VulnerabilityBishop Fox·1 month ago

A Millisecond of Predictability: Why CVE-2026-11374 Is Hard to Exploit

ManageEngine's SSO implementation used only millisecond-precision wall-clock time for ticket generation, theoretically enabling unauthenticated account takeover due to the predictability of this value. While Bishop Fox confirmed end-to-end exploitation is feasible, blind exploitation remains impractical in real-world conditions, and the analysis includes actionable guidance for defenders to mitigate the risk.

PhishingInfosecurity Magazine·1 month ago

FBI Warns of Deepfake Videos Impersonating IC3 Leadership

The FBI has alerted the public to deepfake videos impersonating IC3 leadership being used to redirect victims to fraudulent complaint submission sites. This social engineering tactic leverages synthetic media to establish false credibility and deceive users into interacting with spoofed platforms, representing an evolving threat vector that combines deepfake technology with phishing infrastructure.

Nation-StateGraham Cluley·1 month ago

Ukraine warns fake CAPTCHAs are being used to make you hack yourself

Ukraine's CERT-UA has alerted security professionals to a social engineering campaign by the Kremlin-backed Sandworm group that exploits fake CAPTCHA prompts on compromised websites to trick users into executing malicious code. The technique represents a shift toward leveraging user trust in common security mechanisms as an attack vector rather than targeting technical vulnerabilities directly.

Data BreachInfosecurity Magazine·1 month ago

US Hospital Finance Software Provider Craneware Reports Data Theft

Craneware, a financial software provider serving US healthcare organizations, has disclosed a cyber incident resulting in unauthorized access and theft of data. The incident affects healthcare providers that rely on Craneware's systems for financial operations, though specific details regarding the scope of compromised data and the attack vector remain limited.

Nation-StateInfosecurity Magazine·1 month ago

Researchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 Pros

Researchers have identified a North Korean hacking group called Famous Chollima conducting a targeted campaign against cryptocurrency professionals using ClickFix social engineering lures. The attack delivers trojans designed to compromise both Windows and macOS systems, expanding the threat landscape for Web3 professionals beyond traditional single-platform attacks.

Initiative Gold Eagle - BHIS - Talkin' Bout [infosec] News 2026-07-20

Black Hills Information Security·1.7K views · 1 month ago

Join us LIVE on Mondays, 4:30pm EST. A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.

MalwareInfosecurity Magazine·1 month ago

Cruciferra Crypter Uses Process Ghosting to Evade Detection

Cruciferra crypter employs process ghosting alongside 90 custom ciphers as evasion techniques to conceal payloads from detection systems. The malware has been leveraged by multiple threat actors, demonstrating its appeal as a tool for obfuscating malicious code across different campaigns.

MalwareInfosecurity Magazine·1 month ago

New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications

Researchers have discovered that HollowGraph malware leverages Microsoft 365 calendars and Microsoft Graph APIs to establish covert command-and-control communications, exploiting legitimate cloud services to evade detection. The malware has been linked to the Cavern framework, indicating a coordinated approach to using cloud-based calendar systems as an alternative C2 infrastructure.

Automate Volatility 3 Memory Analysis with This Tool

13Cubed·2.8K views · 1 month ago

In this episode, we'll look at a tool that can run multiple Volatility 3 plugins simultaneously, automating your memory analysis and saving you valuable time during investigations. *** If you enjoy this video, please consider supporting 13Cubed on Patreon at patreon.com/13cubed. *** 📖 Chapters 00:00 - Intro 02:18 - Demo 🛠 Resources VolGolangWrapper:

Data BreachCheck Point Research·1 month ago

20th July – Threat Intelligence Report

Ernst & Young disclosed a data breach involving a compromised third-party IT support platform, with exposed support tickets potentially containing client documents and tax information. Check Point Research's weekly threat intelligence bulletin for July 20th covers this incident along with other significant cyber attacks and breaches discovered that week.

I got inside FIFA’s Secret World Cup Broadcast Network

NetworkChuck·513K views · 1 month ago

HackTheBox Logging

IppSec·8.4K views · 1 month ago

00:00 - Introduction 01:05 - Start of nmap 03:50 - Grabbing files off the open share, looking at logs and seeing an error message that contains an old credential 07:50 - Using BloodyAD to pull information from the account to see password last set, also running BloodHound 09:45 - Running Certipy, then using JQ to show me certificates with non-default groups/accounts in enrollment 12:25 - Going over Bloodhound, showing our SVC_RECOVERY can take over MSA_HEALTH$ 16:30 - Showing BloodyAD to allow ourselves read access to the MSA_HEALTH$ password, could also do Shadow Credentials 20:30 - Getting on the box with WinRM, discovering Monitor.ps1 file. Use COM to look at scheduled task 24:30 - Using MSFVenom to create a malicious DLL, zip it up and upload wait for the scheduled task to execute it 32:40 - Got access to Jaylee Clifton, using Rubeus tgtdeleg to get us a Kerberos ticket so we can run commands as them on our box 38:45 - Using Certipy to confirm the server is vulnerable to ESC17 41:45 - Looking at WSUS Config, discover things are pointed to wsus.logging.htb which does not exist 46:10 - Using Certipy to create a certificate that can impersonate wsus.logging.htb 49:00 - Setting up WSUKS to push a malicious windows update

VulnerabilityGraham Cluley·1 month ago

Google’s Gemini lets strangers send messages from your locked Android phone

Google's Gemini AI assistant on Android devices can be exploited to send messages from a locked phone without authorization, potentially allowing anyone with physical access to impersonate the device owner. This vulnerability undermines the security protections that locked phones are designed to provide, creating a risk for message-based attacks and social engineering. The issue highlights the need for stricter authentication controls when AI assistants have access to sensitive device functions.

Load more