Security News

Researchers Find Exploit Allowing NTLMv1 Despite Active Directory Restrictions
2025-01-16 11:20

Cybersecurity researchers have found that the Microsoft Active Directory Group Policy that's designed to disable NT LAN Manager (NTLM) v1 can be trivially bypassed by a misconfiguration. "A simple...

Researcher Uncovers Critical Flaws in Multiple Versions of Ivanti Endpoint Manager
2025-01-16 06:39

Ivanti has rolled out security updates to address several security flaws impacting Avalanche, Application Control Engine, and Endpoint Manager (EPM), including four critical bugs that could lead...

Google Cloud Researchers Uncover Flaws in Rsync File Synchronization Tool
2025-01-15 12:26

As many as six security vulnerabilities have been disclosed in the popular Rsync file-synchronizing tool for Unix systems, some of which could be exploited to execute arbitrary code on a client....

Google Project Zero Researcher Uncovers Zero-Click Exploit Targeting Samsung Devices
2025-01-10 15:39

Cybersecurity researchers have detailed a now-patched security flaw impacting Monkey's Audio (APE) decoder on Samsung smartphones that could lead to code execution. The high-severity...

Researchers Expose NonEuclid RAT Using UAC Bypass and AMSI Evasion Techniques
2025-01-08 13:37

Cybersecurity researchers have shed light on a new remote access trojan called NonEuclid that allows bad actors to remotely control compromised Windows systems. "The NonEuclid remote access trojan...

Researchers Uncover Major Security Flaw in Illumina iSeq 100 DNA Sequencers
2025-01-07 14:22

Cybersecurity researchers have uncovered firmware security vulnerabilities in the Illumina iSeq 100 DNA sequencing instrument that, if successfully exploited, could permit attackers to brick or...

Researchers Uncover Nuclei Vulnerability Enabling Signature Bypass and Code Execution
2025-01-04 14:29

A high-severity security flaw has been disclosed in ProjectDiscovery's Nuclei, a widely-used open-source vulnerability scanner that, if successfully exploited, could allow attackers to bypass...

Researchers Uncover PyPI Packages Stealing Keystrokes and Hijacking Social Accounts
2024-12-24 13:22

Cybersecurity researchers have flagged two malicious packages that were uploaded to the Python Package Index (PyPI) repository and came fitted with capabilities to exfiltrate sensitive information...

Researchers reveal OT-specific malware in use and in development
2024-12-17 14:29

Malware that’s made specifically to target industrial control systems (ICS), Internet of Things (IoT) and operational technology (OT) control devices is still rare, but in the last few weeks...

MUT-1244 targeting security researchers, red teamers, and threat actors
2024-12-16 15:32

A threat actor tracked as MUT-1244 by DataDog researchers has been targeting academics, pentesters, red teamers, security researchers, as well as other threat actors, in order to steal AWS access...