Cybersecurity Funding
Using AI, the startup provides adaptive prevention through environment mapping, risk analysis, and automated policy enforcement.
Hi, what are you looking for?
Kaspersky told SecurityWeek that it patched the vulnerability affecting its Endpoint Security product.
Using AI, the startup provides adaptive prevention through environment mapping, risk analysis, and automated policy enforcement.
Signed by Microsoft, the vulnerable UEFI shim bootloaders could be abused on any system, regardless of the OS.
The cybersecurity companies patched critical and high-severity vulnerabilities in some of their products.
Bitdefender researchers show how Windows bind links can create conflicting filesystem views to hide malware from endpoint security products.
A variant of DirtyFrag, the flaw allows unprivileged local users to manipulate the Linux page cache and gain root privileges.
A standard non-admin account is sufficient to conduct an attack that exploits legitimate OS behavior rather than software vulnerabilities.
Ent has developed an intent-aware platform designed to interpret user and agent behavior before risky actions are carried out.
The PoC exploits Microsoft Defenderโs offline scan to spawn a SYSTEM shell when rebooting in Recovery Mode.
A stack-based buffer overflow bug can be exploited for remote code execution on a vulnerable device.
The exploitation is mitigated by preventing the FsTx Auto Recovery Utility from starting when the WinRE image launches.
Attackers are increasingly abusing Microsoftโs decades-old MSHTA utility to stealthily deliver stealers, loaders, and persistent malware through phishing, fake software downloads, and LOLBIN-based attack...
Patched in April, the underlying vulnerability allows local attackers to elevate their privileges to root.
The vulnerability, tracked as CVE-2026-46300, is similar to the recently disclosed exploits named Dirty Frag and Copy Fail.
Also called Copy Fail 2 and tracked as CVE-2026-43284 and CVE-2026-43500, the exploit was disclosed before a patch was released.
CISA has added the bug to its KEV list, and Microsoft has observed limited exploitation, mainly associated with PoC testing.
Affecting the kernelโs authencesn cryptographic template, the vulnerability was introduced in 2017 and impacts all distributions.