Security News

QR codes bypass browser isolation for malicious C2 communication
2024-12-08 15:27

Mandiant has identified a novel method to bypass contemporary browser isolation technology and achieve command-and-control C2 operations. [...]

PoC exploit chains Mitel MiCollab 0-day, auth-bypass bug to access sensitive files
2024-12-06 06:01

Still unpatched 100+ days later, watchTowr says A zero-day arbitrary file read vulnerability in Mitel MiCollab can be chained with a now-patched critical bug in the same platform to give attackers...

65% of office workers bypass cybersecurity to boost productivity
2024-12-04 04:00

High-risk access exists throughout the workplace, in almost every job role, proving that the time has come for organizations to re-think the way they protect their workforce, according to...

Phishers send corrupted documents to bypass email security
2024-12-03 12:04

Phishers have come up with a new trick for bypassing email security systems: corrupted MS Office documents. The spam campaign Malware hunting service Any.Run has warned last week about email...

Researchers Uncover Malware Using BYOVD to Bypass Antivirus Protections
2024-11-25 09:16

Cybersecurity researchers have uncovered a new malicious campaign that leverages a technique called Bring Your Own Vulnerable Driver (BYOVD) to disarm security protections and ultimately gain...

North Korean hackers create Flutter apps to bypass macOS security
2024-11-12 13:00

North Korean threat actors target Apple macOS systems using trojanized Notepad apps and minesweeper games created with Flutter, which are signed and notarized by legitimate Apple developer IDs. [...]

Why the long name? Okta discloses auth bypass bug affecting 52-character usernames
2024-11-04 11:28

Mondays are for checking months of logs, apparently, if MFA's not enabled In potentially bad news for those with long names and/or employers with verbose domain names, Okta spotted a security hole...

Threat actors are stepping up their tactics to bypass email protections
2024-11-01 04:30

Although most organizations use emails with built-in security features that filter out suspicious messages, criminals always find a way to bypass these systems. With the development of AI...

New Windows Driver Signature bypass allows kernel rootkit installs
2024-10-26 12:28

Attackers can downgrade Windows kernel components to bypass security features such as Driver Signature Enforcement and deploy rootkits on fully patched systems. [...]

Intel, AMD CPUs on Linux impacted by newly disclosed Spectre bypass
2024-10-18 14:48

The latest generations of Intel processors, including Xeon chips, and AMD's older Zen 1, Zen 1+, and Zen 2 microarchitectures on Linux are vulnerable to new speculative execution attacks that...