Oct 21, 2025Ravie LakshmananCyber Espionage / Threat Intelligence A new malware attributed to the Russia-linked hacking group known as COLDRIVER has undergone numerous developmental iterations since May 2025, suggesting an …
Safety & Security
As we conclude the third quarter of 2025, EHS Insight continues to enhance its platform with features designed to streamline operations, improve compliance, and foster better communication. Here’s a breakdown …
From Clutter to Clarity and Evidence at RMIT’s SHINe Symposium – SafetyAtWorkBlog
Just over a week ago, RMIT University’s research funding program, SHINe, conducted its inaugural symposium. This symposium was both new and fascinating. It was overbooked with a …
Government considered destroying its data hub after decade-long intrusion
Gavin Knapp, cyber threat intelligence lead at Bridewell, a supplier to the UK government critical network infrastructure, endorsed the severity of this approach. He said, “it’s like when a device is …
Email Bombs Exploit Lax Authentication in Zendesk – Krebs on Security
Cybercriminals are abusing a widespread lack of authentication in the customer service platform Zendesk to flood targeted email inboxes with menacing messages that come from hundreds of Zendesk corporate customers …
Microsoft Revokes 200 Fraudulent Certificates Used in Rhysida Ransomware Campaign
Oct 17, 2025Ravie LakshmananMalware / Cybercrime Microsoft on Thursday disclosed that it revoked more than 200 certificates used by a threat actor it tracks as Vanilla Tempest to fraudulently sign …
Coming in at number #8 on OSHA’s annual top 10 list of their most cited standards is 29 CFR 1910.178 Powered Industrial Trucks (PITs) (which includes forklifts and similar equipment). …
Last week, I attended a webinar on psychological safety that confirmed all of my worst fears about the Human Resources approach to addressing psychosocial factors and mental …
SonicWall VPNs face a breach of their own after the September cloud-backup fallout
Huntress’ new discovery, however, points to a separate, credential-driven campaign. Starting around October 4, Huntress observed mass logins into SonicWall SSLVPN devices from attacker-controlled IPs – one notably traced to …
DDoS Botnet Aisuru Blankets US ISPs in Record DDoS – Krebs on Security
The world’s largest and most disruptive botnet is now drawing a majority of its firepower from compromised Internet-of-Things (IoT) devices hosted on U.S. Internet providers like AT&T, Comcast and Verizon, …