NightEagle Uses BlueKeep and DCSync to Move Toward Active Directory Domain Controllers
NightEagle, an espionage-focused threat group also tracked as APT-Q-95, has expanded its operations from Asian targets to Russian organizations, using a laye...
20 articles
NightEagle, an espionage-focused threat group also tracked as APT-Q-95, has expanded its operations from Asian targets to Russian organizations, using a laye...
A sophisticated npm supply-chain campaign has been linked to 10 malicious JavaScript packages that collectively recorded millions of downloads while bypassin...
A ransomware incident in which attackers used Active Directory Group Policy to disrupt operations without deploying a Windows encryptor or leaving malware ru...
A newly identified information-stealing campaign, tracked as Rapuncel, is exploiting a Microsoft-attested kernel driver to terminate up to 145 antivirus (AV)...
A recently published proof-of-concept project named BigDiskBuster claims to prevent Microsoft Defender from completing its platform and security intelligence...
North Korea’s Hangro VPN and mail platform has deployed a new certificate hierarchy that exposes an apparent cross-border management environment spanning sys...
Threat actors are increasingly abusing Microsoft Teams’ external chat capabilities to impersonate corporate IT help desks. They trick employees into installi...
Security researchers have unveiled a cache poisoning technique called cache key injection that lets attackers bypass access controls, expose cached sensitive...
North Korea-linked threat actor TraderTraitor has expanded its developer-focused intrusion activity beyond cryptocurrency targets, using weaponized Terraform...
“HEIF Heist,” a broad class of image-processing attack paths that could allow threat actors to turn malicious HEIF, HEIC, and AVIF uploads into remote code e...
A newly tracked Windows infostealer dubbed Remus is expanding its credential-theft playbook by targeting API tokens and local usage data tied to AI platforms...
Exim maintainers have released version 4.100.
A newly uncovered EtherHiding campaign has turned the Polygon blockchain into a resilient command-and-control mechanism, allowing operators to rotate malware...
Security researchers have revealed a zero-click attack technique known as BragJack, which could enable a malicious browser extension to hijack built-in AI as...
Threat actors linked to the TanStack npm supply chain compromise allegedly used a stolen GitHub OAuth token to clone about 170 private CrowdSec repositories,...
Threat actors rapidly exploited a critical authentication bypass in cPanel and WHM to compromise internet-facing hosting servers, with Japanese telemetry dat...
A recently disclosed WordPress vulnerability, known as Click2Shell, could let attackers execute remote PHP code on vulnerable sites after convincing a logged...
Google has confirmed that its Gemini artificial intelligence model accidentally accessed protected systems belonging to three real companies during a cyberse...
North Korean threat actors, known as WaterPlum (also referred to as Contagious Interview), have infected at least 30,000 devices in over 100 countries by lur...
Researchers have identified a new Android banking Trojan called RatHat that utilizes artificial intelligence to automate device compromise and steal financia...