Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Multiple vulnerabilities have been found in the SUSE Linux kernel that could allow remote attackers to cause denial of service, elevate privileges, or execute remote code. The advisory affects SUSE Linux Micro 6.2 and recommends updating from the vendor.
Microsoft attributed a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. The attacks employ custom malware to compromise Microsoft 365 accounts.
Microsoft attributed a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. The attacks employ custom malware to compromise Microsoft 365 accounts.
Sophos Threat Research reports that the GOLD EMBRACE threat actor is abusing multiple legitimate Digital Forensics and Incident Response (DFIR) tools in double-extortion attacks. The misuse of tools such as Volatility and Interlock allows attackers to blend in and evade traditional security defenses.
Security researchers discovered three attacks that enable malware on compromised Windows devices to abuse Google Password Manager's synced passkeys. These attacks can bypass user verification, extract passkey private keys, and take over accounts.
Security researchers discovered three attacks that enable malware on compromised Windows devices to abuse Google Password Manager's synced passkeys. These attacks can bypass user verification, extract passkey private keys, and take over accounts.