Security News

Microsoft wouldn't look at a bug report without a video. Researcher maliciously complied
2025-03-17 09:30

Maddening techno loop, Zoolander reference, and 14 minutes of time wasted A vulnerability analyst and prominent member of the infosec industry has blasted Microsoft for refusing to look at a bug...

Google paid $12 million in bug bounties last year to security researchers
2025-03-10 15:36

Google paid almost $12 million in bug bounty rewards to 660 security researchers who reported security bugs through the company's Vulnerability Reward Program (VRP) in 2024. [...]

Researchers Expose New Polymorphic Attack That Clones Browser Extensions to Steal Credentials
2025-03-10 14:47

Cybersecurity researchers have demonstrated a novel technique that allows a malicious web browser extension to impersonate any installed add-on. "The polymorphic extensions create a pixel perfect...

Researchers Link CACTUS Ransomware Tactics to Former Black Basta Affiliates
2025-03-04 16:21

Threat actors deploying the Black Basta and CACTUS ransomware families have been found to rely on the same BackConnect (BC) module for maintaining persistent control over infected hosts, a sign...

Twin Google flaws allowed researcher to get from YouTube ID to Gmail address in a few easy steps
2025-02-17 02:25

PLUS: DOGE web design disappoints; FBI stops crypto scams; Zacks attacked again; and more! Infosec In Brief A security researcher has found that Google could leak the email addresses of YouTube...

Researchers Find New Exploit Bypassing Patched NVIDIA Container Toolkit Vulnerability
2025-02-12 14:04

Cybersecurity researchers have discovered a bypass for a now-patched security vulnerability in the NVIDIA Container Toolkit that could be exploited to break out of a container's isolation...

Researchers Find Exploit Allowing NTLMv1 Despite Active Directory Restrictions
2025-01-16 11:20

Cybersecurity researchers have found that the Microsoft Active Directory Group Policy that's designed to disable NT LAN Manager (NTLM) v1 can be trivially bypassed by a misconfiguration. "A simple...

Researcher Uncovers Critical Flaws in Multiple Versions of Ivanti Endpoint Manager
2025-01-16 06:39

Ivanti has rolled out security updates to address several security flaws impacting Avalanche, Application Control Engine, and Endpoint Manager (EPM), including four critical bugs that could lead...

Google Cloud Researchers Uncover Flaws in Rsync File Synchronization Tool
2025-01-15 12:26

As many as six security vulnerabilities have been disclosed in the popular Rsync file-synchronizing tool for Unix systems, some of which could be exploited to execute arbitrary code on a client....

Google Project Zero Researcher Uncovers Zero-Click Exploit Targeting Samsung Devices
2025-01-10 15:39

Cybersecurity researchers have detailed a now-patched security flaw impacting Monkey's Audio (APE) decoder on Samsung smartphones that could lead to code execution. The high-severity...