Exotic files: unexpected sources of cyberthreats
We break down the file formats that can be unfamiliar to some users, and that aren’t always scanned by security solutions but can still pose cyberthreats.
550 articles
We break down the file formats that can be unfamiliar to some users, and that aren’t always scanned by security solutions but can still pose cyberthreats.
Attackers are crafting files that devices can read as two different document types at once, and using these “nesting dolls” to smuggle in malware. How to detect and neutralize these two-faced files?
An analysis of key characteristics of AI agent-driven cyberattacks, why open-source models are sufficient to execute them, and what measures can help defend an organization.
How attackers distribute ScreenConnect under the guise of free software to deploy AsyncRAT.
We analyze the first-ever real-world incidents where attackers targeted AI agents deployed in corporate environments.
A new variation of ClickFix allows attackers to gain access to Microsoft 365 accounts. We break down how this technique works, and what threat it poses to organizations.
How attackers gain access to corporate services without stealing passwords or cookies: we’re analyzing the Shadow Token via Remote Debug technique used in ToddyCat APT attacks.
Microsoft has addressed approximately 600 vulnerabilities in its products, affecting its entire product line — including even Minecraft Server and Age of Empires II. How can organizations handle such a volume?
Before launching a phishing attack, attackers initiate correspondence with the victim.
These attacks didn’t start with sophisticated exploits. Instead, they relied on stolen passwords, too-lenient access rights, and a failure to apply long-released vulnerability patches.
A GReAT study has identified ~250,000 potential security issues in publicly accessible GitHub Actions.
We break down the core challenges and potential solutions for building a fully autonomous security operations center.
Austrian researchers have uncovered a bizarre new way hackers could steal sensitive data.
How to detect and block unauthorized AI tools in an organization.
Approaches to solving cybersecurity challenges in autonomous transportation systems.
High-level strategies for locking down popular AI tools that are either unneeded or outright banned under corporate policy.
How we use Kaspersky Container Security at Kaspersky, and why it’s much more than just an image scanner to us.
Attempts at hijacking AI resources are now taking place on an industrial scale. How is AI infrastructure being targeted, and what defensive measures should you implement?
We regularly create new SIEM rules, but behind the scenes lies a more fundamental process —the evolution of the correlation rules themselves.
A targeted supply chain attack via popular software for mounting disk images.