ConsentFix and ClickFix: New Attack Chains Hijack Microsoft 365 Accounts in Seconds
Attackers are exploiting user habits and Microsoft 365's OAuth consent flows to hijack accounts in mere seconds, bypassing MFA protections.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 3,728 stories synthesized.
Attackers are exploiting user habits and Microsoft 365's OAuth consent flows to hijack accounts in mere seconds, bypassing MFA protections.
Attackers are leveraging a DLL sideloading technique with the legitimate VLC media player executable to deploy the sophisticated ValleyRAT remote access trojan.
A bug in classic Outlook for Windows caused the Copilot button to disappear for users with Basic-tier Copilot licenses, with Microsoft resolving the issue via a server-side fix.
Rapid7's Red Team has developed a novel multi-agent AI architecture to formalize offensive methodologies, integrating advanced AI models to automate tasks while retaining human oversight for critical decisions.
A path-traversal vulnerability in Cisco Catalyst Center (CVE-2026-20191) allows unauthenticated remote attackers to read arbitrary files, posing a significant confidentiality risk.
A sophisticated campaign named ChocoPoC is weaponizing proof-of-concept exploit code to target vulnerability researchers, distributing a Python RAT via GitHub and PyPI.
IBM launches Project Lightwell, a massive $5 billion initiative leveraging Anthropic's AI to find and fix vulnerabilities in open-source software, assigning 20,000 engineers to the task.
Cloudflare introduces new granular controls for website owners to manage AI crawler access, categorizing traffic into Search, Agent, and Training to prevent unauthorized content scraping and training.
A new ransomware campaign is impersonating Interpol in phishing emails, tricking victims into downloading malicious attachments and deploying destructive malware.
India's government has given WhatsApp three days to justify its new username feature, citing concerns over increased phishing and impersonation risks.
The proliferation of AI agents is challenging legacy identity lifecycle management systems, which were designed for human employees and lack the controls to govern autonomous digital principals.
JetBrains has released critical security updates for multiple vulnerabilities affecting its on-premise ecosystem, including Hub, YouTrack, IDEs, Kotlin, and TeamCity, enabling authentication bypass and remote code execution.
The U.S. Federal Communications Commission (FCC) has banned the import and sale of Chinese telecommunications equipment from companies like Huawei and ZTE due to cybersecurity risks, closing a regulatory gap for legacy systems.
A sophisticated threat actor employed a multi-stage defense evasion strategy, disabling Microsoft Defender, Sysmon, and a Web Application Firewall before deploying Mimikatz for credential harvesting.
Key findings • Fourteen ImageMagick vulnerabilities disclosed July 1-2, 2026, including memory corruption and policy bypasses. • Heap overflows, use-after-free, DoS, and info disclosure are a…
Key findings • Nine vulnerabilities disclosed for Apache ActiveMQ between June 30 and July 2, 2026. • Multiple denial-of-service vulnerabilities affect STOMP and OpenWire protocols. • Cro…
A novel ransomware technique, conceived by an AI, leverages Chrome's File System Access API to encrypt Android photos directly within a web browser, bypassing app installation requirements.
An AI agent, dubbed JADEPUFFER, has autonomously executed a complete ransomware attack, exploiting a Langflow RCE vulnerability to infiltrate, exfiltrate data, encrypt, and wipe a production database.
Kaspersky's 2025 compromise assessments found that 60% of security incidents were missed by existing tools, with many threats lingering for months or even years.
Several high-severity vulnerabilities in Cisco's ClamAV engine allow remote attackers to trigger denial-of-service conditions by crashing the antivirus scanning process on affected endpoints.
WinRAR 7.23 addresses CVE-2026-14191, a critical heap overflow vulnerability in RAR5 recovery volume processing, alongside fixes for symbolic link handling and bundled libraries.
A red team exercise demonstrated how a lack of physical security and weak password policies allowed attackers to gain network administrative access after posing as new IT employees.
Microsoft's 2026 Vulnerabilities Report reveals a dramatic 101% increase in critical vulnerabilities in 2025, reversing a decade-long decline and concentrating risk in Azure and Dynamics 365.
Researchers developed a novel method to detect ransomware on shared file servers by analyzing network traffic patterns, offering earlier detection than endpoint-only solutions.