Researchers found Aurora ransomware affiliates using the Cursor AI coding assistant to plan and run intrusions against at least ten organisations, exploiting the same Active Directory weaknesses pen testers have …
incident response
-
-
Most security budgets still assume the job is keeping attackers out. Lateral movement is why that assumption fails, and what actually stops a breach from spreading.
-
A practical guide to running a business impact assessment: NIST’s three-step process, setting real recovery targets, and turning the results into action.
-
N-able’s patch for its N-central platform didn’t fully close the door attackers used. Here is the step-by-step check for anyone running it, beyond just installing the update.
-
Cl0p-linked attackers are exploiting an unauthenticated flaw in PTC Windchill and FlexPLM. Here’s a practical checklist for finding out if you’re exposed.
-
Origin Energy confirmed a data breach affecting millions of customer records, but the company learned of it from a reporter’s call, not its own monitoring. Here’s what that gap means …
-
Hugging Face was breached by an autonomous AI agent that logged 17,000 actions in a weekend. Here’s the practical checklist any business can run against the same weaknesses.
-
A contractor exposing CISA’s credentials on GitHub is the easy story. The nine ignored security alerts that followed reveal the failure worth fixing.
-
An exposed criminal server reveals exactly which plugin flaws powered a mass WordPress webshell attack. Use this checklist to check your own sites now.
-
A US county paid roughly $1 million to a group that never encrypted a single file, exposing how far data-theft extortion has moved beyond classic ransomware.