Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Apparently, opening the thing is now enough. A repo can run before the first prompt, a package can hide among hundreds, and a harmless-looking PDF can finish the job.
Researchers discovered three WebKit mechanisms that bypass Apple's iCloud Private Relay, exposing user IP addresses and DNS queries. DNS prefetching and WebAuthn or passkey requests are performed outside the normal page loading path, preventing the proxy from hiding IP information.
AI has revealed a browser security gap that enterprises previously overlooked and could ignore. Skyhigh Security explains that browsers have become a critical control point for governing data movement, AI interactions, and modern work.
This article is part two of the RAVEN series, shifting from reconnaissance to exploitation. The authors detail how they leverage gathered information to identify and exploit vulnerabilities in the target system.
This article from Broadcom Symantec examines the detection challenges for MITRE ATT&CK technique T1053.005, which involves abusing scheduled tasks on systems. It highlights the importance of monitoring for unauthorized task creation and provides guidance to close detection gaps.
Google Threat Intelligence Group tracks UNC6671, which uses vishing to target enterprises, posing as IT helpdesk to steal credentials and MFA tokens. They have rebranded under multiple extortion brands and focus on financial services, private equity, and cloud environments.