Endpoint Security

Old Attack, New Speed: Researchers Optimize Page Cache Exploits

Old Attack, New Speed: Researchers Optimize Page Cache Exploits 2026-01-22 at 17:22 By Eduard Kovacs A team of researchers from the Graz University of Technology in Austria has revived page Linux page cache attacks. The post Old Attack, New Speed: Researchers Optimize Page Cache Exploits appeared first on SecurityWeek. This article is an excerpt from […]

Old Attack, New Speed: Researchers Optimize Page Cache Exploits Read More »

New StackWarp Attack Threatens Confidential VMs on AMD Processors

New StackWarp Attack Threatens Confidential VMs on AMD Processors 2026-01-15 at 20:27 By Eduard Kovacs Researchers have disclosed technical details on a new AMD processor attack that allows remote code execution inside confidential VMs. The post New StackWarp Attack Threatens Confidential VMs on AMD Processors appeared first on SecurityWeek. This article is an excerpt from

New StackWarp Attack Threatens Confidential VMs on AMD Processors Read More »

OpenAEV: Open-source adversarial exposure validation platform

OpenAEV: Open-source adversarial exposure validation platform 2026-01-05 at 08:02 By Sinisa Markovic OpenAEV is an open source platform designed to plan, run, and review cyber adversary simulation campaigns used by security teams. The project focuses on organizing exercises that blend technical actions with operational and human response elements, all managed through a single system. Scenarios

OpenAEV: Open-source adversarial exposure validation platform Read More »

UEFI Vulnerability in Major Motherboards Enables Early-Boot Attacks

UEFI Vulnerability in Major Motherboards Enables Early-Boot Attacks 2025-12-18 at 17:42 By Eduard Kovacs ASRock, Asus, Gigabyte, and MSI motherboards are vulnerable to early-boot DMA attacks. The post UEFI Vulnerability in Major Motherboards Enables Early-Boot Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

UEFI Vulnerability in Major Motherboards Enables Early-Boot Attacks Read More »

How exposure management changes cyber defense

How exposure management changes cyber defense 2025-12-17 at 07:36 By Help Net Security In this Help Net Security video, Larry Slusser, VP of Strategy at SixMap, explains why endpoint detection and response is only part of the security story. Drawing on his work as an incident responder, engagement manager, and ransomware negotiator, he describes EDR

How exposure management changes cyber defense Read More »

MITRE Posts Results of 2025 ATT&CK Enterprise Evaluations

MITRE Posts Results of 2025 ATT&CK Enterprise Evaluations 2025-12-11 at 16:25 By Eduard Kovacs Eleven companies took part in the evaluations and several have boasted 100% detection and coverage rates. The post MITRE Posts Results of 2025 ATT&CK Enterprise Evaluations appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

MITRE Posts Results of 2025 ATT&CK Enterprise Evaluations Read More »

Intel, AMD Processors Affected by PCIe Vulnerabilities

Intel, AMD Processors Affected by PCIe Vulnerabilities 2025-12-10 at 10:22 By Eduard Kovacs The PCIe flaws, found by Intel employees, can be exploited for information disclosure, escalation of privilege, or DoS. The post Intel, AMD Processors Affected by PCIe Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Intel, AMD Processors Affected by PCIe Vulnerabilities Read More »

Microsoft Silently Mitigated Exploited LNK Vulnerability

Microsoft Silently Mitigated Exploited LNK Vulnerability 2025-12-03 at 14:35 By Ionut Arghire Windows now displays in the properties tab of LNK files critical information that could reveal malicious code. The post Microsoft Silently Mitigated Exploited LNK Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft Silently Mitigated Exploited LNK Vulnerability Read More »

Microsoft Highlights Security Risks Introduced by New Agentic AI Feature

Microsoft Highlights Security Risks Introduced by New Agentic AI Feature 2025-11-24 at 15:32 By Ionut Arghire Without proper security controls, AI agents could perform malicious actions, such as data exfiltration and malware installation. The post Microsoft Highlights Security Risks Introduced by New Agentic AI Feature appeared first on SecurityWeek. This article is an excerpt from

Microsoft Highlights Security Risks Introduced by New Agentic AI Feature Read More »

AI can flag the risk, but only humans can close the loop

AI can flag the risk, but only humans can close the loop 2025-11-05 at 09:07 By Mirko Zorz In this Help Net Security interview, Dilek Çilingir, Global Forensic & Integrity Services Leader at EY, discusses how AI is transforming third-party assessments and due diligence. She explains how machine learning and behavioral analytics help organizations detect

AI can flag the risk, but only humans can close the loop Read More »

