Security News Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication TheHackerNews
Security News N-central Attackers Reach Managed Systems and Persist After Server Access Is Revoked TheHackerNews
Security News Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts TheHackerNews
Security News Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer TheHackerNews
Security News 18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers TheHackerNews
Security News Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails TheHackerNews
Security News AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day TheHackerNews
Security News New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables TheHackerNews
Security News Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access TheHackerNews
Security News Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets TheHackerNews
Security News TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign TheHackerNews
Security News OpenAI rolls out a major ChatGPT upgrade, even if you don’t pay for it BleepingComputer
Security News Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group BleepingComputer