Microsoft Threat Intelligence has published a technical breakdown of DeadLock, an emerging financially motivated ransomware operation distinguished by its use of decentralized infrastructure for victim communications and data leak operations.DeadLock surfaced in July 2025 and runs a double-extortion playbook, encrypting victim systems while threatening to dump stolen data. By July…
Sting startup hired three suspected Pyongyang IT workers.
Split instructions sneak secrets past AI coding assistants.
Emulated USB gadgets turn Windows PnP into SYSTEM access.
China-linked crew drops StormEncryptor after N-central raids.
Poisoned JSON stream plants rogue admins in WordPress shops.
Kimsuky runs local AI models to sharpen phishing lures.
OpenAI's GPT-5.6-Cyber answers most risky security requests.
Private cellular link let attackers stop a Polish plant turbine.
US and South Korea warn of Gunra raids on critical sectors.
Anyone who verifies Firefox and Thunderbird downloads by hand now has extra homework: Mozilla has retired the GPG subkey behind its Linux releases after an unencrypted copy was accidentally committed to a private company repository.The affected subkey signed Linux tarballs, RPM packages, and checksum files for both products. That key is what lets a user, or a distro bundling the…
SIM card commands turn phones and EV chargers into pawns.
Surtr Defense, an RVII portfolio company, builds a hardware-agnostic operating system for counter-drone operations.
Didit, backed by Robinhood Ventures Fund II, builds identity verification and fraud infrastructure for the financial stack.
Silmaril Security, an RVII portfolio company, builds runtime security for self-improving AI systems that outpace signature-based defenses.
Robinhood Ventures Fund II lists Aug 13 on the NYSE as RVII with a security cohort spanning digital identity, AI runtime protection, and counter-drone defense.
OpenAI halted internal work on its upcoming Astra model after evaluations suggested it could reach the critical cyber capability threshold.
Kaspersky says the Head Mare group exploited a two-flaw chain in unpatched TrueConf servers to poison client installers with the PhantomCore RAT.
PortSwigger's HTTP Terminator generated and proved new HTTP desynchronization techniques and helped expose a patched Apache Traffic Server zero-day.
Tenet Security's Ghostjacking demo shows attackers planting instructions in logs that AI agents read and execute, targeting Cloudflare, Datadog, and…
The denim maker told the SEC that a social engineering attack hit three employee computers and led to exfiltration of…
A researcher found the Connective browser extension used by two million Belgians could be abused to read card data, steal…
IEH Corporation told the SEC that a phished employee's Microsoft 365 mailbox exposed engineering files and potentially export-controlled technical data.
A cyberattack forced all three North Carolina port facilities to delay gate openings and shift to manual processing, with the…
Sign in to your account