vulnerabilities

Some software vulnerabilities are unforgivable—easy to find, easy to fix, and never should’ve existed. Here’s how to spot and prevent them.
More details.

Posted on Fri, 04 Apr 2025 14:27:14 +0000


Preventing Crypto Exchange Hacks: Lessons from Bybit Heist

Bybit lost $1.4B in a North Korean hack via malware, fake UI, and blind signing. Learn key security strategies to protect exchanges from cyber threats!
More details.

Posted on Wed, 26 Feb 2025 09:27:46 +0000


Cyber Defense Using Cyber Kill Chain and MITRE ATT&CK Explained

Learn how the Cyber Kill Chain and MITRE ATT&CK Framework enhance security by identifying, detecting, and responding to cyber threats effectively.
More details.

Posted on Thu, 06 Feb 2025 13:41:48 +0000


The Future of Authentication: Passkeys vs Passwords and 2FA

Passkeys replace passwords with secure, easy logins using biometrics and cryptography, eliminating phishing, breaches, and 2FA issues.
More details.

Posted on Wed, 22 Jan 2025 09:22:47 +0000


Lessons from 2024’s Worst Cyberattacks and How to Stay Secure

Analyzing 2024’s biggest cyberattacks: breaches, vulnerabilities exploited, and actionable steps to strengthen defenses for 2025.
More details.

Posted on Mon, 13 Jan 2025 21:47:29 +0000



What we do and what we offer.

About penetration tests and about our news.


Our certificates:

(ISC)2
CISSP
Offensive Security
OSCP
ISACA
CISA
CISM
Microsoft
PECB
LPTP
Qualys
PECB
LPTP
BSI
LPTP
BSI

Наши партнёры, ИБ и ИТ компании Киев, Украина, мир:

Qualys
IBM
Tenable
Microsoft
AWS
ENX
Ernst&Young
KPMG
PriceWater­HouseCoopers
Deloitte
Buro Veritas
Underdefense
Hacken
Infosafe
10Guards
RMRF
Softseq
AAA auditagency
Berezha Security
Protectmaster
IT спеціаліст