CISA, UK NCSC, FBI Unveil Principles to Combat Cyber Risks in OT

• CISA, UK NCSC, FBI Unveil Principles to Combat Cyber Risks in OT WASHINGTON - Today, the Cybersecurity and Infrastructure Security Agency (CISA), United Kingdom’s National Cyber

Cybersecurity · January 14, 2026 (updated February 24, 2026) · 2 min · 254 words

Patch Tuesday, January 2026 Edition

• Microsoft today issued patches to plug at least 113 security holes in its various Windows operating systems and supported software. • Eight of the vulnerabilities earned Microsof

Cybersecurity · January 14, 2026 (updated February 19, 2026) · 2 min · 283 words
Threat Brief: MongoDB Vulnerability (CVE-2025-14847)

Threat Brief: MongoDB Vulnerability (CVE-2025-14847)

• Executive Summary On Dec. • 19, 2025, MongoDB publicly disclosed MongoBleed, a security vulnerability (CVE-2025-14847) that allows unauthenticated attackers to leak sensitive hea

Cybersecurity · January 13, 2026 (updated February 24, 2026) · 2 min · 242 words
Remote Code Execution With Modern AI/ML Formats and Libraries

Remote Code Execution With Modern AI/ML Formats and Libraries

• Executive Summary We identified vulnerabilities in three open-source artificial intelligence/machine learning (AI/ML) Python libraries published by Apple, Salesforce and NVIDIA o

Cybersecurity · January 13, 2026 (updated February 24, 2026) · 2 min · 309 words

Who Benefited from the Aisuru and Kimwolf Botnets?

• Our first story of 2026 revealed how a destructive new botnet called Kimwolf has infected more than two million devices by mass-compromising a vast number of unofficial Android T

Cybersecurity · January 8, 2026 (updated February 24, 2026) · 2 min · 357 words

CISA Retires Ten Emergency Directives, Marking an Era in Federal Cybersecurity

• CISA Retires Ten Emergency Directives, Marking an Era in Federal Cybersecurity WASHINGTON - Today, the Cybersecurity and Infrastructure Security Agency (CISA) announced the succe

Cybersecurity · January 8, 2026 (updated February 24, 2026) · 2 min · 264 words
Securing Vibe Coding Tools: Scaling Productivity Without Scaling Risk

Securing Vibe Coding Tools: Scaling Productivity Without Scaling Risk

• Threat Research Center Insights General Securing Vibe Coding Tools: Scaling Productivity Without Scaling Risk By:Kate MiddaghMichael Spisak Kate Middagh Michael Spisak Published:

Cybersecurity · January 8, 2026 (updated February 24, 2026) · 2 min · 265 words

The Kimwolf Botnet is Stalking Your Local Network

• The story you are reading is a series of scoops nestled inside a far more urgent Internet-wide security advisory. • The vulnerability at issue has been exploited for months alrea

Cybersecurity · January 2, 2026 (updated February 24, 2026) · 2 min · 407 words

Happy 16th Birthday, KrebsOnSecurity.com!

• KrebsOnSecurity.com celebrates its 16th anniversary today! • A huge ’thank you’ to all of our readers - newcomers, long-timers and drive-by critics alike. • Your engagement this

Cybersecurity · December 29, 2025 (updated February 24, 2026) · 2 min · 352 words
The HoneyMyte APT evolves with a kernel-mode rootkit and a ToneShell backdoor

The HoneyMyte APT evolves with a kernel-mode rootkit and a ToneShell backdoor

• Overview of the attacks In mid-2025, we identified a malicious driver file on computer systems in Asia. • The driver file is signed with an old, stolen, or leaked digital certifi

Cybersecurity · December 29, 2025 (updated February 24, 2026) · 2 min · 278 words
Threat landscape for industrial automation systems in Q3 2025

Threat landscape for industrial automation systems in Q3 2025

• Table of Contents Statistics across all threats Selected industries Diversity of detected malicious objects Main threat sources Threat categories Malicious objects used for initi

Cybersecurity · December 25, 2025 (updated February 24, 2026) · 2 min · 337 words
Evasive Panda APT poisons DNS requests to deliver MgBot

Evasive Panda APT poisons DNS requests to deliver MgBot

• Introduction The Evasive Panda APT group (also known as Bronze Highland, Daggerfly, and StormBamboo) has been active since 2012, targeting multiple industries with sophisticated,

Cybersecurity · December 24, 2025 (updated February 24, 2026) · 2 min · 233 words
Assessing SIEM effectiveness

Assessing SIEM effectiveness

• A SIEM is a complex system offering broad and flexible threat detection capabilities. • Due to its complexity, its effectiveness heavily depends on how it is configured and what

Cybersecurity · December 23, 2025 (updated February 24, 2026) · 1 min · 199 words

Dismantling Defenses: Trump 2.0 Cyber Year in Review

• The Trump administration has pursued a staggering range of policy pivots this past year that threaten to weaken the nation’s ability and willingness to address a broad spectrum o

Cybersecurity · December 19, 2025 (updated February 24, 2026) · 3 min · 494 words

CISA Releases Dynamic New Guide for Stadium and Arena Owners to Fortify Operations, Mitigate Vulnerabilities and Elevate Emergency Preparedness

• CISA Releases Dynamic New Guide for Stadium and Arena Owners to Fortify Operations, Mitigate Vulnerabilities and Elevate Emergency Preparedness WASHINGTON - Today, the Cybersecur

Cybersecurity · December 17, 2025 (updated February 24, 2026) · 2 min · 295 words

Opening Doors to the Future: CISA Announces Participation in the CyberCorps® Scholarship for Service (SFS)

