Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
2+ hour, 47+ min ago (792+ words) A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL. Confiant, which detailed the campaign on…...
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
9+ hour, 18+ min ago (597+ words) Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process....
DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
11+ hour, 41+ min ago (829+ words) The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims. Swiss cybersecurity company PRODAFT is tracking the centrally administered…...
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
11+ hour, 58+ min ago (362+ words) Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign. "Attackers chain a pre-authentication information disclosure in…...
CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
11+ hour, 58+ min ago (715+ words) For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and accounts were compromised later when an opportunity arose. That model is changing. Recent investigations into insurance-focused…...
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
13+ hour, 31+ min ago (515+ words) Security researcher Yuhang Wu at depthfirst has published a working proof-of-concept (PoC) exploit that executes commands as git on an unpatched self-managed GitLab 18.11.3 server. An ordinary authenticated user triggers it by committing two crafted Jupyter notebooks and requesting their diff....
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
1+ day, 5+ hour ago (843+ words) The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware. Describing…...
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
1+ day, 7+ hour ago (508+ words) Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. They codenamed the flaw Certighost. Because Domain Controller accounts carry directory…...
Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do
1+ day, 9+ hour ago (1050+ words) Recent guidance on the careful adoption of agentic AI services makes the point clear: agentic AI introduces privilege, authentication, accountability, design, and behavioral risks that security teams need to address before these systems become embedded in critical workflows. Visibility is…...
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
1+ day, 10+ hour ago (653+ words) A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet. XBOW's testing got the same result on workers across different…...