2026-04-16 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Francis deSouza · indexed 2026-08-15 18:55 UTC
Introduction Advances in AI model-powered exploitation have demonstrated that general-purpose AI models can excel at vulnerability discovery, even without being purpose-built for the task. Eventually, capabilities such as these will be integrated directly into the development cycle, and code will be more difficult to exploit than ever; however, this transition creates a critical window of risk. As we harden existing software with AI, threat actors will use it to discover and exploit novel vulne…
P60
2026-04-09 19:25 UTC
Vendor Research
Google Security Blog · Benjamin Ackerman · indexed 2026-08-15 18:55 UTC
Following our April 2024 announcement, Device Bound Session Credentials (DBSC) is now entering public availability for Windows users on Chrome 146, and expanding to macO…
P0
2026-04-09 17:07 UTC
Vendor Research
Google Online Security Blog · Google · indexed 2026-08-15 14:33 UTC
Posted by Ben Ackerman, Chrome team, Daniel Rubery, Chrome team and Guillaume Ehinger, Google Account Security team Following our April 2024 announcement, Device Bound Session Credentials (DBSC) is now entering public availability for Windows users on Chrome 146, and expanding to macOS in an upcoming Chrome release. This project represents a significant step forward in our ongoing efforts to combat session theft, which remains a prevalent threat in the modern security landscape. Session theft t…
P0
2026-04-07 09:00 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
Threat actors are using AI to supercharge tried-and-tested TTPs. When attacks move this fast, cyber-defenders need to rethink their own strategy.
P0
2026-04-02 16:00 UTC
Vendor Research
Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC
Posted by Adam Gavish, Google GenAI Security TeamIndirect prompt injection (IPI) is an evolving threat vector targeting users of complex AI applications with multiple data sources, such as Workspace with Gemini. This technique enables the attacker to influence the behavior of an LLM by injecting malicious instructions into the data or tools used by the LLM as it completes the user’s query. This may even be possible without any input directly from the user.IPI is not the kind of technical proble…
P0
2026-03-25 07:51 UTC
Government
CERT-EU Security Advisories · indexed 2026-08-15 18:50 UTC
On 17 March 2026, Microsoft updated one of its January 2026 security advisories related to a remote code execution vulnerability in Microsoft SharePoint. Specifically, Microsoft raised the CVSS score and changed the FAQ section to indicate that the vulnerability could be exploited by an unauthenticated attacker. This vulnerability was added in the CISA's Known Exploited Vulnerabilities (KEV) catalogue on 18 March 2026. Additionally, three further RCE flaws affecting Microsoft SharePoint were ad…
P55
2026-03-23 21:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Railway PaaS is being weaponized as a clean token replay engine in an active AiTM and device code phishing campaign impacting 268+ M365 organizations and 100+ MSPs.
P0
2026-02-05 15:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress uncovers the mechanics of the Windows Projected File System. Explore the ProjFS driver, virtualization roots, and the PowerShell commands.
P0
2026-01-29 15:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
SOAPHound's LDAP query (!soaphound=*) never appears in Event 1644 logs, but it transforms into (! (FALSE)) through LDAP optimization. Understanding this transformation reveals a unique detection signature that most defenders have never seen.
P0
2026-01-15 06:07 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
This blog uncovers DeadLock’s stealthy usage of Polygon smart contracts for proxy address storage, a poorly-documented and under-reported technique that Group-IB analysts have observed increased usage in the wild. Variants of this technique are very wide and offer great alternatives to threat actors for bypassing traditional defenses by abusing decentralized blockchains available worldwide.
P35
2026-01-13 06:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress researchers weigh in on the challenge of getting feature parity across Windows, macOS, and Linux. And learn how unique security models and platform maturity shape the way products are built.
P0
2025-12-22 09:55 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
A comprehensive analysis and assessment of a critical severity vulnerability with low likelihood of mass exploitation
P35
2025-12-22 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Think all threat actors are pros? This post reveals how 'unsophisticated' malware and attacker errors help defenders stop attacks before damage is done.
P0
2025-11-26 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress CEO Kyle Hanslovan's live hack demo: modern hacker playbook, with stolen credentials, MFA bypass, and M365 token hijacking. Get defense tips, stay protected.
P0
2025-11-26 08:22 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Since late June 2025, Group-IB analysts observed a surge in spear-phishing emails across Central Asia. The attackers impersonate government agencies to gain the trust of their victims. This blog describes the techniques, tools and ongoing activity of the threat group known as Bloody Wolf.
P0
2025-11-17 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress is now on the Microsoft Marketplace. Combine our protection with Microsoft 365 and Defender, get 24/7 monitoring, and enjoy enterprise-grade security without the hefty price tag.
