Windows Plug and Pwn Attack
Security researchers have disclosed a new 'Plug and Pwn' attack that abuses the Windows Plug and Play feature to gain SYSTEM privileges.
Attackers exploit identity verification processes, particularly during onboarding and account recovery, to gain unauthorized access to corporate systems.
Security researchers have disclosed a new 'Plug and Pwn' attack that abuses the Windows Plug and Play feature to gain SYSTEM privileges.
A new Android malware combo uses SpyNote and WindRelay to steal card data and take out loans in victims' names, with transactions approved in just 13 minutes.
An ongoing data theft campaign, dubbed City-Forum, targets Salesforce and ServiceNow portals, exploiting overly permissive sharing rules and permissions to steal data exposed to anonymous users.
WhatsApp has rolled out a new optional 'Scam Alert' feature that uses a local machine learning model to warn users of potential scam messages.
CISA orders federal agencies to patch CVE-2026-68820, a Windows vulnerability exploited by North Korean hackers in the 'Dream Job' campaign, by August 25.
Microsoft released fixes for 419 security vulnerabilities, one of the largest monthly counts on record, as AI-powered vulnerability discovery continues to increase the number of software flaws.
A sophisticated campaign targets Salesforce and ServiceNow using a custom toolset, exploiting unauthenticated guest user access and exfiltrating sensitive data.
The FBI warns that cybercriminals are targeting online accounts to steal sexually explicit images or videos, which can be used for blackmail or sold on criminal marketplaces.
North Korean IT workers impersonate nationals of other countries to obtain remote work, then send salaries back to parent agencies and may exfiltrate proprietary information.