Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
An actively exploited authentication bypass vulnerability in N-able N-central allows remote unauthenticated attackers to obtain administrative access to vulnerable servers. Attackers then use the Take Control functionality to connect to managed Windows endpoints and register Cloudflare tunnels for persistent access.
Apple is reportedly launching a new legal challenge to British demands for ways around its Advanced Data Protection feature. The company seeks to protect user iCloud accounts from government access, continuing a privacy dispute.
A misconfiguration in Google Firebase allowed users of the AI meeting tool tl;dv to query other users' meeting information and potentially join calls. This vulnerability puts government and corporate video call security at risk.
A misconfigured Google Firebase instance allowed users of the AI meeting tool tl;dv to query any other user's meeting information and potentially join calls. This vulnerability put sensitive government and corporate video conversations at risk.
A misconfigured Google Firebase instance allowed users of the AI meeting tool tl;dv to query any other user's meeting information and potentially join calls. This vulnerability put sensitive government and corporate video conversations at risk.
FortiGuard Labs analyzed a QuickFox supply chain attack that distributed trojanized Windows installers to deploy the FDMTP implant with selective targeting. The implant evolved to avoid detection, highlighting the sophistication of modern supply chain threats.