search

Sections

Cyber Security

2432 articles

Cavern Manticore: Exposing Iran-Linked Modular C2 Framework
cybersecurity

Cavern Manticore: Exposing Iran-Linked Modular C2 Framework

Since early 2026, Check Point Research has been monitoring a new modular command-and-control framework associated with the Iranian APT group Cavern Manticore. This group primarily targets Israeli organizations, particularly in the IT and government sectors. Cavern Manticore is linked to Iran’s Ministry of Intelligence and Security and has connections to the OilRig group, highlighting its strategic focus on cyber operations against specific entities in Israel.

Check Point Research ·
6th July – Threat Intelligence Report
cybersecurity

6th July – Threat Intelligence Report

The latest Threat Intelligence Bulletin for the week of July 6th highlights significant developments in cyber research. One notable incident involves River Bank & Trust, a US financial institution that fell victim to a ransomware attack after an unauthorized individual breached the network of its parent company, River Financial Corporation, on June 16. The bank continues to assess the impact of this cybersecurity breach.

Check Point Research ·
Summer of Clearinghouses
cybersecurity

Summer of Clearinghouses

Clearinghouses alone won’t secure open source. Learn why actuation, trusted builds, and secure-by-design software matter more than vulnerability data.

Chainguard: Unchained ·
Catan and Mouse
cybersecurity

Catan and Mouse

What do board games and cybersecurity have in common? Pattern recognition. Strategy. Adaptation. In this week’s Threat Source Bill explores why curiosity may be a defender’s most valuable skill.

Cisco Talos Blog ·
AI-Speed Risk Requires Identity-Defined Reachability
cybersecurity

AI-Speed Risk Requires Identity-Defined Reachability

The article by Philip Griffiths highlights the need for evolution in Zero Trust security measures, specifically steps 3, 4, and 5, beyond traditional methods like patching and ticket-driven connectivity. It emphasizes that the rapid pace of AI-driven threats necessitates a shift from merely identifying and fixing vulnerabilities to adopting a more comprehensive architectural approach to risk management. The focus should be on proactive strategies to mitigate exposure rather than just reactive measures.

Cloud Security Alliance ·
Secure Amazon container workloads using container attribute-based rules in AWS Network Firewall
cybersecurity

Secure Amazon container workloads using container attribute-based rules in AWS Network Firewall

Today, you can use AWS Network Firewall to protect traffic flowing to and from containerized applications on Amazon Elastic Kubernetes Service (Amazon EKS) and Amazon Elastic Container Service (Amazon ECS) clusters. If you run AI and machine learning (ML) workloads on Amazon EKS—such as model inference, RAG pipelines, or JupyterHub—your containerized workloads require the same

AWS Security Blog ·
How to use the AWS Workload Credentials Provider for cross-account secret retrieval and prefetching secrets
cybersecurity

How to use the AWS Workload Credentials Provider for cross-account secret retrieval and prefetching secrets

If you manage secrets across multiple AWS accounts or need faster secret access for latency-sensitive applications, this post shows you how to meet those requirements using two new features of the AWS Workload Credentials Provider (provider). You will learn how to configure role chaining for cross-account secret retrieval and prefetching of secrets to reduce cold-start

AWS Security Blog ·
Vulnerability Prioritization Is Missing the AI-Era Point
cybersecurity

Vulnerability Prioritization Is Missing the AI-Era Point

Modern software development increasingly depends on third-party open source components, which has spurred significant innovation by allowing teams to concentrate on delivering value. However, this reliance introduces risks and pressures for Application Security teams, who must navigate a barrage of threats that challenge even seasoned organizations. To manage their growing workload, effective teams prioritize efforts to tackle the most critical tasks first, ensuring essential security measures are addressed.

2024 Sonatype Blog ·