Security News

New 'Sneaky 2FA' Phishing Kit Targets Microsoft 365 Accounts with 2FA Code Bypass
2025-01-17 10:07

Cybersecurity researchers have detailed a new adversary-in-the-middle (AitM) phishing kit that's capable of Microsoft 365 accounts with an aim to steal credentials and two-factor authentication...

New UEFI Secure Boot bypass vulnerability discovered (CVE-2024-7344)
2025-01-16 10:00

ESET researchers have identified a vulnerability (CVE-2024-7344) impacting most UEFI-based systems, which allows attackers to bypass UEFI Secure Boot. The issue was found in a UEFI application...

Fortinet warns of auth bypass zero-day exploited to hijack firewalls
2025-01-14 15:24

​Attackers are exploiting a new authentication bypass zero-day vulnerability in FortiOS and FortiProxy to hijack Fortinet firewalls and breach enterprise networks. [...]

Researchers Expose NonEuclid RAT Using UAC Bypass and AMSI Evasion Techniques
2025-01-08 13:37

Cybersecurity researchers have shed light on a new remote access trojan called NonEuclid that allows bad actors to remotely control compromised Windows systems. "The NonEuclid remote access trojan...

Nuclei flaw lets malicious templates bypass signature verification
2025-01-04 22:59

A now-fixed vulnerability in the open-source vulnerability scanner Nuclei could potentially allow attackers to bypass signature verification while sneaking malicious code into templates that...

Researchers Uncover Nuclei Vulnerability Enabling Signature Bypass and Code Execution
2025-01-04 14:29

A high-severity security flaw has been disclosed in ProjectDiscovery's Nuclei, a widely-used open-source vulnerability scanner that, if successfully exploited, could allow attackers to bypass...

Apache fixes remote code execution bypass in Tomcat web server
2024-12-23 12:33

Apache has released a security update that addresses an important vulnerability in Tomcat web server that could lead to an attacker achieving remote code execution. [...]

Ongoing phishing attack abuses Google Calendar to bypass spam filters
2024-12-18 23:16

An ongoing phishing scam is abusing Google Calendar invites and Google Drawings pages to steal credentials while bypassing spam filters. [...]

Researchers Uncover Symlink Exploit Allowing TCC Bypass in iOS and macOS
2024-12-12 12:35

Details have emerged about a now-patched security vulnerability in Apple's iOS and macOS that, if successfully exploited, could sidestep the Transparency, Consent, and Control (TCC) framework and...

Ivanti warns of maximum severity CSA auth bypass vulnerability
2024-12-10 19:40

Ivanti warned customers on Tuesday about a new maximum-severity authentication bypass vulnerability in its Cloud Services Appliance (CSA) solution. [...]