Talos has exposed UAT-10608, a major automated credential-harvesting campaign operated via the NEXUS Listener modular framework. Unlike targeted phishing tactics, this operation relentlessly targets a […]
Category: 128
128: CareCloud Confirms Data Breach Affecting Sensitive Patient Information
CareCloud, a major healthcare technology provider, has disclosed a significant cyberattack resulting in the breach of sensitive patient data, including names, addresses, Social Security numbers, […]
128: F5 BIG-IP Vulnerability Escalates: Immediate Patch Required as RCE Risk Emerges
F5 Networks has escalated a previously known BIG-IP Access Policy Manager (APM) flaw from a denial-of-service (DoS) to a remote code execution (RCE) vulnerability. Attackers […]
128: How Microsoft Defender’s Enhanced Security Exposure Management Protects High-Value Assets
Microsoft has enhanced Defender with new Security Exposure Management features, specifically targeting protection for critical infrastructure assets like domain controllers and web servers. This update […]
128: Widespread Vulnerabilities Highlight Need for Patch Management and Supplier Transparency
Cisco Talos has disclosed 30 new vulnerabilities affecting major brands, including TP-Link (10 flaws), Canva (19), and Hikvision (1). All vendors acted promptly to issue […]
128: Who Governs the Machines? Microsoft’s Guidance on AI Agent Authority in the Enterprise
Microsoft’s latest guidance addresses the governance of AI agents in enterprise, highlighting the need for clear authority as these systems act autonomously. Decisions involve user […]
128: PyPI LiteLLM Supply Chain Attack Highlights Open-Source Security Risks
The widely used open-source LiteLLM Python package on PyPI has been compromised by the TeamPCP hacking group, resulting in leaked data from hundreds of thousands […]
128: Microsoft Issues Guidance on Governing AI Agent Behaviour in the Enterprise
Artificial intelligence agents are rapidly entering mainstream business operations, raising key governance questions. Microsoft has issued updated guidance for enterprises on managing AI behaviour, emphasising […]
128: Tycoon2FA Phishing Platform Rapidly Resurrects After Global Takedown
Tycoon2FA, a major phishing-as-a-service platform, has swiftly resurfaced following a coordinated takedown led by Microsoft and Europol, which disrupted 330 domains. This resurgence highlights the […]
128: AWS Bahrain Outage: How Geopolitical Events Can Disrupt Cloud Services
AWS recently suffered a significant outage in its Bahrain region, triggered by airspace closures linked to Middle East conflict. While AWS attributed the incident to […]

