Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
AWS announces the availability of the latest IRAP Phase 1a report on AWS Artifact. The report adds four new services assessed at the PROTECTED level, bringing the total to 167.
This article discusses a high-severity vulnerability in Microsoft Active Directory Certificate Services that allows privilege escalation. Microsoft has released a patch to address the issue, which could enable attackers to compromise an AD environment.
This article reports on a high-severity vulnerability in Microsoft Active Directory certificates, dubbed 'Certighost'. The flaw enables threat actors to escalate privileges and compromise an AD environment.
Microsoft patched a high-severity vulnerability in Active Directory Certificate Services (AD CS) that could enable attackers to conduct certificate-based attacks against domain environments. The Certighost flaw, as it came to be known, threatened the foundation of certificate-based authentication in Active Directory, potentially allowing adversaries to forge certificates, escalate privileges, or impersonate domain entities.
Microsoft patched a high-severity vulnerability in Active Directory Certificate Services (AD CS) that could enable attackers to conduct certificate-based attacks against domain environments. The Certighost flaw, as it came to be known, threatened the foundation of certificate-based authentication in Active Directory, potentially allowing adversaries to forge certificates, escalate privileges, or impersonate domain entities.
A new Mirai-derived botnet named Tengu has been discovered targeting Linux devices, using a hardware watchdog to reboot compromised systems if defenders attempt to terminate its main process. This persistence mechanism allows Tengu to relaunch itself, alongside other techniques like creating fake systemd services, modifying shell startup files, and altering reboot utilities.