general
20 articles
CBTS brings continuous penetration testing to enterprise security
CBTS has launched Penetration Testing as a Service (PTaaS), combining autonomous penetration testing with security expertise to help organizations continuous...
Fresh Windows Zero-Day Exploited in North Korean Cyberattacks
The bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor. The post Fresh Windows Zero-Day Exploited in Nort...
Crytica’s RDAi detects OT device tampering from within
Crytica Security has developed a patented solution that delivers rapid, deterministic threat detection for operational technology (OT), protecting the embedd...
Chrome’s anti-abuse protections block 7 billion unwanted Android notifications daily
Google Chrome’s latest measures against abusive web push notifications include automatically revoking notification permissions for inactive and suspicious we...
Kimwolf v7 Hides DDoS Traffic Behind Chrome Fingerprints and Ethereum
Kimwolf v7: The Android TV Botnet That Now Hides Its Traffic Behind Chrome Fingerprints and Ethereum Palo Alto Networks Unit 42 discovered Kimwolf v7 on Febr...
The Best Network Traffic Analysis (NTA) Tools, Compared and Priced (2026)
Network traffic analysis spans two buying worlds — ops tools with published price lists and security platforms with quote-only enterprise pricing — and knowi...
Microsoft Outlook RCE Vulnerability Lets Attackers Execute Code Remotely
Microsoft has disclosed a new remote code execution (RCE) vulnerability in Outlook, tracked as CVE-2026-70329. They warn that successful exploitation could a...
Ivanti EPM Update Patches Remotely Exploitable Flaws
The vulnerabilities could be exploited to leak credentials for external SQL connections or crash an agent service. The post Ivanti EPM Update Patches Remotel...
Microsoft Fixes 400 Flaws on August Patch Tuesday
Microsoft has issued another massive batch of security updates with 400 fixed in the August Patch Tuesday
ShieldBreak: New Windows Zero-Day Bypasses Microsoft’s RoguePlanet Patch
Chaotic Eclipse released a PoC for ShieldBreak, a Microsoft Defender zero-day that bypasses the CVE-2026-50656 patch and could enable SYSTEM-level code execu...
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubern...
ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact
CISA has also published several advisories describing vulnerabilities in ICS and other OT products. The post ICS Patch Tuesday: Vulnerabilities Fixed by Siem...
Split-second deepfake glitch blows digital certificate fraudster’s cover
Spanish police have arrested a man in Murcia accused of using deepfake software to trick a certificate provider’s video identity checks in an attempt to obta...
Project CAV3RN Uses Google Apps Script and DNS to Hide C2 Traffic in Israeli Cyberespionage Attacks
Project CAV3RN, a modular cyberespionage framework targeting organizations in Israel, has added a sophisticated command-and-control design that dynamically b...
Windows AFD.sys Zero-Day Exploited by Lazarus Hackers to Gain SYSTEM Access
Lazarus has expanded its long-running Operation Dream Job campaign by exploiting a Windows zero-day vulnerability that grants attackers SYSTEM-level access a...
SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code executio...
SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform
The security defects could allow unauthenticated attackers to execute arbitrary code remotely and read sensitive data. The post SonicWall Patches Critical Vu...
Microsoft Patch Tuesday for August 2026 Fixed a Zero-Day and Wormable RCE
Microsoft Patch Tuesday for August 2026 fixes 398 CVEs, including an actively exploited zero-day and a wormable DNS flaw enabling remote code execution. Micr...
ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access
The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) ...