DPAPISnoop Tool Gains CREDHIST Extraction for Offline Password Cracking

The updated DPAPISnoop tool parses Windows CREDHIST files to generate crackable hashes that reveal users' complete password change history through iterative offline recovery.

The Latest

Breaking News and Alerts

SniperDz PhaaS Platform Arms Criminals with 70+ Brand Impersonation Templates

Group-IB researchers uncovered a turnkey PhaaS platform enabling brand impersonation and browser hijacking through social media lures across the Middle East and North Africa.

Spotlight

Cybersecurity Profiles and Stories

ServiceNow Warns Customers After Malicious Actors Exploit Instance Access Flaw

ServiceNow disclosed that threat actors exploited an unpatched configuration flaw to query a subset of customer instances before a security update was applied on June 5.

npm 12 to Block Install Scripts by Default to Thwart Code Execution Attacks

npm version 12 will require explicit user approval for install scripts and Git dependencies to block automatic code execution from compromised packages.

AI Assistant OpenClaw Found Vulnerable to Credential Theft via Email Trickery

A controlled phishing test demonstrated that the OpenClaw AI agent can be manipulated into forwarding sensitive credentials like AWS keys and database passwords with a single deceptive email.

Smart TV Apps Expose Home Networks as Stealth Proxies for AI Data Collection

A reverse engineering investigation reveals that free apps on smart TVs and phones act as exit nodes for a web scraping network serving AI companies, using home IP addresses without…

Features

Research and Thought Leadership