Microsoft Disables Downloaded File Previews to Block NTLM Hash Leaks

Microsoft Disables Downloaded File Previews to Block NTLM Hash Leaks 2025-10-24 at 15:38 By Ionut Arghire In files downloaded from the internet, HTML tags referencing external paths could be used to leak NTLM hashes during file previews. The post Microsoft Disables Downloaded File Previews to Block NTLM Hash Leaks appeared first on SecurityWeek. This article

Microsoft Disables Downloaded File Previews to Block NTLM Hash Leaks Read More »

Lanscope Endpoint Manager vulnerability exploited in zero-day attacks (CVE-2025-61932)

Lanscope Endpoint Manager vulnerability exploited in zero-day attacks (CVE-2025-61932) 2025-10-23 at 17:10 By Zeljka Zorz CVE-2025-61932, an “improper verification of source of a communication channel” vulnerability affecting Lanscope Endpoint Manager, has been exploited as a zero-day since April 2025, the Japan Computer Emergency Response Team Coordination Center (JPCERT/CC) warned on Wednesday. According to information received

Lanscope Endpoint Manager vulnerability exploited in zero-day attacks (CVE-2025-61932) Read More »

Microsoft Patches 173 Vulnerabilities, Including Exploited Windows Flaws

Microsoft Patches 173 Vulnerabilities, Including Exploited Windows Flaws 2025-10-15 at 07:40 By Ionut Arghire The tech giant has rolled out fixes for 173 CVEs, including five critical-severity security defects. The post Microsoft Patches 173 Vulnerabilities, Including Exploited Windows Flaws appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft Patches 173 Vulnerabilities, Including Exploited Windows Flaws Read More »

Windows 10 Still on Over 40% of Devices as It Reaches End of Support

Windows 10 Still on Over 40% of Devices as It Reaches End of Support 2025-10-14 at 13:03 By Eduard Kovacs Users can continue receiving important security updates for Windows 10 by enrolling in the ESU program. The post Windows 10 Still on Over 40% of Devices as It Reaches End of Support appeared first on

Windows 10 Still on Over 40% of Devices as It Reaches End of Support Read More »

WireTap Attack Breaks Intel SGX Security

WireTap Attack Breaks Intel SGX Security 2025-10-02 at 14:31 By Ionut Arghire The attack uses a passive interposer to control the SGX enclave and extract the DCAP attestation key, breaking the mechanism. The post WireTap Attack Breaks Intel SGX Security appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

WireTap Attack Breaks Intel SGX Security Read More »

Patch Bypassed for Supermicro Vulnerability Allowing BMC Hack

Patch Bypassed for Supermicro Vulnerability Allowing BMC Hack 2025-09-23 at 21:45 By Eduard Kovacs Binarly researchers have found a way to bypass a patch for a previously disclosed vulnerability.  The post Patch Bypassed for Supermicro Vulnerability Allowing BMC Hack appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Patch Bypassed for Supermicro Vulnerability Allowing BMC Hack Read More »

Ransomware attackers used incorrectly stored recovery codes to disable EDR agents

Ransomware attackers used incorrectly stored recovery codes to disable EDR agents 2025-09-16 at 15:46 By Zeljka Zorz All target organizations are different, but ransomware attackers are highly adaptive and appreciate – and will exploit – any mistake you make. The latest Akira ransomware attacks Managed security service providers and external incident responders have had a

Ransomware attackers used incorrectly stored recovery codes to disable EDR agents Read More »

Neon Cyber Emerges from Stealth, Shining a Light into the Browser

Neon Cyber Emerges from Stealth, Shining a Light into the Browser 2025-09-16 at 14:49 By Kevin Townsend Neon Cyber argues that phishing, social engineering, and insider threats demand protections that follow users into the browser, where most attacks now begin. The post Neon Cyber Emerges from Stealth, Shining a Light into the Browser appeared first

Neon Cyber Emerges from Stealth, Shining a Light into the Browser Read More »

Rowhammer Attack Demonstrated Against DDR5

Rowhammer Attack Demonstrated Against DDR5 2025-09-16 at 14:41 By Ionut Arghire Researchers devise Phoenix, a new Rowhammer attack that achieves root on DDR5 systems in less than two minutes. The post Rowhammer Attack Demonstrated Against DDR5 appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Rowhammer Attack Demonstrated Against DDR5 Read More »

Endpoint Security Firm Remedio Raises $65 Million in First Funding Round

Endpoint Security Firm Remedio Raises $65 Million in First Funding Round 2025-09-16 at 11:54 By Ionut Arghire The bootstrapped company will invest in an AI-powered unified enterprise platform combining configuration, compliance, patching, and vulnerability management. The post Endpoint Security Firm Remedio Raises $65 Million in First Funding Round appeared first on SecurityWeek. This article is

Endpoint Security Firm Remedio Raises $65 Million in First Funding Round Read More »

Scroll to Top