Rogue external MFA providers can steal passwords during logins
Varonis Threat Labs demonstrated TrustSink, a post-compromise technique in which an attacker controlling a highly privileged Microsoft Entra account registers a rogue external MFA…
6 articles
Varonis Threat Labs demonstrated TrustSink, a post-compromise technique in which an attacker controlling a highly privileged Microsoft Entra account registers a rogue external MFA…
Sweden’s privacy regulator IMY fined IT systems provider Miljödata SEK 1.8 million ($183,000) after finding inadequate security measures contributed to an August 2025 cyberattack…
BigCommerce disclosed that compromised credentials for the third-party Ribon and Ribon 1.5 applications were used to inject malicious scripts into a small number of merchant store…
CISA warned that three Linux kernel vulnerabilities are being actively exploited, including CVE-2025-39964, which is rated critical and existed in the kernel for 14 years. Federal…
Checkmarx identified an ongoing npm supply-chain malware campaign centered on the malicious "indexed-btree" package, which impersonates "sorted-btree" and evades install-script pr…
Researchers reported two sandbox-escape flaws in OpenAI Codex that could allow untrusted repository content or agent actions to execute commands outside Codex's sandbox. Accomplis…