Fake Teams Help-Desk Calls Turn Remote Support Into a Path Toward Domain Control
A campaign dubbed Spring Ring used external Microsoft Teams accounts and convincing help-desk calls to push remote-access tools and malware. In some cases, the attackers progressed toward SMB...
Boston Scientific Cyber Incident Disrupts Manufacturing and Device Shipments
Boston Scientific is recovering from a cyber incident that interrupted on-premises systems supporting manufacturing, order processing and product shipments. The company says connected devices and previously enrolled remote...
Critical Artifactory Bypass Is Being Used to Mint Administrator Tokens
A critical JFrog Artifactory authentication bypass is under active exploitation, with attackers reportedly creating administrator tokens on vulnerable servers. Self-hosted customers should upgrade immediately, revoke suspicious credentials and...
Attackers Exploit Critical Langflow and Rails Flaws to Hunt Cloud Secrets
Attackers are actively exploiting critical flaws in Langflow and Ruby on Rails, with observed activity focused on credentials, application secrets and paths to remote code execution. Defenders should...
D-Link Fixes Router Flaws That Exposed Admin and Wi-Fi Credentials on Local Networks
D-Link has patched access-control failures in the DIR-X1860Z that could let an unauthenticated local attacker reset the administrator password and retrieve wireless credentials. Owners should install the corrected...
BGP Hijack Poisoned Virtualizor Updates and Put Hosting Servers at Root-Level Risk
A routing hijack diverted Softaculous infrastructure and enabled a malicious Virtualizor update to reach a small number of hosting servers. Because update packages lacked cryptographic verification, valid TLS...
ValleyRAT Campaign Turns Fake Adware Installers Into a Persistent Espionage Backdoor
A ValleyRAT campaign is disguising its infection chain as adware and familiar software installers, with most observed victims in China and India. The backdoor uses DLL sideloading and...
Public HardBreacher Code Claims Kaspersky Privilege Escalation, but Evidence Remains Unverified
A public proof of concept called HardBreacher claims a local privilege-escalation weakness in Kaspersky Endpoint Security on Windows 11. The report remains unconfirmed, has no CVE, and is...