Aggregator
Public PoC Released for Windows NT OS Kernel Privilege Escalation Vulnerability
Public proof-of-concept (PoC) exploit code was released for CVE-2026-42980, a local privilege escalation vulnerability in the Windows NT OS Kernel. This vulnerability occurs due to an integer underflow in kernel-mode code. CVE-2026-42980 is an elevation-of-privilege flaw in the Windows NT OS Kernel caused by an integer underflow (wraparound) condition in a kernel code path. This […]
The post Public PoC Released for Windows NT OS Kernel Privilege Escalation Vulnerability appeared first on Cyber Security News.
Hackers Let Victims Complete MFA Then Steal the Entire Microsoft 365 Session
Multi-factor authentication is meant to stop stolen-password attacks. A newly documented phishing technique instead persuades users to approve a real Microsoft sign-in, allowing attackers to take over the resulting Microsoft 365 session without directly stealing credentials. The campaign abuses the OAuth device-code flow, a feature intended for devices such as smart TVs and meeting-room systems […]
The post Hackers Let Victims Complete MFA Then Steal the Entire Microsoft 365 Session appeared first on Cyber Security News.
Kali365 Phishing Kit Abuses Microsoft Device Codes to Hijack Microsoft 365 Accounts
A phishing kit known as Kali365 is targeting U.S. organizations through device code phishing attacks that abuse Microsoft’s legitimate authentication process to hijack Microsoft 365 accounts. Unlike conventional phishing campaigns that direct targets to counterfeit login portals, Kali365 sends victims to a real Microsoft Device Login page. Victims are persuaded to enter an attacker-provided device […]
The post Kali365 Phishing Kit Abuses Microsoft Device Codes to Hijack Microsoft 365 Accounts appeared first on Cyber Security News.
What 434 AI-Generated Vulnerabilities Reveal About Secure Software Development
New research finds that modern AI coding models frequently generate insecure code that exposes AI-generated applications to denial-of-service attacks, hardcoded secrets and authorization failures. The rapid adoption of AI coding assistants has transformed software development, enabling developers to generate production-ready applications in minutes rather than days. But as organizations increasingly rely on AI-generated code, a […]
The post What 434 AI-Generated Vulnerabilities Reveal About Secure Software Development appeared first on Cyber Security News.
Представьте: герои комикса стоят прямо у вас за спиной, а реплики появляются, если вы на них посмотрите. Нужно только надеть шлем
Bebunk Database Allegedly Leaked, 12,324 Banking Customers With IBANs and KYC Records Exposed
Iranian Hackers Are Quietly Building Access They Can Turn Into Wartime Disruption
Iran-linked hackers are not relying only on loud attacks, public leaks, or website defacements. They are quietly building access inside companies, cloud accounts, service providers, and industrial networks that could later be used to disrupt operations during a crisis. The activity includes stolen credentials, remote management tools, recruitment-themed phishing, and attacks on exposed industrial systems. […]
The post Iranian Hackers Are Quietly Building Access They Can Turn Into Wartime Disruption appeared first on Cyber Security News.
Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack
数学家仍然不知道乘法的最快方法
RevolutionParts Database Allegedly Leaked, 5.1 Million Customer Records Posted for Free
New Kimsuky campaign compromised South Korean software vendors
White House accuses Chinese company of distilling Anthropic’s Fable
While distillation attacks by foreign governments and companies have real national security implications, questions around who ultimately owns the data in AI systems are fraught.
The post White House accuses Chinese company of distilling Anthropic’s Fable appeared first on CyberScoop.
Месяцы обучения — и $500000 на восстановление. Вот что теряют компании после атаки JADEPUFFER
Apple Releases Fixes for Hide My Email Flaw that Exposes Users’ Real Email Addresses
Apple has released a security fix addressing a critical flaw in its iCloud+ “Hide My Email” feature that could expose users’ real email addresses, undermining the core privacy promise of the service. The vulnerability, which reportedly remained unresolved for over a year, allowed attackers to determine a user’s actual email address from an anonymized alias […]
The post Apple Releases Fixes for Hide My Email Flaw that Exposes Users’ Real Email Addresses appeared first on Cyber Security News.