Russian Hackers Exploit Exchange OWA Zero-Day to Deploy OWAReaper Backdoor
Laundry Bear is exploiting a zero-day XSS flaw in Exchange OWA to deploy the OWAReaper backdoor, enabling persistent mailbox access that survives credential res
Laundry Bear is exploiting a zero-day XSS flaw in Exchange OWA to deploy the OWAReaper backdoor, enabling persistent mailbox access that survives credential res
Check Point has patched three vulnerabilities, including a critical actively exploited authentication bypass in SmartConsole. CISA has added the flaw to its KEV
Google has introduced an opt-in selfie video feature for account recovery. It uses facial comparison to verify identity when users are locked out.
IRIS C2, a startup offering up to $7M for zero-day exploits, is run by Jack Burkman and Jacob Wohl—convicted felons with a history of fraud and fabrication.
CISA has added a high-severity Microsoft SharePoint RCE flaw to its KEV catalog. Federal agencies must patch by Saturday under BOD 26-04.
The AryStinger botnet has compromised over 4,000 outdated routers, converting them into proxies for scanning, tunneling, and malicious traffic operations.
Group-IB researchers detail how Sniper DZ campaigns targeted MENA users through fake Facebook accounts, browser notification abuse, and traffic monetization sch
ESET researchers document new FrostyNeighbor cyberespionage activity targeting Ukrainian governmental organizations, featuring an updated JavaScript-based compr
Smart glasses can record and identify people without their knowledge. Here's what wearers and bystanders can do to reduce the risks.
Nmap is more than an attacker's tool. Defenders can use it to audit assets, spot rogue devices, and verify firewall rules.
Pi-hole intercepts DNS queries network-wide, blocking ads and trackers before they load. Here's how it works and what it can't do.
Burp Suite Community Edition is free but deliberately limited. Here's what you can realistically do with it and where it stops.