LIVE FEED
Subscribe
//

Category: Exploits

Exploits Akira Affiliate Rebooted a Victim Into Safe Mode to Kill EDR, Ransomware Still Failed
HIGH Exploits

Akira Affiliate Rebooted a Victim Into Safe Mode to Kill EDR, Ransomware Still Failed

An Akira ransomware operator disabled endpoint defenses by forcing a compromised host into Safe Mode with Networking, but the encryption payload crashed…

by Robbie · 20 hours ago
Exploits US and South Korea Warn of Gunra Ransomware Hitting Government Networks
HIGH Exploits

US and South Korea Warn of Gunra Ransomware Hitting Government Networks

A joint advisory details how the Conti-derived Gunra ransomware group is exploiting Fortinet flaws and VPN weaknesses to breach critical infrastructure, now…

by Robbie · 2 days ago
Exploits Head Mare Hackers Trojanize TrueConf Installers to Spread Backdoors
HIGH Exploits

Head Mare Hackers Trojanize TrueConf Installers to Spread Backdoors

A hacktivist group is exploiting unpatched TrueConf video conferencing servers to plant web shells and swap legitimate client installers with backdoored versions,…

by Robbie · 6 days ago
Exploits ClickFix Campaign Delivers macOS Crypto-Draining Stealer
HIGH Exploits

ClickFix Campaign Delivers macOS Crypto-Draining Stealer

A Go-based malware pushed through fake Terminal-command lures steals browser passwords and iCloud Keychain data while quietly siphoning cryptocurrency from active transactions.

by Robbie · 7 days ago
Exploits Researchers Chain Three Samsung Bugs to Turn Bixby Into a Root Shell
HIGH Exploits

Researchers Chain Three Samsung Bugs to Turn Bixby Into a Root Shell

A Pwn2Own-winning exploit chain used Samsung Members, Samsung Account, and Bixby's hidden Capsule system to achieve system-level compromise on Galaxy phones, earning…

by Robbie · 1 week ago
Exploits Attackers Hide Post-Exploitation Toolkit Inside Oracle Database Itself
HIGH Exploits

Attackers Hide Post-Exploitation Toolkit Inside Oracle Database Itself

Huntress uncovered a rare technique in which hackers used a SQL injection flaw to compile and run a custom post-exploitation toolkit called…

by Robbie · 1 week ago
Exploits N-able Patches Second Auth Bypass Flaw Under Active Attack on N-central Servers
CRITICAL Exploits

N-able Patches Second Auth Bypass Flaw Under Active Attack on N-central Servers

N-able rushed out a hotfix after discovering that attackers were exploiting an incomplete patch for a prior authentication bypass, granting administrator access…

by Robbie · 1 week ago
Exploits Coldcard Maker Destroys Vulnerable Inventory After $88M Bitcoin Theft
HIGH Exploits

Coldcard Maker Destroys Vulnerable Inventory After $88M Bitcoin Theft

Coinkite has scrapped remaining stock of its Coldcard hardware wallets after attackers exploited a years-old firmware flaw to drain more than $88…

by Robbie · 2 weeks ago
Exploits Adform Ad Script Hijacked to Swap Crypto Wallet Addresses on Copy
HIGH Exploits

Adform Ad Script Hijacked to Swap Crypto Wallet Addresses on Copy

A supply-chain compromise of Adform's widely embedded tracking script let attackers silently replace Bitcoin, Ethereum, and TRON addresses copied by site visitors,…

by Robbie · 2 weeks ago
Exploits Hijacked Hotel Wi-Fi Delivers CornFlake Spyware via Fake Browser Updates
HIGH Exploits

Hijacked Hotel Wi-Fi Delivers CornFlake Spyware via Fake Browser Updates

Microsoft says a Storm-2945 campaign dubbed CaptiveCrunch is hijacking hotel Wi-Fi captive portals to push fake browser updates that install the CornFlake…

by Robbie · 2 weeks ago
Exploits Adform Ad Script Hijacked to Swap Crypto Wallet Addresses on Copy
HIGH Exploits

Adform Ad Script Hijacked to Swap Crypto Wallet Addresses on Copy

Attackers tampered with a JavaScript file served by ad-tech firm Adform, turning it into a browser-based tool that silently rewrote copied cryptocurrency…

by Robbie · 2 weeks ago
Exploits Arch Linux Halts AUR Package Adoption After Malware Takeover Surge
HIGH Exploits

Arch Linux Halts AUR Package Adoption After Malware Takeover Surge

Arch Linux has temporarily disabled Arch User Repository package adoption following a wave of malicious takeovers, with researchers linking the campaign to…

by Robbie · 2 weeks ago
1 2 6

THE 0600 BRIEF

Every critical CVE and AI-security story, in your inbox each morning.