Aggregator
Digital Triage and the Rules of Evidence: What Holds Up, and Where
Akamai Recognized as a Customers’ Choice in the 2026 Gartner® Peer Insights™ Voice of the Customer for Edge Distribution Platforms
FBI Warns of Deepfake Videos Impersonating IC3 Leadership
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2021-27137 DD-WRT Stack-Based Buffer Overflow Vulnerability
- CVE-2026-0770 Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
- CVE-2026-63030 WordPress Core Interpretation Conflict Vulnerability
- CVE-2026-60137 WordPress Core SQL Injection Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.
While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
bypass the Substack Paywall?
New ClickLock Stealer locks your Mac until you hand over your password
Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs
Microsoft Defender XDR Blind Spot Lets Public C2 Traffic Evade Detection Queries
Microsoft Defender XDR users may inadvertently overlook command-and-control (C2) traffic when searching for Internet-bound connections due to a specific behavior in how IP addresses are classified. This issue arises from Kusto Query Language (KQL) detections that depend solely on filtering by RemoteIPType == “Public” in the DeviceNetworkEvents table. As a result, traffic destined for public […]
The post Microsoft Defender XDR Blind Spot Lets Public C2 Traffic Evade Detection Queries appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
使用Memfit复现最新的Fastjson远程代码执行漏洞
Settra
You must login to view this content
Hackers Use Cruciferra Crypter to Disable EDR and Deploy XWorm, Remcos, and AsyncRAT
Hackers are abusing the Cruciferra crypter-as-a-service to systematically turn off endpoint detection and response (EDR) tools and stealthily deploy XWorm, Remcos, AsyncRAT, and other commodity malware in email-driven campaigns targeting multiple sectors worldwide. By combining BYOVD-based driver abuse, indirect syscalls and a polymorphic encryption engine with more than 90 mix-and-match crypto routines, Cruciferra has rapidly […]
The post Hackers Use Cruciferra Crypter to Disable EDR and Deploy XWorm, Remcos, and AsyncRAT appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
N-day is Becoming N-Hour. Patching Faster Won't Save You.
Hackers Hide Malware Commands in Outlook Events Dated 2050 and Use as C2 Channel
A newly identified malware component linked to the Project CAV3RN framework is abusing Microsoft Outlook calendar events scheduled for 2050 to conceal command-and-control (C2) traffic. The tool also uses DNS AAAA responses as a fallback channel to restore Microsoft Graph credentials when cloud authentication fails. Kaspersky researchers have associated the activity with highly targeted cyberespionage […]
The post Hackers Hide Malware Commands in Outlook Events Dated 2050 and Use as C2 Channel appeared first on Cyber Security News.
Смотрели ЧМ-2026 на пиратском сайте? Возможно, заодно кто-то похищал ваши данные карты
Don’t trust that “FBI agent” in your DMs
New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit
Akira
You must login to view this content
Black X
You must login to view this content
Space Bears
You must login to view this content