A static key in SolarWinds ARM lets outsiders run code remotely

SolarWinds has patched a hard-coded key that let unauthenticated attackers run code in Access Rights Manager.

The Latest

Breaking News and Alerts

A lighter stealer called WeaselBiscuit turns up in 13 npm packages

A small JavaScript stealer with fingerprints of North Korean developer-targeting campaigns has been found riding a cluster of malicious packages.

Spotlight

Cybersecurity Profiles and Stories

A long username is enough to crack Check Point management servers

Check Point has shipped an emergency fix for a flaw that lets anyone on the network run code as root on the servers that control its customers' firewall policy.

Attackers breach Cisco ISE management interface through an API blind spot

Cisco's identity appliance is being hit through an API endpoint that never checked who was asking.

A logic error in Pixel modems lets attackers climb in silently

A logic error below Android's reach lets attackers escalate on Pixel handsets without any interaction.

BambooToken hides its command channel in a signed security token

A signed banking token becomes the delivery vehicle for an implant that talks to its handlers over IoT messaging.

Features

Research and Thought Leadership