Protecting education: How MDR can tip the balance in favor of schools
The education sector is notoriously short on cash, but rich in assets for threat actors to target. How can managed detection and response (MDR) help learning institutions regain the initiative?
With developer verification, Google's Apple envy threatens to dismantle Android's open legacy
Questions remain as Google prepares to lock down Android app distribution in the name of security.
Firefox JIT Bug - Pwn2Own Documentary (Part 3)
This month in security with Tony Anscombe – February 2026 edition
Threat actors are actively exploiting weak authentication mechanisms and unmanaged exposures to compromise systems, while also leveraging popular AI tools for malicious purposes. This opportunistic approach highlights ongoing vulnerabilities in common security practices that organizations continue to struggle with.
Mobile app permissions (still) matter more than you may think
Start using a new app and you’ll often be asked to grant it permissions. But blindly accepting them could expose you to serious privacy and security risks.
New AirSnitch attack bypasses Wi-Fi encryption in homes, offices, and enterprises
That guest network you set up for your neighbors may not be as secure as you think.
A Deep Dive into the GetProcessHandleFromHwnd API
Google Project Zero researcher Jann Horn examines the evolution of the GetProcessHandleFromHwnd API across Windows versions, revealing critical security flaws that allow opening protected processes when UIPI is enabled. The API's journey from a hook-based implementation in Vista through a kernel function in Windows 10 introduced dangerous access bypasses, particularly affecting restricted token sandboxes and protected processes that opened windows. Windows 11 24H2 introduced significant hardening including permanent UIPI enforcement and protection level checks, though older versions remain vulnerable to exploitation through process handle duplication and memory manipulation attacks.
The First Exploit - Pwn2Own Documentary (Part 2)
Apache ActiveMQ Exploit Leads to LockBit Ransomware
A threat actor exploited CVE-2023-46604 on an exposed Apache ActiveMQ server in mid-February 2024 to achieve remote code execution using a Java Spring class, ultimately leading to LockBit ransomware deployment. The DFIR Report provides a detailed analysis of this intrusion chain, including insights into the attacker's techniques and methodology.
Faking it on the phone: How to tell if a voice call is AI or not
Can you believe your ears? Increasingly, the answer is no. Here’s what’s at stake for your business, and how to beat the deepfakers.
The World's Hardest Hacking Competition - Pwn2Own Documentary (Part 1)
PromptSpy ushers in the era of Android threats using GenAI
ESET researchers have identified PromptSpy, marking the first documented Android malware to leverage generative AI within its attack mechanism. The discovery indicates an emerging threat vector where threat actors are integrating AI capabilities into mobile malware operations.
Is Poshmark safe? How to buy and sell without getting scammed
Like any other marketplace, the social commerce platform has its share of red flags. It pays to know what to look for so you can shop or sell without headaches.
Tracking Program Execution with a Little Known Registry Key
In this episode, we’ll take a look at another obscure, registry-based execution artifact that may help you fill in yet another piece of the puzzle. *** If you enjoy this video, please consider supporting 13Cubed on Patreon at patreon.com/13cubed. *** 📖 Chapters 00:00 - Intro 00:33 - About Registry Hives 02:10 - Demo 🛠 Resources FeatureUsage — Evidence of Execution:
Is it OK to let your children post selfies online?
When it comes to our children’s digital lives, prohibition rarely works. It’s our responsibility to help them build a healthy relationship with tech.
Naming and shaming: How ransomware groups tighten the screws on victims
When corporate data is exposed on a dedicated leak site, the consequences linger long after the attack fades from the news cycle
Bypassing Administrator Protection by Abusing UI Access
Google Project Zero researcher has documented five root causes behind nine discovered bypasses of Windows Administrator Protection, all of which have now been fixed. The vulnerabilities primarily exploited weaknesses in the UI Access feature—originally designed to allow accessibility applications to function across privilege boundaries—including insecure directory checks, token manipulation, DLL hijacking through environment variables, and TOCTOU race conditions in the RPC process creation mechanism. While all reported issues have been patched, the researcher emphasizes that the underlying architectural reliance on UI Access processes remains a potential vector for future attacks if code execution can be achieved in a High integrity level process.
LummaStealer Is Getting a Second Life Alongside CastleLoader
Bitdefender researchers have identified a resurgence in LummaStealer activity, demonstrating how this prolific information-stealing malware persisted despite near-disruption by law enforcement within the past year. Operating as a malware-as-a-service since late 2022, LummaStealer has established itself as one of the most widely deployed information stealers through its highly scalable architecture. The malware's renewed distribution alongside CastleLoader indicates continued evolution and adaptation by the threat actors behind the operation.
Taxing times: Top IRS scams to look out for in 2026
It’s time to file your tax return. And cybercriminals are lurking to make an already stressful period even more edgy.