11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
Cybersecurity researchers have discovered 11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications that could be abused to bypass Secure...
Category Added in a WPeMatico Campaign
Cybersecurity researchers have discovered 11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications that could be abused to bypass Secure...
Researchers at KU Leuven tested 85 of the most popular crypto wallets that run as browser extensions and found that...
AI security agents are starting to influence real security decisions. They summarize findings, prioritize remediation, recommend next steps, and help...
xAI's Grok Build coding CLI was uploading entire Git repositories, full commit history and all, to a Google Cloud Storage...
The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) has designated two individuals and a VPN service provider for...
A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service botnet for...
Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting...
Ravie LakshmananJul 13, 2026Endpoint Security / Cybercrime Cybersecurity researchers have flagged a new macOS information stealer called CrashStealer that's capable...
Google and Microsoft have pulled ModHeader, a popular header-editing extension with roughly 1.6 million installs across Chrome and Edge, after...
Ravie LakshmananJul 13, 2026Cybersecurity / Hacking Somewhere right now, a security tool is quietly finding bugs faster than any human...
Give an AI assistant a memory and access to your inbox, and you hand an attacker a way to rewrite...
A new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion,...
An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with...
Ravie LakshmananJul 13, 2026Vulnerability / Web Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security...
The jscrambler npm package was compromised, and simply installing its 8.14.0 release runs an infostealer on your machine. Published on July 11,...