Category index

Cyber Security

4276 articles

4276 ARTICLES

FEATURED REPORT

Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday

Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive. It has been described as a Windows User Profile Service arbitrary hive load elevation of privileges vulnerability. The Windows User Profile Service, also referred to as ProfSvc, is a core system component that manages user accounts and environments. “The PoC requires

BY The Hacker News
MIN READ 1 MIN READ
EXPLORE north_east
Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday
New Webinar: Closing the Approval Gap in AI-Era Ad Tech
CYBERSECURITY

New Webinar: Closing the Approval Gap in AI-Era Ad Tech

A single approved marketing tag can quietly load fourth-party code your security team has never seen, granting full access to your forms, customer data, and checkout pages. This on-demand webinar reveals how this Approval Gap forms, and gives your team the blueprint to close it before an auditor, regulator, or attacker finds it first. The Reality of the Approval Gap It’s a pattern every

1 MIN READ arrow_forward
A Video Screen That Is Also a Camera
CYBERSECURITY

A Video Screen That Is Also a Camera

Amazing: Researchers from ETH Zurich in Switzerland, however, managed to create a new type of pixel that can simultaneously do both. This hypercharged pixel, called a Fourier pixel, can generate and sense arbitrary light fields and tap into a pixel’s full potential for carrying information by manipulating light’s intensity, oscillation phases, and polarization. The team reported its findings in a paper published yesterday in Nature. We are one step closer to 1984 technology: The telescreen received and transmitted simultaneously. Any sound that Winston made, above the level of a very low whisper, would be picked up by it; moreover, so long as he remained within the field of vision which the metal plaque commanded, he could be seen as well as heard. There was of course no way of knowing whether you were being watched at any given moment…

1 MIN READ arrow_forward
Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution
CYBERSECURITY

Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution

Open a repository in Cursor on Windows and, if a file named git.exe is sitting in the project root, Cursor runs it. No click, no approval dialog, no warning that anything in the folder is about to execute. Whatever that binary does, it does as you, with your source, your SSH keys and your cloud tokens. Cursor keeps re-running it for as long as the project stays open. No prompt

1 MIN READ arrow_forward
Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware
CYBERSECURITY

Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware

Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security, SafeDep, Socket, and StepSecurity. The affected packages are listed below - @asyncapi/generator-helpers@1.1.1 @asyncapi/generator-components@0.7.1 @asyncapi/generator@3.3.1 @asyncapi/specs(v6.11.2, v6.11.2-alpha.1) “The

1 MIN READ arrow_forward
Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
CYBERSECURITY

Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands

SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution. The vulnerabilities are listed below - CVE-2026-15409 (CVSS score: 10.0) - A Server-side request forgery (SSRF) vulnerability that a remote unauthenticated attacker could exploit to

1 MIN READ arrow_forward
ICYMI: June 2026 @AWS Security
CYBERSECURITY

ICYMI: June 2026 @AWS Security

Read all about the latest AWS security features, compliance updates, and hands-on resources in our new, monthly digest posts. You’ll find expert blog posts, new service capabilities, code samples, and workshops. AWS Security Blog posts This month’s AWS Security Blog posts covered identity and access management, threat intelligence, network security, AI-powered security tooling, and multi-account

1 MIN READ arrow_forward
Follow the money
CYBERSECURITY

Follow the money

Why give away the most valuable data in security? Learn how Athena’s business model aligns trust, incentives, and open source defense.

1 MIN READ arrow_forward
You Are Using Auth0 The Hard Way
CYBERSECURITY

You Are Using Auth0 The Hard Way

Stop writing manual API calls and hand-rolling token refresh logic. Learn how to accelerate your production setups using the Auth0 SDK, Auth0 CLI, and Infrastructure as Code.

1 MIN READ arrow_forward