Defense Contractor Employee Sentenced for Selling Zero-Day Exploits

An Australian national has been sentenced for selling eight zero-day exploits to a Russian broker, impacting U.S. national security.

An Australian national has been sentenced for selling eight zero-day exploits to a Russian broker, impacting U.S. national security.

As organizations increasingly deploy Large Language Models (LLMs), the security risks associated with exposed endpoints are becoming more pronounced. This article examines how these vulnerabilities can be exploited and the importance of managing endpoint privileges.

This week’s cybersecurity landscape reveals significant vulnerabilities and incidents affecting various sectors, including a zero-day exploit in Dell RecoverPoint and the emergence of new malware targeting Android devices.

The U.S. Cybersecurity and Infrastructure Security Agency has added two significant vulnerabilities in Roundcube webmail software to its Known Exploited Vulnerabilities catalog, highlighting the urgency for remediation.

A financially motivated threat actor has compromised more than 600 FortiGate devices across 55 countries, leveraging AI tools to exploit weak security measures.

The Government Accountability Office has called on the National Science Foundation's CIO to improve technology procurement and management, emphasizing accountability and standardization.

A recent report from Dragos highlights the persistent threat posed by Chinese-backed groups like Volt Typhoon, which continue to compromise U.S. energy networks, alongside the emergence of new threat actors targeting critical infrastructure.

A critical security flaw in Dell RecoverPoint for Virtual Machines has been exploited by attackers linked to China since mid-2024, raising concerns about long-term network access.

A recent webinar highlighted the challenges of cloud forensics and the necessity of modern techniques to investigate breaches effectively.

A recent SmartLoader attack has been identified, leveraging a trojanized version of the Oura MCP server to deploy the StealC infostealer, targeting sensitive user data.