New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables This story has been flagged as significant cybersecurity news. For full details, see the original source linked…
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers This story has been flagged as significant cybersecurity news. For full details, see the original source linked…
Growing Up The Hard Way
Growing Up The Hard Way This story has been flagged as significant cybersecurity news. For full details, see the original source linked above. Why This Matters This development is being…
FOMO in the SOC: Where AI Platforms Like Claude Actually Fit in Modern Security Operations
AI platforms like Claude, Codex, and Cursor are already helping security teams write detections, investigate alerts, summarize incidents, and automate repetitive work. The conversation has evolved from whether AI belongs…
Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
An unknown Chinese-speaking threat actor has been running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit. Attack surface management platform Censys…
Three Critical Flaws in Hugging Face Diffusers Library Enable Arbitrary Code Execution
Three high-severity security vulnerabilities have been disclosed in Hugging Face’s Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load them. Critically, these…
N-able N-central Servers Compromised After Initial Patch Proves Incomplete
N-able has confirmed that attackers are exploiting an authentication bypass in N-central (CVE-2026-18577) to gain remote administrative access and reach customer systems managed through those servers. The critical detail: N-able’s…
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
According to a report by Resecurity, the INC Ransomware operation has emerged as the “dominant threat actor” exploiting recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series…
Critical Flaw in Google Password Manager Lets Malware Hijack Passkey-Protected Accounts
Unit 42 has disclosed three attack paths against Chrome’s Google Password Manager cloud authenticator, dubbed Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key. The strongest variant targets the master key, enabling malware…
‘Certighost’ Flaw Haunts Microsoft Active Directory Certificates
Microsoft has patched a high-severity vulnerability, dubbed “Certighost,” that allows threat actors to escalate privileges and compromise Active Directory environments. The flaw affects Microsoft Active Directory certificates and represents a…
