Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory …
آسیبپذیریها و تهدیدات روز با رتبهبندی CVSS و شدت — مستقیم از تیم تحلیل تهدیدات سیاره فناوری اطلاعات.
Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory …
Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are …
For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and …
Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched …
Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for …
A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank …
The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a …
Slopsquatting, phantom squatting, and HalluSquatting all exploit the same late-binding attack pattern, where AI coding agents trust hallucinated …
A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during …
A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers …