Krebs On Security
- A new Internet-of-Things botnet called Kimwolf has spread to more than 2 million devices, forcing infected systems to participate in massive distributed denial-of-service (DDoS) attacks […]
- Microsoft today issued patches to plug at least 113 security holes in its various Windows operating systems and supported software. Eight of the vulnerabilities earned […]
- Our first story of 2026 revealed how a destructive new botnet called Kimwolf rapidly grew to infect more than two million devices by mass-compromising a […]
- The story you are reading is a series of scoops nestled inside a far more urgent Internet-wide security advisory. The vulnerability at issue has been […]
- KrebsOnSecurity.com celebrates its 16th anniversary today! A huge "thank you" to all of our readers — newcomers, long-timers and drive-by critics alike. Your engagement this […]
- The Trump administration has pursued a staggering range of policy pivots this past year that threaten to weaken the nation’s ability and willingness to address […]
Secure World
- The "traditional" ransomware playbook—encrypting servers and demanding a ransom for the key—is increasingly taking a backseat to a more surgical, […]
- In the world of cybersecurity, we often talk about "defense in depth." But for state governments, a new philosophy is […]
- Businesses of all sizes are still wrestling with a core infrastructure question: Are dedicated servers or cloud servers more secure?
- Most cloud programs can point to a stack of green checkmarks: CIS Benchmarks passed, vendor "secure by default" settings enabled, CSPM […]
- As organizations look ahead to the latter half of the decade, cybersecurity leaders are converging on a shared conclusion: the […]
- Data Privacy Week, occurring January 26-30, 2026, is an international campaign led by the National Cybersecurity Alliance (NCA) aimed at […]
Dark Reading
- People trust organizations to do the right thing, but websites’ and apps’ dark patterns pose a hidden threat that can […]
- A malware-free phishing campaign targets corporate inboxes and asks employees to view "request orders," ultimately leading to Dropbox credential theft.
- Iowa police arrested two penetration testers in 2019 for doing their jobs, highlighting the risk to security professionals in red […]
- State-sponsored threat actors compromised the popular code editor's hosting provider to redirect targeted users to malicious downloads.
- Following their attacks on Salesforce instances last year, members of the cybercrime group have broadened their targeting and gotten more […]
- Investors poured $140 million into Torq's Series D Round, raising the startup's valuation to $1.2 billion, to bring AI-based "hyper […]
