Security News

Palo Alto Networks Patches Authentication Bypass Exploit in PAN-OS Software
2025-02-13 09:39

Palo Alto Networks has addressed a high-severity security flaw in its PAN-OS software that could result in an authentication bypass. The vulnerability, tracked as CVE-2025-0108, carries a CVSS...

Fortinet discloses second firewall auth bypass patched in January
2025-02-11 18:56

Fortinet has disclosed a second authentication bypass vulnerability that was fixed as part of a January 2025 update for FortiOS and FortiProxy devices. [...]

7-Zip MotW bypass exploited in zero-day attacks against Ukraine
2025-02-04 14:43

A 7-Zip vulnerability allowing attackers to bypass the Mark of the Web (MotW) Windows security feature was exploited by Russian hackers as a zero-day since September 2024. [...]

Russian Cybercrime Groups Exploiting 7-Zip Flaw to Bypass Windows MotW Protections
2025-02-04 12:28

A recently patched security vulnerability in the 7-Zip archiver tool was exploited in the wild to deliver the SmokeLoader malware. The flaw, CVE-2025-0411 (CVSS score: 7.0), allows remote...

Palo Alto Firewalls Found Vulnerable to Secure Boot Bypass and Firmware Exploits
2025-01-23 15:13

An exhaustive evaluation of three firewall models from Palo Alto Networks has uncovered a host of known security flaws impacting the devices' firmware as well as misconfigured security features....

New 'Sneaky 2FA' Phishing Kit Targets Microsoft 365 Accounts with 2FA Code Bypass
2025-01-17 10:07

Cybersecurity researchers have detailed a new adversary-in-the-middle (AitM) phishing kit that's capable of Microsoft 365 accounts with an aim to steal credentials and two-factor authentication...

New UEFI Secure Boot bypass vulnerability discovered (CVE-2024-7344)
2025-01-16 10:00

ESET researchers have identified a vulnerability (CVE-2024-7344) impacting most UEFI-based systems, which allows attackers to bypass UEFI Secure Boot. The issue was found in a UEFI application...

Fortinet warns of auth bypass zero-day exploited to hijack firewalls
2025-01-14 15:24

​Attackers are exploiting a new authentication bypass zero-day vulnerability in FortiOS and FortiProxy to hijack Fortinet firewalls and breach enterprise networks. [...]

Researchers Expose NonEuclid RAT Using UAC Bypass and AMSI Evasion Techniques
2025-01-08 13:37

Cybersecurity researchers have shed light on a new remote access trojan called NonEuclid that allows bad actors to remotely control compromised Windows systems. "The NonEuclid remote access trojan...

Nuclei flaw lets malicious templates bypass signature verification
2025-01-04 22:59

A now-fixed vulnerability in the open-source vulnerability scanner Nuclei could potentially allow attackers to bypass signature verification while sneaking malicious code into templates that...