Global security desk · updated coverage of threats, exploits & breaches

IT, Cyber, Network & Enterprise Security News

Coverage of threats, vulnerabilities, exploits and cybercrime — from dark web activity to Android and iOS patches.

Dark navy blue globe with faint grid lines, glowing network nodes, and a moody atmospheric grain

What's on SecNews24

SecNews24.com tracks IT Security, Cyber Security, Network Security and Enterprise Security topics, with recurring coverage of Threats, Vulnerabilities, Exploits and Cybercrime, plus dedicated reporting on the Dark Web, Hacking, IoT, Malware, OS issues and Cloud Computing.

Close-up analog photograph of a circuit board lit in cool blue tones with visible film grain
30 March 2019

What is Single Sign-on (SSO)?

A look at SSO as a way to help organizations manage company data security across systems.

Read on the News feed →
Dark slate-toned photograph of an abstract exploit-themed graphic with faint code-like texture and grain
30 March 2019

Bithumb Exchange Hacked a Third Time

The Bithumb cryptocurrency exchange was reported hacked for a third time in two years.

See more on Threats →

Recent Reporting

A selection of stories published on the site, spanning mobile threats, patch cycles and hardware curiosities.

Malvertising Campaign Abuses Chrome for iOS Bug

A malvertising campaign exploited a vulnerability in the Chrome for iOS browser to target iPhone and iPad users. Reported with reference to ZDNet.

Google May 2019 Patches Address 4 RCE Flaws in Android

Google's May 2019 Android patches addressed critical vulnerabilities, including four remote code execution flaws. Reported with reference to Security Affairs.

PSA: Update WhatsApp to Prevent Spyware Installation

WhatsApp patched a critical vulnerability that had allowed spyware to be installed on users' phones, according to coverage citing The Next Web.

Cellebrite iPhone Tool Found at a Thrift Store

A collector found a Cellebrite iPhone data transfer tool at a thrift store and installed Doom on it, per a story citing Motherboard.

Modern IT security operations rely on layered defenses that combine network monitoring, identity controls, and timely patch management to reduce exposure to common threats. As attack surfaces expand across cloud workloads, remote endpoints, and unmanaged devices, defenders shift from purely preventive tools to continuous detection paired with rapid response playbooks. Threat intelligence feeds enrich alerts with context, helping teams prioritize vulnerable systems over generic noise and steadily lowering the dwell time of intruders inside enterprise environments.

Vulnerability management remains a cornerstone of cyber hygiene, requiring organizations to track disclosures, assess exploitability, and deploy fixes before adversaries weaponize weaknesses. Public databases catalog issues by severity and affected versions, while proof-of-concept code circulating in the wild raises urgency. Mature programs pair automated scanning with manual validation, ensuring critical assets receive attention first and that compensating controls are applied when patches must wait.

Enterprise security increasingly intersects with privacy and compliance obligations, as regulators demand clearer records of how data is collected, stored, and shared. Security teams collaborate with legal and business stakeholders to map sensitive flows, document retention rules, and respond to incidents in line with regional frameworks. This cross-functional approach treats data protection as an ongoing governance concern rather than a purely technical checklist handled in isolation.

The dark web continues to function as a marketplace for stolen credentials, leaked documents, and illicit services, motivating defenders to monitor underground forums for early warning signs. Researchers track shifts in pricing, vendor reputation, and emerging fraud kits to inform defensive priorities. Proactive dark-web monitoring complements traditional telemetry by surfacing brand impersonation, credential resale, and planned campaigns before they escalate into active incidents.

Malware analysis and incident response benefit from sharing indicators of compromise across organizations, industries, and public-private partnerships. Coordinated disclosure allows researchers to publish technical details after affected vendors release fixes, striking a careful balance between transparency and user safety. Cross-sector collaboration turns isolated observations into collective resilience, giving network defenders broader visibility into adversary techniques and helping shape safer default configurations for browsers, devices, and enterprise platforms.

Explore by Topic

Jump into focused coverage areas across the site.

Dark Web Watch

Reports on dark web market activity, including coverage of market shutdowns and service transfers, alongside analysis of illicit goods activity.

Visit Dark Web section →

Exploits & CVEs

Coverage of specific flaws such as CVE-2019-10953, affecting programmable logic controllers from vendors including ABB, Phoenix Contact, Schneider Electric, Siemens and WAGO, plus mobile OS patch updates.

Visit Exploits section →

"New Intel Chip Bug Can Expose All Data on a Computer to Hackers" — one of the hardware-security stories featured on the homepage feed.

From SecNews24.com reporting

Archived Coverage

Articles are organized by month going back to 2017, covering breach aftermath, regulatory shifts such as GDPR planning, and DDoS activity across that period.

Browse Archives

Books & Reference

A resource section pointing to security-related reading, including material on encryption, forensics and defensive practice.

Visit Books →