Kimsuky’s New C2 Channel Is Microsoft’s Own VS Code Tunnels
Kimsuky's HTTPSpy rides Microsoft VS Code Tunnels as C2 while npm typosquats drain CI/CD secrets. Here's what to actually do about it.
Kimsuky's HTTPSpy rides Microsoft VS Code Tunnels as C2 while npm typosquats drain CI/CD secrets. Here's what to actually do about it.
Carnival lost 6M records to a stolen employee login while Oracle accelerates patches. The cybersecurity defense worth buying isn't on the CVE list.
The Gentlemen ransomware self-propagates without an operator while AI scaffolds the rest. Here's what your cybersecurity playbook needs to fix this quarter.
An unpatched Gogs RCE exposes a cybersecurity blind spot most teams ignore: self-hosted developer infrastructure. See where to start hardening today.
Cryptojacking now ships with a RAT, and this week's cybersecurity reports show three delivery channels feeding the same wallet. Here's what to change tonight.
Extortion crews dropped encryption and moved to silent data theft. Your cybersecurity stack still watches for the old playbook. Here's what to fix first.
Akira's intrusion artifacts sit in firewall and Windows logs most cybersecurity teams never join. See where the gap closes this quarter.
Silent Ransom Group is walking into law firms in person while Kali365 eats MFA online. Here's the cybersecurity playbook that actually closes both gaps.
LA Metro's "hacktivists" were Iranian operators. Phishers now hide behind Adobe Target. Stop trusting the wrapper around the attack. See what to do.
AI chatbots are now surfacing the same poisoned download links search engines do, and ScreenConnect cryptojacking proves it. Here's how to harden up.