Ad image

Unpatched Windows Search URI Flaw Exposes User Credentials via NTLM Leak

Researchers found that the Windows Search URI handler can be tricked into leaking NTLMv2 hashes to attackers via malicious links, and Microsoft has declined to patch the issue.

The Latest

Breaking News and Alerts

Trusted Cloud Giants Weaponized to Mask Malicious Command and Control Traffic

Researchers found that attackers are hosting Cobalt Strike command and control servers on AWS, Google Cloud, Azure, Cloudflare, and GitHub to avoid detection and blend into normal enterprise traffic.

Spotlight

Cybersecurity Profiles and Stories

Autonomous AI Bug Hunter Discovers Critical Flaw in Redis Database

An autonomous AI tool has discovered a critical remote code execution vulnerability in Redis that remained hidden for over two years across multiple stable versions.

Attackers Abuse FortiClient Management Server Bug to Push Password Stealer

Threat actors are exploiting a critical FortiClient EMS vulnerability to disguise credential-stealing malware as a legitimate software update, using the server's own management tools to infect endpoints.

Ivanti ITSM Flaw Opens Door to Full Admin Takeover

A newly disclosed privilege escalation vulnerability in Ivanti Neurons for ITSM allows authenticated attackers to gain full administrative control over the platform.

OpenClaw Flaws Enable AI Agent Hijacking via Identity Confusion

Five zero-day vulnerabilities in OpenClaw let attackers hijack AI agent access across multiple chat platforms by exploiting mutable display names during identity resolution.

Features

Research and Thought Leadership