Uncategorized

Microsoft Entra ID Vulnerability Enables Privilege Escalation to Global Administrator

A critical vulnerability in Microsoft's Entra ID (formerly Azure Active Directory) that allows attackers to escalate privileges and impersonate any…

9 months ago

Cybercriminals Leveraging DNS Gaps to Conceal and Distribute Malware

A sophisticated technique where threat actors are exploiting DNS infrastructure to hide malware and establish persistent command-and-control communications, turning the…

9 months ago

Over 4 Million Internet-Exposed Devices Exploited in Emerging DoS Attacks

A staggering 4.26 million vulnerable Internet-connected devices that can be exploited to launch devastating denial-of-service (DoS) attacks. The comprehensive study,…

9 months ago

Massive Cyberattack Hits Co-op, Exposes Data of 6.5 Million Members

The chief executive of Co-op has confirmed that all 6.5 million of its members had their personal data stolen in…

9 months ago

NVIDIA Container Toolkit Vulnerabilities Enables Attackers to Run Code with Elevated Privileges

NVIDIA has released critical security updates for its Container Toolkit and GPU Operator following the discovery of two high-severity vulnerabilities…

9 months ago

Oracle Cloud Code Editor 1-Click RCE Vulnerability Allows Remote Shell Access via Malicious File Upload

A critical Remote Code Execution (RCE) vulnerability in Oracle Cloud Infrastructure's (OCI) Code Editor that enabled attackers to silently hijack…

9 months ago

DNS Queries Abused by Hackers for Stealthy C2 and Data Exfiltration

Cybercriminals are increasingly exploiting the Domain Name System (DNS) - often called the "phonebook of the internet" - to conduct…

9 months ago

SharePoint RCE Vulnerability Exploited via Malicious XML in Web Part

A serious remote code execution vulnerability has been discovered in Microsoft SharePoint that allows attackers to execute arbitrary code through…

9 months ago

Hackers Exploited CitrixBleed 2 Vulnerability Ahead of Public PoC Release

The vulnerability, designated CVE-2025-5777 and dubbed "CitrixBleed 2," represents a significant security concern for organizations relying on Citrix infrastructure. Cybersecurity…

9 months ago

Cisco Intelligence Center Vulnerability Enables Remote File Upload Attacks

Cisco disclosed a critical weakness within the web-based management interface of its Unified Intelligence Center (CUIC) that can be exploited…

9 months ago