CISA added CVE-2026-48939 and CVE-2026-56291 to its Known Exploited Vulnerabilities catalog after automated attackers ...
ESET found 11 Microsoft-signed UEFI shims, some over a decade old, that let attackers bypass Secure Boot without a single new ...
A technical walkthrough of the kerberoasting attack: the Kerberos quirk it abuses, RC4 vs AES, and how to detect and fix it ...
GodDamn ransomware's PoisonX driver is a textbook EDR bypass driver: a Microsoft-signed kernel driver that kills security ...
Google, the FBI and the IRS Criminal Investigation division disrupted NetNut, a residential proxy network built on two million hijacked devices and used by 316 threat clusters in a single week.
SonicWall CVE-2024-40766 is an improper access control flaw in SonicOS. It affects the management interface and SSLVPN service on Gen 5, Gen 6, and Gen 7 firewalls. NIST rates it CVSS 9.8. An ...
Google has rewritten the default rate-limiting schedule behind Android’s lockscreen. Its mechanics are worth understanding if you test, forensically image, or manage fleets of Android devices. The new ...
Linux server hardening guides often present a flat list of fifty things to do, which is not useful when you have a production deployment in two hours. This guide is structured by time: what to do in ...
Most software composition analysis tools read what developers declare. Insignary Clarity’s patented binary-first platform analyzes what is actually built, shipped, and deployed — including the ...
Credential stuffing is the automated testing of stolen username and password pairs against a login endpoint, at scale, until a valid match turns up. For defenders, it is less a single attack to block.
Two new Cursor IDE vulnerabilities let an attacker break out of the editor’s command sandbox. All it takes is text the AI agent reads on your behalf. Cato AI Labs disclosed the pair, tracked as ...
CVE-2026-8451 hits NetScaler ADC and NetScaler Gateway appliances running as a SAML identity provider. That is a common setup for single sign-on into internal apps. Vulnerable versions are 14.1 before ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results