• Opening Doors to the Future: CISA Announces Participation in the CyberCorps® Scholarship for Service (SFS) WASHINGTON - Today, the Cybersecurity and Infrastructure Security Agenc

Cybersecurity · December 17, 2025 (updated February 24, 2026) · 2 min · 287 words

Most Parked Domains Now Serving Malicious Content

• Direct navigation - the act of visiting a website by manually typing a domain name in a web browser - has never been riskier: A new study finds the vast majority of ‘parked’ doma

Cybersecurity · December 16, 2025 (updated February 24, 2026) · 3 min · 543 words

Welcome to the new Project Zero Blog

• While on Project Zero, we aim for our research to be leading-edge, our blog design was ⦠not so much. • We welcome readers to our shiny new blog! • For the occasion, we asked me

Cybersecurity · December 16, 2025 (updated February 20, 2026) · 2 min · 252 words

Thinking Outside The Box [dusted off draft from 2017]

• Preface Hello from the future! • This is a blogpost I originally drafted in early 2017. • I wrote what I intended to be the first half of this post (about escaping from the VM to

Cybersecurity · December 16, 2025 (updated February 20, 2026) · 2 min · 306 words

Windows Exploitation Techniques: Winning Race Conditions with Path Lookups

• This post was originally written in 2016 for the Project Zero blog. • However, in the end it was published separately in the journal PoC||GTFO issue #13 as well as in the second

Cybersecurity · December 16, 2025 (updated February 20, 2026) · 2 min · 259 words

A look at an Android ITW DNG exploit

• Introduction Between July 2024 and February 2025, 6 suspicious image files were uploaded to VirusTotal. • Thanks to a lead from Meta, these samples came to the attention of Googl

Cybersecurity · December 12, 2025 (updated February 20, 2026) · 1 min · 207 words

Microsoft Patch Tuesday, December 2025 Edition

• Microsoft today pushed updates to fix at least 56 security flaws in its Windows operating systems and supported software. • This final Patch Tuesday of 2025 tackles one zero-day

Cybersecurity · December 9, 2025 (updated February 19, 2026) · 2 min · 241 words

Drones to Diplomas: How Russia's Largest Private University is Linked to a $25M Essay Mill

• A sprawling academic cheating network turbocharged by Google Ads that has generated nearly $25 million in revenue has curious ties to a Kremlin-connected oligarch whose Russian u

Cybersecurity · December 6, 2025 (updated February 24, 2026) · 2 min · 403 words

Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure

• Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure Actions for Operational Technology Owners and Operators to Take Today to Mitiga

Cybersecurity · December 5, 2025 (updated February 24, 2026) · 2 min · 273 words

SMS Phishers Pivot to Points, Taxes, Fake Retailers

• China-based phishing groups blamed for non-stop scam SMS messages about a supposed wayward package or unpaid toll fee are promoting a new offering, just in time for the holiday s

Cybersecurity · December 4, 2025 (updated February 24, 2026) · 2 min · 383 words

CISA Shares Lessons Learned from an Incident Response Engagement

• CISA Shares Lessons Learned from an Incident Response Engagement Advisory at a Glance Executive Summary | CISA began incident response efforts at a U.S. • federal civilian execut

Cybersecurity · September 22, 2025 (updated February 24, 2026) · 2 min · 285 words

Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System

• Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System Executive summary People’s Republic of China (PRC) state-sponsored cybe

Cybersecurity · August 25, 2025 (updated February 24, 2026) · 2 min · 260 words

CISA and USCG Identify Areas for Cyber Hygiene Improvement After Conducting Proactive Threat Hunt at US Critical Infrastructure Organization

• CISA and USCG Identify Areas for Cyber Hygiene Improvement After Conducting Proactive Threat Hunt at US Critical Infrastructure Organization Summary The Cybersecurity and Infrast

Cybersecurity · July 29, 2025 (updated February 24, 2026) · 1 min · 206 words

#StopRansomware: Interlock

• #StopRansomware: Interlock Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Interlock Ransomware Activity Prevent initial access by implementing domai

Cybersecurity · July 21, 2025 (updated February 24, 2026) · 2 min · 239 words

Ransomware Actors Exploit Unpatched SimpleHelp Remote Monitoring and Management to Compromise Utility Billing Software Provider

• Ransomware actors target unpatched SimpleHelp RMM to breach utility billing software provider customers. • Vulnerability CVE-2024-57727, a path traversal flaw, exploited in Simpl

Cybersecurity · June 12, 2025 (updated February 24, 2026) · 1 min · 160 words

Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations

• FBI & CISA issue joint advisory on LummaC2 infostealer targeting critical infrastructure. • Malware infiltrates networks, exfiltrates sensitive data via spearphishing links and a

Cybersecurity · May 20, 2025 (updated February 24, 2026) · 1 min · 150 words

Russian GRU Targeting Western Logistics Entities and Technology Companies

• Russian GRU’s 85th GTsSS unit 26165 targets Western logistics and tech firms. • Campaign focuses on coordination, transport, delivery of foreign aid to Ukraine. • Uses known TTPs

Cybersecurity · May 12, 2025 (updated February 24, 2026) · 1 min · 155 words

Fast Flux: A National Security Threat

• Fast flux hides malicious server locations by rapidly changing DNS records. • Enables cybercriminals and nation-state actors to evade detection and maintain C2. • Resilient, high

Cybersecurity · April 1, 2025 (updated February 24, 2026) · 1 min · 156 words

#StopRansomware: Medusa Ransomware

• Patch OS, software, firmware promptly to close known vulnerabilities across all systems. • Segment networks to limit lateral movement from infected devices and protect critical a

Cybersecurity · March 11, 2025 (updated February 24, 2026) · 1 min · 173 words