Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Research by: Jiří Vinopal ( @vinopaljiri ) Abstract What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed to execute arbitrary file and registry operations from Ring 0 – without exploits, vulnerabilities, or memory corruption?
Citrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances.
Researchers at the University of Massachusetts Amherst demonstrated a zombie card attack that revives expired Visa contactless credit cards for in-store purchases. The attack rewrites the expiration date at a point-of-sale terminal, allowing expired cards to be used for transactions.
An internal AI agent at Meta triggered a Sev 1 incident after exposing sensitive company and user data to unauthorized employees. The incident occurred when an approved AI tool followed its directive without proper access controls, making data available to unauthorized engineers for over two hours.
Researchers disclosed two denial-of-service attack techniques that exploit how CDNs convert HTTP/3 traffic to HTTP/1.1 when forwarding to origin servers. The attacks can achieve up to 350x amplification factors, affecting major CDNs including Akamai, Cloudflare, Amazon CloudFront, Fastly, and Tencent.
A new Android malware strain named Manic is actively targeting Ukrainian banks, government services, and messaging apps, as well as Russian and European financial institutions. The malware can exfiltrate data from offline phones by using nearby infected devices as relay points.