-
Microsoft will make passkeys the default authentication experience in Entra ID beginning September 1, 2026, and will fully retire its native SMS and voice multifactor authentication (MFA) delivery services on February 1, 2027. According to Microsoft, t…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly disclosed universal deserialization gadget chain shows how a single unsafe Marshal.load operation can reportedly produce remote command execution in Ruby 4.0.6, underscoring the persistent danger of exposing Ruby’s native serialization mechanis…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly disclosed Windows attack technique, dubbed “Download More RAM,” can undermine Virtualization-Based Security (VBS), bypass Hypervisor-Protected Code Integrity (HVCI), and disable endpoint protections including Microsoft Defender and third-party …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Microsoft is reshaping its consumer and productivity AI strategy with a major update to its Copilot application, merging personal chat histories and generated content while discontinuing several prominent capabilities. The changes affect consumer users…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Four incidents involving OpenAI, Anthropic, Meta and the UK AI Security Institute (AISI) describe AI agents reaching systems belonging to other organizations without their consent. The defining capability is now persistence: models can repeatedly test …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly disclosed, unpatched SQL injection vulnerability in GeoServer is currently being actively tested across the internet. Researchers have issued warnings that affected deployments may be vulnerable to remote code execution (RCE) under specific dat…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The Dysphoria botnet has expanded into a major Internet of Things threat, with a new Shadowserver Special Report identifying approximately 296,000 compromised devices. The campaign targets exposed routers, gateways, IP cameras and other embedded Linux …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly analyzed DarkCrystal RAT (DCRat) campaign shows how threat actors are turning an apparently harmless SVG attachment into a full malware-delivery mechanism. The operation, investigated by the Trellix Advanced Research Center (ARC) following a cu…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A growing underground market is turning mature malware-evasion techniques into subscription products. An analysis of 24 active crypting-service vendors shows that customers can now buy payload obfuscation, in-memory execution, anti-analysis controls, p…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researchers have introduced a new technique called “Bring Your Own EDR” (BYOEDR) that exploits legitimate SentinelOne components to bypass Windows Protected Process Light (PPL) protections, allowing the execution of unsigned code within highly…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


