Metal Gear Online 3 vulnerability allowed remote code execution
The vulnerability, discovered by researcher Alice Cecchetto and detailed by CERT/CC, stemmed from a heap-based buffer overflow in the game's player-removal m...
Ransomware exploiting Exchange vulnerabilities and Fortinet flaws, targeting municipalities, legal firms, and manufacturing.
Also known as: play ransomware, playcrypt, play malware
The vulnerability, discovered by researcher Alice Cecchetto and detailed by CERT/CC, stemmed from a heap-based buffer overflow in the game's player-removal m...
A phishing method, named Chameleon SEO Poisoning, that uses manipulated search results and cloaked fake banking websites to steal credentials while evading s...
The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote co...
The hacking group, identified as Salt Typhoon, compromised hundreds of companies, including major players like AT&T, Verizon, Viasat, Charter, and Windst...
North Korean state-backed threat actor Kimsuky is extending its established espionage playbook with locally hosted artificial intelligence tooling, according...
Security researchers Alejandro Hernando and Borja Martínez demonstrated attacks at DEF CON 34 that exploit Windows' automatic hardware identification and dri...
Security researchers have disclosed new "Plug and Pwn" attacks that abuse the Windows Plug and Play feature to trigger Windows into installing vulnerable or ...
Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researcher...
This vulnerability allows remote attackers to bypass authentication on affected installations of Microsoft Exchange. Authentication is not required to exploi...
The vulnerabilities were found in Samsung's proprietary system apps, which cannot be uninstalled by users and operate outside the protection of Google Play P...
Play ransomware is using a familiar Windows-administration disguise to reduce suspicion during intrusions: a custom service binary named PSexesvc.exe.
Key takeaways OAuth client ID spoofing defeats detections that key off application name or a known application ID, because the field itself is fabricated, ro...
The attack on water systems across seven states was preventable. Utilities had the playbook.
Connor Moucka obtained almost $500,000 for playing a key role in one of the most widespread and damaging cyberattack sprees on record. The post Snowflake hac...
Fake Xeno Executor installers are targeting Roblox players with malware that provides remote access and steals sensitive information.
Fake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals sensitive information. [.
The scenario is all too familiar for any cybersecurity professional: It’s late in the day, and a critical zero-day vulnerability is disclosed. When this happ...
AI is compressing exploit timelines. The real question isn't whether your vulnerability management playbook needs to change, it's which part of it you've bee...
As outlined in Cyber Insider, a malicious Steam Workshop map for the game MECCHA CHAMELEON exploited a vulnerability in the game's mod-loading system to deli...
Get practical insight from teams who’ve built, scaled and handed over engineering functions at enterprise level. Most engineering teams don’t fail because of...