Security researcher MSNightmare, also known as Nightmare-Eclipse, has released BigDiskBuster, a proof-of-concept denial-of-service technique designed to…
Tag: EN
Hackers Use Microsoft-Signed Driver to Disable 145 Security Tools and Steal Passwords
Researchers uncovered a malware campaign that used a Microsoft-attested Windows kernel driver to turn off 145 antivirus and endpoint security processes,…
Claude Opus 5 Helps Researchers Weaponize HEIF Image Flaw Into Remote Code Execution
A specially crafted image file was enough to turn a normal upload feature into a potential path to server takeover. Researchers have shown that a flaw in…
Google hit with €403 million GDPR fine over location tracking
Ireland’s Data Protection Commission (DPC) has fined Google €403 million (about $463 million) over its processing of users’ location data and ordered the…
Remus Infostealer Removes Syscall Hooks to Evade EDR and Steal Sensitive Credentials
Remus is a Windows information stealer that is gaining attention for the way it hides before taking data. The malware surfaced on underground marketplaces…
New Rapuncel Infostealer Abuses Microsoft-Signed Driver to Disable 145 Security Tools
A newly identified information-stealing campaign, tracked as Rapuncel, is exploiting a Microsoft-attested kernel driver to terminate up to 145 antivirus…
Rust Team Members and Popular Crate Owners Targeted via Video Calls
It’s unclear if the attacks are part of previous campaigns against Rust, but the techniques used by the attackers match those used by North Korea.
From Energy Consumer to Grid Partner: The Business Case for Smart Power
Discover how storage, renewables and demand response can help businesses cut costs, improve resilience and unlock new energy revenue.
PAYLOAD Ransomware Abuses Active Directory Group Policy to Disrupt Entire Windows Domain
A ransomware incident in which attackers used Active Directory Group Policy to disrupt operations without deploying a Windows encryptor or leaving malware…
BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates
A recently published proof-of-concept project named BigDiskBuster claims to prevent Microsoft Defender from completing its platform and security…
CrowdSec Confirms Source Code Stolen in Supply Chain Attack
The cybersecurity firm believes the data breach was the result of the May 2026 TanStack supply chain attack.
A BYD Shark 6 Hack Shows the Risks of Connected Cars
A BYD Shark 6 was remotely hacked, exposing vehicle controls, location tracking and cabin audio, raising serious connected-car security concerns. A…
Scammers impersonate cops, use arrest threats to extort victims
Scammers are posing as police officers and federal agents, threatening arrest unless victims pay up, the FBI warns. The FBI’s Internet Crime Complaint…
Rustaceans warned of job interviews with a malicious payload
Attackers are courting crate owners with plausible company profiles and booby-trapped recruitment calls
US and China Discuss Alerting Each Other to AI National Security Threats
Officials discussed setting up a mechanism for the two countries to notify each other of AI incidents which could threaten national security.
ShinyHunters hacks rival extortion gang and takes over its dark web site
Hackers hacked the hackers as a feud between two cybercrime groups escalated, leaving ShinyHunters with the upper hand over rival Clop.
Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active…
TerminalFix: PNG Steganography, (Mon, Sep 21st)
Microsoft Security Research published an interesting blog post “TerminalFix campaign deploys a reverse tunnel through multistage intrusion” about a…
Hackers Hide Malware Servers on Blockchain to Steal Bank Logins and 2FA Codes
A new malware campaign is using blockchain technology to keep its control servers out of reach. The operation tricks visitors to compromised business…
From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies
We explore how AWS neutralizes exposed IAM credentials using managed policies, detailing GitHub secret scanning and CloudTrail monitoring strategies.
