SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

A Critical SAP Kernel Flaw Exposes Millions to Remote Code Execution SAP, a leading provider of enterprise software solutions, has issued patches for a devastating kernel flaw that allows unauthenticated attackers to execute code remotely on affected systems. This vulnerability, rated CVSS 10.0 – the highest severity rating possible – puts millions of organizations at … Read more

Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

Microsoft’s flagship security software, Defender, has been left vulnerable once again after a researcher revealed a proof-of-concept (PoC) exploit that can bypass the patch designed to protect against ShieldBreak attacks. This development highlights the cat-and-mouse game between cybersecurity vendors and attackers, with each side continually pushing the boundaries of what is possible. The PoC, released … Read more

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

A sophisticated malware campaign has been discovered targeting F5 BIG-IP Application Delivery Controllers (ADCs), leaving organizations vulnerable to web shell injections and potentially catastrophic data breaches. The malicious code, dubbed a “PHP web shell,” injects itself into system memory, evading detection by conventional disk-based scanning methods. The attack vector leverages the vulnerabilities in BIG-IP APM … Read more

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

A sophisticated cyber threat has come to light, where malicious actors are exploiting compromised login credentials to bypass multi-factor authentication (MFA) and gain unauthorized access to sensitive systems. The attack method involves using stolen AI tokens, which are essentially digital keys that can be replayed to authenticate a user, thereby sidestepping MFA protections. The vulnerability … Read more

Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

Microsoft’s latest Patch Tuesday update has set a new record, with an astonishing 974 vulnerabilities addressed across various products and services. Among these patches are two critical Windows zero-day flaws that have already been exploited by attackers in the wild. This massive effort to shore up security weaknesses is a testament to the ongoing cat-and-mouse … Read more

U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok

A string of high-profile accusations has emerged from U.S. agencies, targeting Chinese artificial intelligence (AI) firms for allegedly developing sophisticated AI-powered tools that mimic the capabilities of language models like Claude, GPT, Gemini, and Grok. At stake are concerns over data security, intellectual property theft, and the potential for these tools to be used in … Read more

Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets

A Critical Flaw in Alby Hub Exposes Bitcoin Wallets to Takeover by Hackers A critical vulnerability in Alby Hub, a software used for managing internet-exposed Bitcoin wallets, has been discovered, putting thousands of users at risk of having their accounts taken over by attackers. The flaw, which allows hackers to exploit cross-domain privilege escalation and … Read more

DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval

A Critical Flaw in AI Agents’ File Sandbox Leaves Users Exposed DeepSeek, a cutting-edge technology used by several organizations to enhance their cybersecurity posture through artificial intelligence-powered file sandboxing, has been found vulnerable to a critical flaw. This weakness allows malicious actors to disable the very mechanism designed to protect against threats, rendering users’ systems … Read more

Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE

As it turns out, many organizations are sitting ducks for cyber attacks due to their inability to quickly identify and respond to potential security breaches. A recent webinar highlighted 11 real-life stories of how identity exposure can unlock active attack paths, revealing a common thread – cross-domain privilege escalation. These stories show that when an … Read more