Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Learn how root access on a compromised K8s node allows attackers to utilize SPIFFE/SPIRE metadata to spoof and harvest co-located workload identities. The post The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE appeared first on Unit 42.
Broadcom/Symantec examines the detection gap in MITRE ATT&CK technique T1047, which covers Windows Management Instrumentation (WMI) for execution. The report highlights how many organizations fail to detect WMI-based attacks despite their prevalence in ransomware and APT campaigns.
Scammers are abusing Metas copyright-reporting system to suspend peoples Instagram accounts and then hold them for ransom, according to the BBC . Criminals file fake copyright complaints with Instagram, claiming that an account is using material it doesnt own.
CISA has added a WatchGuard firewall RCE vulnerability to its Known Exploited Vulnerabilities catalog after confirming it is now being actively exploited in ransomware attacks. The flaw allows remote attackers to execute arbitrary code on unpatched WatchGuard firewalls.
WeLiveSecurity explores GuardBreaker, a technique for derailing AI-assisted malware analysis. The article details how malware authors can craft samples that confuse or evade AI-based analysis tools by exploiting blind spots in machine learning models used for malware classification.
Microsoft has fixed a bug that was wiping Windows desktop settings and customizations for users after installing recent updates. The issue caused desktop icons, wallpaper, and theme settings to reset unexpectedly.