LDAPNightmare PoC Exploit Crashes LSASS and Reboots Windows Domain Controllers

A proof-of-concept (PoC) exploit has been released for a now-patched security flaw impacting Windows Lightweight Directory Access Protocol (LDAP) that could trigger a denial-of-service (DoS) condition.
The out-of-bounds reads vulnerability is tracked a… Continue reading LDAPNightmare PoC Exploit Crashes LSASS and Reboots Windows Domain Controllers

Posted in Uncategorized

New ‘All-Optical’ Nanoscale Sensors of Force Access Previously Unreachable Environments

ZipNada shares a report from Phys.org: In a paper published today in Nature, a team led by Columbia Engineering researchers and collaborators report that they have invented new nanoscale sensors of force. They are luminescent nanocrystals that can chan… Continue reading New ‘All-Optical’ Nanoscale Sensors of Force Access Previously Unreachable Environments

Critical Deadline: Update Old .NET Domains Before January 7, 2025 to Avoid Service Disruption

Microsoft has announced that it’s making an “unexpected change” to the way .NET installers and archives are distributed, requiring developers to update their production and DevOps infrastructure.
“We expect that most users will not be directly affected… Continue reading Critical Deadline: Update Old .NET Domains Before January 7, 2025 to Avoid Service Disruption

Posted in Uncategorized

SwaetRAT Delivery Through Python, (Fri, Jan 3rd)

We entered a new year, but attack scenarios have not changed (yet). I found a Python script with an interesting behavior[1] and a low Virustotal score (7/61). It targets Microsoft Windows hosts because it starts by loading all libraries required to call Microsoft API Calls and manipulate payloads:

Continue reading SwaetRAT Delivery Through Python, (Fri, Jan 3rd)

Posted in Uncategorized

Apple to Pay Siri Users $20 Per Device in Settlement Over Accidental Siri Privacy Violations

Apple has agreed to pay $95 million to settle a proposed class action lawsuit that accused the iPhone maker of invading users’ privacy using its voice-activated Siri assistant.
The development was first reported by Reuters.
The settlement applies to U…. Continue reading Apple to Pay Siri Users $20 Per Device in Settlement Over Accidental Siri Privacy Violations

Posted in Uncategorized

The modern CISO is a cornerstone of organizational success

The chief information security officer (CISO) role has undergone a remarkable transformation, evolving from a purely technical position to a role that bridges business strategy, operational efficiency, and cybersecurity.
The post The modern CISO is a c… Continue reading The modern CISO is a cornerstone of organizational success

Best practices for ensuring a secure browsing environment

In this Help Net Security interview, Devin Ertel, CISO at Menlo Security, discusses how innovations like AI and closer collaboration between browser vendors and security providers will shape the future of browser security.
The post Best practices for e… Continue reading Best practices for ensuring a secure browsing environment