Fresh Windows Zero-Day Exploited in North Korean Cyberattacks
The bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor. The post Fresh Windows Zero-Day Exploited in Nort...
20 articles
The bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor. The post Fresh Windows Zero-Day Exploited in Nort...
Crytica Security has developed a patented solution that delivers rapid, deterministic threat detection for operational technology (OT), protecting the embedd...
Google Chrome’s latest measures against abusive web push notifications include automatically revoking notification permissions for inactive and suspicious we...
Kimwolf v7: The Android TV Botnet That Now Hides Its Traffic Behind Chrome Fingerprints and Ethereum Palo Alto Networks Unit 42 discovered Kimwolf v7 on Febr...
Network traffic analysis spans two buying worlds — ops tools with published price lists and security platforms with quote-only enterprise pricing — and knowi...
Microsoft has disclosed a new remote code execution (RCE) vulnerability in Outlook, tracked as CVE-2026-70329. They warn that successful exploitation could a...
The vulnerabilities could be exploited to leak credentials for external SQL connections or crash an agent service. The post Ivanti EPM Update Patches Remotel...
Microsoft has issued another massive batch of security updates with 400 fixed in the August Patch Tuesday
Chaotic Eclipse released a PoC for ShieldBreak, a Microsoft Defender zero-day that bypasses the CVE-2026-50656 patch and could enable SYSTEM-level code execu...
Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubern...
CISA has also published several advisories describing vulnerabilities in ICS and other OT products. The post ICS Patch Tuesday: Vulnerabilities Fixed by Siem...
Spanish police have arrested a man in Murcia accused of using deepfake software to trick a certificate provider’s video identity checks in an attempt to obta...
Project CAV3RN, a modular cyberespionage framework targeting organizations in Israel, has added a sophisticated command-and-control design that dynamically b...
Lazarus has expanded its long-running Operation Dream Job campaign by exploiting a Windows zero-day vulnerability that grants attackers SYSTEM-level access a...
SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code executio...
The security defects could allow unauthenticated attackers to execute arbitrary code remotely and read sensitive data. The post SonicWall Patches Critical Vu...
Microsoft Patch Tuesday for August 2026 fixes 398 CVEs, including an actively exploited zero-day and a wormable DNS flaw enabling remote code execution. Micr...
The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) ...
An advanced recruitment-themed intrusion campaign attributed to UAC-0145, a cluster that includes subcluster UAC-0002, also tracked as Sandworm, APT44 and Se...
Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Softw...