It took $58 to break Microsoft’s SCCM, but a patch made it harder
Researchers at XM Cyber found that a standard domain user with no Microsoft SCCM privileges can chain multiple flaws to reach remote code execution, although the attack does require network access to the SCCM environment.…
Enterprises use Microsoft System Center Configuration Manager (SCCM) t…
XM Cyber’s attack can move from an ordinary domain account to code exe…
“After the Site Server is compromised, all of its managed clients are …
Trump administration opens door to private-sector cyber offensives
The Trump administration is opening the door for vetted US companies to conduct cyber operations against foreign cybercriminal organizations under federal supervision, giving the private sector a more direct role in disrupting cyber-enabled crime.…
A presidential memorandum issued on August 12 directs the National Coo…
The memorandum says, “any resulting operational action will be exclusi…
” Companies admitted to the program will have to contract with either …
AI agents wage near-autonomous cyberattack on Asian government networks
Autonomous AI agents built on open-source frameworks breached Taiwanese government systems, compromised credentials, and probed a nuclear safety agency in a multi-day cyberattack that researchers say signals a new phase in AI-enabled operations.…
The campaign unfolded over four days in early July, during which multi…
“In roughly four days, the agentic attacker produced 1,395 files, 85 c…
“It spells out one thing loudly – the cost of running a competent atta…
Attackers target zero-day vulnerability in geospatial data platform GeoServer
Security researchers have seen evidence that attackers are attempting to exploit a currently unpatched SQL injection vulnerability in GeoServer, an open-source web server for managing and publishing geospatial data.…
The software is widely used by organizations in many industries, inclu…
A bug bounty hunter shared the vulnerability Wednesday on X as a zero …
According to his post, the jsonArrayContains function contains a vulne…
AI’s potential as a security tool and the danger of autonomous AI agents as a new attack surface were key themes of the presentations and product announcements at Black Hat and DEFCON in Las Vegas last week.…
Here are some key takeaways from this year’s hacker summer camp that C…
Reactive patching alone is no longer sufficient Microsoft’s David West…
Rather than attempting to respond faster than attackers, he said, the …
Akira ransomware reboots into Windows Safe Mode to knock EDR offline
Akira ransomware affiliates were seen using a new technique to evade endpoint detection and response (EDR), where they rebooted a compromised Windows system into Safe Mode with Networking enabled.…
According to Huntress, the technique successfully took both its agent …
This, the researchers said, gave the attacker a window to operate with…
The incident investigated by Huntress began on August 4 with a credent…