New “Pass-the-Passkey” Technique Shows How Windows 11 Logs Undermined Phishing-Resistant MFA
Security researchers at SpecterOps have detailed a family of attacks called Pass-the-Passkey that exploit how Windows 11 logged WebAuthn authentication data and how Microsoft Entra ID validated it,...
Gunra Ransomware Gang Turns Fortinet VPN Bugs Into a Backdoor Around MFA
A joint advisory from the FBI, CISA, NSA, and South Korean authorities warns that the Gunra ransomware operation is exploiting known Fortinet VPN flaws to sidestep multi-factor authentication...
An AI Assistant Bumped a Stranger Off a Gym Waitlist — and Nobody Told It To
In what's being called Australia's first known autonomous AI cyberattack, a Claude-powered personal assistant discovered it could cancel other members' gym bookings through an unprotected API — and...
Microsoft Is Giving Teams Admins a Single Dashboard to Catch Phishing and Malware in Chats
Microsoft is rolling out a new Security Detection Report inside the Teams admin center that consolidates impersonation attempts, malicious links, and dangerous file types into one exportable dashboard....
Maximum-Severity Metabase Zero-Day Let Attackers Walk Into Admin Accounts Unauthenticated
A CVSS 10.0 SQL injection flaw in Metabase's password-reset endpoint was actively exploited to hand attackers full admin control without a login. Metabase Cloud was breached before a...
Hackers Are Turning Plain CSS Into Keyloggers Hidden Inside Everyday Emails
Security researcher Gareth Heyes has demonstrated that ordinary CSS styling code, not JavaScript or malware, can be weaponized to hijack webmail interfaces and capture passwords keystroke by keystroke....
Zapscape Flaw Lets a Rogue Cloud Virtual Machine Seize Root on Its Host Server
A Linux kernel vulnerability nicknamed Zapscape and tracked as CVE-2026-64561 allows a malicious KVM guest running nested virtualization to escape its virtual machine entirely and take root control...
Researchers Show How Malware Can Hijack Windows Hello Keys to Slip Into Microsoft Entra ID
New research demonstrates that malware running inside an active, unlocked Windows session can abuse Windows Hello for Business cryptographic keys to authenticate to Microsoft Entra ID, without ever...