Tag: endpoint security

Metabase has released security updates after confirming active exploitation of a zero day vulnerability that allows attackers to gain administrator access without authentication.
Research presented at Black Hat USA 2026 demonstrates CSS based attack techniques affecting major webmail services, highlighting risks involving passwords, authentication tokens, and AI connected email workflows.

New OXLOADER Malware Campaign Uses Fake Google Ads To Deliver CastleStealer

Researchers have uncovered a new malware campaign using malicious Google Ads to distribute CastleStealer through a newly identified loader called OXLOADER, employing advanced obfuscation and evasion techniques.

Organizations Shift Toward Operational Cyber Resilience As EDR Challenges Grow

Organizations are increasingly expanding EDR capabilities with proactive hardening and managed detection and response to improve cyber resilience and reduce operational pressure on security teams.

Kimsuky Expands Cyber Arsenal With HTTPSpy, HelloDoor, And VS Code Tunnels

North Korean threat actor Kimsuky has intensified cyberattacks targeting South Korean military and corporate organizations, deploying HTTPSpy malware, HelloDoor, and abusing VS Code tunneling for covert access.

Trillium Information Security Systems And IBM Host Cybersecurity Forum In Lahore On Identity, Secrets, And Endpoint Security

Trillium Information Security Systems, in collaboration with IBM, hosted a cybersecurity event in Lahore focused on identity security, endpoint protection, and secrets management with leading CISOs and security experts.

Kaspersky Report Highlights Rising Ransomware Tactics And Growing Trade Of Stolen Data In 2026

Kaspersky’s latest ransomware report highlights evolving cybercriminal tactics, including encryption less extortion, EDR killers, and the sale of stolen credentials through Telegram channels and dark web forums.

Researchers Examine BYOVD Risks Through Vulnerable Windows Drivers Without Hardware Dependencies

New cybersecurity research highlights how vulnerable Windows kernel mode drivers may remain exploitable without dedicated hardware, raising concerns around BYOVD attacks and endpoint security risks.

Tax Search Ads Deliver ScreenConnect Malware Using Huawei Driver To Evade Security

A malvertising campaign targets U.S. users searching for tax forms, delivering ScreenConnect malware and HwAudKiller to bypass EDR using a Huawei driver.

Ubuntu CVE 2026 3888 Flaw Enables Root Access Through systemd Timing Exploit

A high severity Ubuntu vulnerability CVE 2026 3888 allows attackers to gain root access via systemd cleanup timing and snap confine interaction.

OpenClaw AI Agent Security Flaws Raise Prompt Injection And Data Exfiltration Concerns

China’s CNCERT warns that OpenClaw AI agent security weaknesses could enable prompt injection attacks, endpoint compromise, and sensitive data exfiltration.

Microsoft Uncovers ClickFix Campaign Using Windows Terminal To Deploy Lumma Stealer Malware

Microsoft reports a ClickFix social engineering campaign abusing Windows Terminal to execute malicious commands and deploy Lumma Stealer targeting browser credentials.

Nets International Pakistan Achieves Kaspersky Gold Partnership To Expand Cybersecurity Solutions

Nets International Pakistan becomes a Kaspersky Gold Partner to enhance enterprise cybersecurity offerings in Pakistan with advanced threat protection and endpoint security solutions.

Kaspersky Launches Special Offer on EDR Foundations for Enhanced Threat Protection

Kaspersky rolls out discounted access to its Next EDR Foundations solution for new customers, offering advanced threat detection and global intelligence-backed protection until August 2025.

Recent articles

spot_img