Tag Windows

When ‘Secure Boot’ Falls Short of True Security

Endpoint Security, Hardware / Chip-level Security Eclypsium Uncovers UEFI Vulnerability in Framework Laptops and Desktops Pooja Tikekar (@PoojaTikekar) • October 15, 2025     Image: Shutterstock Security researchers from Eclypsium have identified a critical firmware weakness in approximately 200,000 laptops and desktops manufactured by the modular company Framework. This vulnerability…

Read MoreWhen ‘Secure Boot’ Falls Short of True Security

Hacking Team DoNot Targets Government and Military Entities in South Asia

A persistent threat actor, suspected to have ties to an Indian cybersecurity firm, has been actively attacking military organizations in South Asia since at least September 2020. The targeted nations include Bangladesh, Nepal, and Sri Lanka, with various iterations of their specialized malware framework used in each assault. According to…

Read MoreHacking Team DoNot Targets Government and Military Entities in South Asia

SonicWall VPNs Experience a Breach Following September Cloud Backup Incident

New Discovery Unveils Credential-Driven Campaign Targeting SonicWall Devices Recent findings by cybersecurity firm Huntress reveal a new and concerning trend in cyberattacks, indicating a credential-based campaign aimed at SonicWall SSLVPN devices. The investigation, which began around October 4, detected significant login activity from IP addresses linked to attackers, including one…

Read MoreSonicWall VPNs Experience a Breach Following September Cloud Backup Incident

Weekly Cybersecurity Newsletter: Discord Updates, Red Hat Data Breach, 7-Zip Vulnerabilities, and SonicWall Firewall Hack

In the latest edition of the Cybersecurity Newsletter, we explore significant vulnerabilities and threats currently impacting the digital environment. This week’s focus highlights several critical incidents that occurred leading up to October 12, 2025, including a Discord platform breach, a substantial data leak at Red Hat, and concerning vulnerabilities associated…

Read MoreWeekly Cybersecurity Newsletter: Discord Updates, Red Hat Data Breach, 7-Zip Vulnerabilities, and SonicWall Firewall Hack

Researchers Discover Exploit Bypassing Active Directory Restrictions on NTLMv1

Recent findings by cybersecurity experts have unveiled a considerable vulnerability in the Microsoft Active Directory Group Policy designed to disable the authentication method NT LAN Manager (NTLM) version 1. Researchers indicate that a misconfiguration within on-premises applications is capable of easily bypassing this Group Policy measure. According to Dor Segal,…

Read MoreResearchers Discover Exploit Bypassing Active Directory Restrictions on NTLMv1

Russian Cybercrime Groups Capitalizing on 7-Zip Vulnerability to Circumvent Windows MotW Protections

A newly addressed security vulnerability in the popular 7-Zip archiving tool has been actively exploited to distribute the SmokeLoader malware, raising significant concerns in the cybersecurity community. This vulnerability, identified as CVE-2025-0411, has a CVSS score of 7.0 and enables remote attackers to bypass mark-of-the-web (MotW) protections and run arbitrary…

Read MoreRussian Cybercrime Groups Capitalizing on 7-Zip Vulnerability to Circumvent Windows MotW Protections

Increasing Malware Attacks Utilizing Dark Utilities’ C2-as-a-Service

A newly emerging service known as Dark Utilities has gained popularity among cybercriminals, with approximately 3,000 users drawn to its capability to provide command-and-control (C2) services aimed at seizing control of compromised systems. This platform has positioned itself as a “C2-as-a-Service” (C2aaS), marketed for tasks including remote access, command execution,…

Read MoreIncreasing Malware Attacks Utilizing Dark Utilities’ C2-as-a-Service

Iran Seeks to Recruit European Aerospace Engineers Seeking Employment

Cyberwarfare / Nation-State Attacks, Fraud Management & Cybercrime, Social Engineering Iranian Hackers Pose as Online Recruiters Prajeet Nair (@prajeetspeaks) • September 23, 2025 Image: Shutterstock Recent reports reveal that Western Europeans employed in aerospace, defense manufacturing, and telecommunications are being targeted by Iranian state-sponsored hackers masquerading as online recruiters. These…

Read MoreIran Seeks to Recruit European Aerospace Engineers Seeking Employment