A newly disclosed attack class, NatJack, reveals significant weaknesses in the implementation of Network Address Translation (NAT) across modern network…
Tag: EN
Attacker phished way into US defense supplier’s Microsoft 365 account
Intruder gained access to engineering files and potentially export-controlled technical data
Vishing Extortion Group UNC6671 Rebrands After Making Millions
Initially calling itself BlackFile, the group has expanded operations to the Redact, Pink, Helix, and Falcon brands.
UNC6671 Automates Microsoft 365 Data Theft After Hijacking Employee Sessions
UNC6671 is carrying out data theft campaigns that begin with a phone call. The group poses as an IT helpdesk, claiming an urgent security migration is…
ISA VDA 6.0.3 – The Data Protection sheet explained
The Data Protection catalog is the shortest of the three in ISA 6.0.3 and the one most often underestimated. Twelve control questions across eight…
Meta Ordered to Pay $567 Million Over Child Safety Failures in New Mexico Case
Meta was ordered to pay $567M after a judge ruled its platforms harmed children, bringing New Mexico penalties to $942M. Meta ‘s child-safety legal bill…
Papyrus Mobile Ad Fraud Uses Hidden WebViews to Fake Clicks, Scrolls and Attention
Papyrus is a mobile ad fraud operation hiding behind apps built for reading serialized fiction. While people turn pages and follow stories, the apps can…
AI firms know policymakers won’t ‘let you make a Terminator factory,’ DHS official says
Leading AI companies have learned important lessons from recent incidents, the official said, and regulation isn’t necessary to preserve those lessons.
Researchers Discover Hidden Backdoor in 20 Router Models Allowing Remote Root Access
A hidden backdoor in 20 router models lets remote servers execute commands as root, putting affected devices at risk of takeover. Jacob Baines had a…
Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix
NMFTA research shows a Bendix EC80 brake controller safety recall also patched remote code execution and DoS vulnerabilities.
ICE Is Buying Access to Credit Card Records
Through data brokers, ICE is buying the information you provided to open a credit card.
Healthcare and Victim Support Charities Affected by Beacon Cyber Incident
Beacon has informed around 1500 customer charities that its CRM databases were accessed and likely exfiltrated by an unauthorized actor
‘Asimov was right’ about rules for robots, says ex-US Cyber Director
Humans will get the AI models they deserve
Google Chrome 151 Update Fixes 41 Security Vulnerabilities, Including 6 Critical Flaws
Google has released Chrome version 151.0.7922.108/.109 for Windows and macOS, and version 151.0.7922.108 for Linux. This update delivers 41 security fixes…
AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP…
Claude Code RCE Flaw Lets Malicious Pull Requests Execute Code on Developer Systems
A malicious pull request has the potential to turn Claude Code’s project-scoped Model Context Protocol (MCP) configuration into a trigger for code…
Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
Cybersecurity researchers have called attention to an active “widespread email-driven phishing campaign” that employs adversary-in-the-middle (AitM)…
Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to…
Microsoft, Apple Release Fresh Security Updates
Microsoft fixed critical vulnerabilities across Azure, Entra, and SharePoint, while Apple patched a high-severity authentication bypass.
Google Links Redact Extortion Group to BlackFile Rebrand
BlackFile has rebranded as Redact after an alleged affiliate hijack, with Google linking the group to ongoing vishing and extortion campaigns