P0
2025-11-04 16:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn how cybercriminals bypass Microsoft 365 MFA and steal credentials in a live hacking demo. Discover defense strategies to protect your systems.
P0
2025-10-28 17:01 UTC
Vendor Research
Google Online Security Blog · Google · indexed 2026-08-15 14:33 UTC
One year from now, with the release of Chrome 154 in October 2026, we will change the default settings of Chrome to enable “Always Use Secure Connections”. This means Chrome will ask for the user's permission before the first access to any public site without HTTPS. The “Always Use Secure Connections” setting warns users before accessing a site without HTTPS Chrome Security's mission is to make it safe to click on links. Part of being safe means ensuring that when a user types a URL or clicks o…
P0
2025-10-24 04:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress has observed threat actors exploiting a Microsoft Windows Server Update Services (WSUS) vulnerability (CVE-2025-59287).
P5
2025-10-06 08:11 UTC
Other
Red Hunt Labs · Lohit · indexed 2026-09-07 17:30 UTC
In today’s sprawling digital landscape, the question for security leaders isn’t whether Attack Surface Management (ASM) matters; it’s whether your ASM platform is doing enough to earn its place in the budget. If your board or finance team is asking you to justify the spend, you’re not alone. Saying it “improves visibility” or “reduces risk” isn’t enough anymore. You need to show real outcomes, saved hours, reduced incidents, lower cloud costs, and stronger operational resilience. That’s where C…
P0
2025-09-24 18:42 UTC
Vendor Research
Google Online Security Blog · Kimberly Samra · indexed 2026-08-15 14:33 UTC
Posted by Elie Bursztein and Marianna Tishchenko, Google Privacy, Safety and Security TeamEmpowering cyber defenders with AI is critical to tilting the cybersecurity balance back in their favor as they battle cybercriminals and keep users safe. To help accelerate adoption of AI for cybersecurity workflows, we partnered with Airbus at DEF CON 33 to host the GenSec Capture the Flag (CTF), dedicated to human-AI collaboration in cybersecurity. Our goal was to create a fun, interactive environment, …
P0
2025-09-23 09:20 UTC
Other
Red Hunt Labs · redhuntAdmin · indexed 2026-09-07 17:30 UTC
1. Introduction The vibe coding revolution has empowered millions to build and deploy websites using natural languages. Entrepreneurs, artists, and small businesses can now bring their ideas to life online without writing a single line of code. But has this convenience come at a hidden security cost? In this post, we present the 15th wave of Project Resonance: A RedHunt Labs Research Initiative, investigating the security posture of websites built on modern “vibe coding” platforms. Our research…
P0
2025-09-17 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A critical vulnerability discovered in Microsoft's Entra ID (formerly Azure AD) allowed for cross-tenant access and potential global admin privilege escalation. The flaw was found in the legacy Azure AD Graph API, which improperly validated the originating tenant for undocumented "Actor tokens." An attacker could use a token from their own tenant to authenticate as any user, including Global Admins, in any other tenant. This vulnerability bypassed security policies like Conditional Access. The …
P10
2025-09-02 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Don’t fall for common Microsoft 365 identity security myths. Here, Huntress debunks misconceptions around logins, MFA, Conditional Access, Impossible Travel, and security tuning.
P0
2025-08-27 07:50 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
This blog describes attacks on victims in Central Asia and APAC. Research into the attack has identified a group also called YoroTrooper. We also identified profiles of attackers on hacker forums, their malicious web-panels, test infections of attackers' own machines, and screenshots of attackers' desktops.
P0
2025-07-30 04:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Transform raw Windows event data into actionable insights. Learn expert methodologies for intrusion analysis, authentication events, credential dumping, and RDP activity to stay ahead of threats.
P0
2025-07-21 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
**[Mise à jour du 23 juillet 2025]** Le 20 juillet 2025, Microsoft a publié des correctifs pour une vulnérabilité de type limitation insuffisante d'un chemin d'accès à un répertoire restreint, aussi appelé *path traversal*, affectant SharePoint Enterprise Server 2016, SharePoint Server 2019 et...
P0
2025-07-14 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress is collaborating with Microsoft to help your business get the most out of your Microsoft security investments.
P0
2025-07-04 10:59 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Discover how attackers leverage Windows Kernel loaders and abuse digitally signed drivers to gain privileged access, disable security tools, and stealthily maintain control — bypassing traditional defenses and enabling advanced threat operations.
P0
2025-06-30 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Is AI in cybersecurity a tool for defenders or the attackers? Find out in our recap of Huntress’ June Tradecraft Tuesday, where we break it down.
P0