Lunar Cyber today announced Token Exposure Monitoring, a new capability designed to identify, attribute and validate ...
Testing for a CORS misconfiguration vulnerability comes down to one move. Send a request with an untrusted Origin header at a sensitive, authenticated endpoint. Then check whether the server reflects ...
Device code phishing let a Russian state hacking crew skip stealing passwords entirely. It walked straight into business travelers’ Microsoft 365 accounts instead. Microsoft’s Threat Intelligence team ...
Check Point has confirmed active attacks on a critical SmartConsole authentication bypass. The flaw sits in its Security Management and Multi-Domain Management servers. A working proof-of-concept is ...
Sweet Security, the proactive runtime enforcement company for cloud and AI, today announced its further expansion into AI security with Agentic AI Blocking. Sweet now blocks rogue agent behavior in ...
A public proof-of-concept for an unauthenticated remote code execution flaw in vBulletin landed on July 27, exposing forum administrators who skipped last month’s patch cycle. The vBulletin RCE ...
7-Zip has patched a heap-based buffer overflow in its XZ decompression code. A specially crafted archive could run arbitrary code the moment a victim extracted it. This 7-Zip vulnerability, tracked as ...
An AI agent broke into a Langflow server, hit a dead end, then wrote its own way past it. Five minutes and twenty-four seconds later it had a working deployment pipeline for a new strain called ...
Does your team point a coding agent at Azure DevOps pull requests? You now have a configuration problem to fix. Researchers at Manifold Security disclosed an Azure DevOps MCP flaw this week. It lets ...
Two Joomla file upload vulnerabilities landed on CISA’s Known Exploited Vulnerabilities catalog on July 10. Both were already being hit by automated attackers weeks before anyone assigned them a CVE ...
Most EDR bypass driver incidents rely on a driver the attacker never had to hide, because it already has a real, valid signature. That is exactly what happened with GodDamn, a ransomware family that ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results