Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
From Misconfigured Spring Boot Actuator to SharePoint Exfiltration: How Stolen Credentials Bypass MFA. Not every cloud breach starts with malware or a zero-day. In this incident, attackers discovered an exposed Spring Boot Actuator endpoint, harvested credentials from leaked configuration data, then used the OAuth2 Resource Owner Password Credentials (ROPC) flow to authenticate without MFA. Organizations should treat this as an active threat and take immediate defensive action.
Not every cloud breach starts with malware or a zero-day.
Learn how east-west traffic visibility helps detect and stop lateral movement attacks inside electric grid infrastructure and critical OT networks.
Why East-West Visibility Matters for Grid Security. Learn how east-west traffic visibility helps detect and stop lateral movement attacks inside electric grid infrastructure and critical OT networks.
Why East-West Visibility Matters for Grid Security. Learn how east-west traffic visibility helps detect and stop lateral movement attacks inside electric grid infrastructure and critical OT networks.
The Warlock threat group has enhanced its attack chain with new tactics, including TightVNC remote access, Yuze tunneling tools, and a persistent Bring Your Own Vulnerable Driver (BYOVD) technique exploiting the NSec driver. These additions improve the group's ability to maintain persistence, move laterally, and evade defensive measures.