Aggregator
AI Agents and Non-Human Identities Creating Critical Security Gaps, Report
Cookie控制的PHP Webshell:Linux托管环境中的隐秘攻击手法
微软揭秘:AI驱动的Device Code钓鱼攻击如何规模化绕过MFA
CVE-2026-35616:Fortinet FortiClientEMS 零日漏洞已被野外利用(CVSS 9.1)
BlueHammer:研究员公开未修复 Windows 零日漏洞,可提权至 SYSTEM
Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI
UK exposes Russian military intelligence hijacking vulnerable routers for cyber attacks
APT28 exploit routers to enable DNS hijacking operations
AI-enabled device code phishing campaign exploits OAuth flow for account takeover
A phishing campaign that bypasses the standard 15-minute expiration window through automation and dynamic code generation, leveraging the OAuth Device Code Authentication flow to compromise organizational accounts at scale, has been observed by the Microsoft Defender Security Research team. The campaign uses AI-assisted infrastructure and end-to-end automation. Attack overview Device Code Authentication is a legitimate OAuth flow designed for devices that cannot support a standard interactive login. In this model, a code is presented on … More →
The post AI-enabled device code phishing campaign exploits OAuth flow for account takeover appeared first on Help Net Security.
Ваш VPN вас выдает. Популярные клиенты (v2rayNG, Clash, Hiddify) оказались уязвимы
The Hidden Cost of Recurring Credential Incidents
GPUBreach exploit uses GPU memory bit-flips to achieve full system takeover
ShadowByt3 New threat Actor
You must login to view this content
TDF 基金会称它取消 Collabora 员工的会员资格是为了遵守非营利组织法
The Gentleman
You must login to view this content
The Gentleman
You must login to view this content
The Gentleman
You must login to view this content
The Gentleman
You must login to view this content
The Gentleman
You must login to view this content