CVE-2024-40766 Is Patched. The Leftover Passwords Still Log In
You patched CVE-2024-40766. The leaked VPN passwords still log in. Here's the cybersecurity cleanup the update never does for you. See the steps.
The Proxy You Forgot Just Leaked User Data
Squidbleed proves the riskiest cybersecurity gaps hide in middleware you forgot you ran. See where to look before attackers do.
usbliter8 Lives In A12 and A13 Silicon. No Patch Is Coming.
usbliter8 can't be patched and a slick IPv6 phish can't be cleanly blocked. See why patch-and-block fails and what cybersecurity controls actually hold.
15,000 Sites Scrubbed, And Your CMS Is Still The Delivery Truck
A SocGholish takedown cleaned 15,000 sites, but your CMS is still a malware delivery truck. Here's how to lock down the web property nobody owns.
You Can’t Fire What You Can’t Name
AI agents are minting credentials at machine speed, and your cybersecurity program isn't tracking them. Here's how to inventory and govern them before one leaks.
Even The Threat Hunters Lost Their Salesforce Data
Klue's breach drained Salesforce data from top cybersecurity firms through OAuth tokens no firewall watches. See how to lock down your integrations.
One Web Page. Your Host Is Theirs.
AutoJack proves localhost is no security boundary when AI agents browse hostile pages. See the cybersecurity controls that actually break the chain.
Millions of TV Boxes Are Laundering Your Attackers’ Traffic
Residential proxy botnets turn home devices into attacker exit nodes and break your firewall. See the cybersecurity controls that still work.
Your AI Scanner Just Refused To Read Malware
Malware now hides prompt injection to fool AI scanners. See why cybersecurity teams must treat analyzed files as hostile input, and how to lock it down.
They Built A Product To Switch Off Your EDR
A ransomware gang now ships an EDR killer that disables 400+ security processes. Here's how to keep your cybersecurity stack from going dark when it counts.
You Copied The Address. The Money Left Anyway
A crypto clipper silently swaps the wallet address you copied, backed by Tor, worms, and fake reviews. See how cybersecurity teams shut it down before payday.
You Bought The Tool. Did You Check It Works?
Your security tools report green while attackers walk past them. The fix isn't buying more cybersecurity gear, it's proving what you own works. See where to start.
Your Attacker Can’t Code. His AI Can.
A low-skilled attacker used AI agents to breach 14 companies, and a fresh VPN credential leak hands the next one a head start. Here's how to slam the door.
RoguePlanet Turns Microsoft Defender Into A SYSTEM Shell
RoguePlanet exploits a Defender race condition for SYSTEM access. See why your cybersecurity tools are the target and how to contain it.
A Dozen Cops Stalked People Using Lawful Access
A dozen cops stalked people with lawful access, and it's a cybersecurity failure your own audit logs are quietly repeating. See how to catch it.
Nothing Hit The Disk. The Credentials Still Walked.
Memory-only malware and poisoned plugins steal credentials without touching disk. See why file-based cybersecurity misses them, and how to defend.
Three FortiSandbox CVEs Are Live, And The Exploit Was Vibecoded
Three live FortiSandbox CVEs, a Vertex AI bucket-squat, and an Android trojan that kills Play Protect all share one weakness. See what to patch first.
The Disk Image That Skated Past Your Scanner
A VHDX file mounted itself and dropped Remcos. Here's why your cybersecurity stack missed it, and what to change this week.
Your CDN Just Pushed Malware To Visitors
A WordPress CDN, an OIDC flow, and an SD-WAN console all got owned this week. The cybersecurity lesson is uncomfortable. See what to do.
Your Inbox Was Forwarding Itself For A Year
UNC6508 spent a year exfiltrating research emails using Workspace forwarding rules. Here's the cybersecurity gap that let it happen, and how to close it.
One Click On microsoft.com. Your Inbox Walked.
SearchLeak proved one click on microsoft.com can drain a Copilot tenant. Here's how to lock down the AI surface your cybersecurity team just bought.
Everything’s Green. So Why Are You Bleeding?
A CISO admits the green-yellow-red dashboard hides the real cybersecurity risks. Hardware backdoors and CI/CD attacks prove it. See what to do next.
Your SOC Closed At Five. Theirs Didn’t.
Adversaries treat Friday evening through Monday morning as prime time. Here's how to close the weekend cybersecurity gap without 24/7 staffing.
Three Cities, Three Keynotes, Zero Tickets Closed
The summer conference circuit is dense, but the patch queue doesn't move on its own. Here's what actually buys down cybersecurity risk this quarter.
A Million Phishing URLs Down. Your Credentials Already Moved.
The FBI nuked a million phishing URLs this week. The credentials already moved. Here's where cybersecurity defenders should actually invest next.
