General cybersecurity industry news, market trends, and analysis
The latest M-Trends report is based on insights from over 500,000 hours of Mandiant incident response investigations in 2025.
The semiconductor company says hackers deployed file-encrypting ransomware on the network of a subsidiary in Singapore.
Hackers published a malicious scanner release and replaced tags to point to information-stealer malware.
Trivy backdoored, FBI buys location data, iOS DarkSword kit, WhatsApp usernames, Langflow RCE, Cisco FMC zero-day & critical CVEs to patch.
8 Bedrock attack vectors exploit permissions and integrations, enabling data theft, agent hijacking, and system compromise at scale.
The flaws could allow attackers to access sensitive information, execute code, or cause unexpected behavior.
Microsoft warns tax-season phishing hit 29,000 users via IRS lures, enabling credential theft and RMM-based access.
Attack volumes are back to pre-disruption levels, and the adversary tactics have remained unchanged.
Trivy supply chain attack pushed malicious Docker images on March 22, enabling credential theft and worm spread, impacting cloud environments.
CVE-2025-32975 exploited since March 2026 on unpatched KACE SMA systems, enabling admin takeover and payload delivery.
CVE-2026-21992 can be used without authentication for remote code execution and it may have been exploited in the wild.
The 10 finalists will each have three minutes to make their case for being the most innovative, promising young security company of the year.