The Week Defender Was The Privilege Escalation
Defender zero-days and a nine-year Linux kernel bug both handed attackers SYSTEM. See what cybersecurity teams should change this week.
Defender zero-days and a nine-year Linux kernel bug both handed attackers SYSTEM. See what cybersecurity teams should change this week.
TamperedChef and the npm Shai-Hulud lineage prove search results and package registries now ship malware. Here's the cybersecurity playbook that holds up.
One Odesa teenager allegedly harvested 28,000 accounts with off-the-shelf infostealers. Here's why your stack misses it, and what to fix now.
Grafana rotated tokens after TanStack and still got breached. Here's the cybersecurity lesson on token inventory. Tighten yours before you need it.
GitHub lost 3,800 repos to a poisoned VS Code extension on one employee laptop. Here's the cybersecurity fix every dev shop needs now.
Luxembourg's whole telecom network died from one Huawei zero-day. Verizon says patching got 34% slower. See what to fix first.
Microsoft disrupted Fox Tempest's malware-signing-as-a-service. Here's what it means for your cybersecurity trust model, and how to adjust.
A compromised VS Code extension reached 2.2M developer machines. See what the Nx Console and TeamPCP incidents demand from your cybersecurity playbook now.
Storm-2949 breached a cloud tenant with zero malware. Your EDR never saw it. See what to harden this week before the next stolen token lands.
CISA's own contractor pushed GovCloud keys to public GitHub. Here's why your secret scanner won't save you and what to fix this week.