Software

Microsoft starts removing WMIC tool used by cybercriminals

Microsoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week. WMIC is a legacy built-in Windows command-line utility that helps interact with the Windows Management Instrumentation (WMI) system using text commands. This move is part of […]

Microsoft starts removing WMIC tool used by cybercriminals Read More »

Crypto hardware wallet owners face fresh security risks after recent spate of personal data thefts

Data breaches at two shipping companies has put cryptocurrency owners with physical hardware wallets at greater risk of having their funds stolen, highlighting weaknesses in the broader tech ecosystem relied on by the crypto industry. In recent weeks, makers of hardware crypto wallets Trezor and SafePal reported that collectively thousands of their customers had their

Crypto hardware wallet owners face fresh security risks after recent spate of personal data thefts Read More »

Philips and GE investigating Clop ransomware data theft claims

Tech giants General Electric (GE) and Philips have also confirmed they’re investigating claims that the Clop ransomware gang breached their systems and stole data. While a GE spokesperson said the company is aware of the claim and is “working to assess the potential issue,” a Philips spokesperson confirmed its systems were breached but said the

Philips and GE investigating Clop ransomware data theft claims Read More »

French tax authority data breach affects 678,000 individuals

The French Ministry of the Economy and Finance has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems and stole data belonging to 678,000 individuals. This incident was discovered after a threat actor using the “ZeroBytes” handle claimed the attack and listed a stolen database for sale on

French tax authority data breach affects 678,000 individuals Read More »

Microsoft working on Defender patch for ShieldBreak zero-day

On Friday, Microsoft confirmed it has begun working on a security patch for a Defender zero-day vulnerability named “ShieldBreak.” A security researcher who uses the “Nightmare Eclipse” handle disclosed this privilege escalation vulnerability after Microsoft released the August 2026 Patch Tuesday security updates. ​”Microsoft is aware of the reported vulnerability and is actively investigating the

Microsoft working on Defender patch for ShieldBreak zero-day Read More »

The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI

By Rajan Kapoor, VP Security, Material Security Over the past two months, I’ve written about the Vercel breach and the Composio breach separately. Both offer lessons to learn on their own. But reading them together, I keep coming back to the same observation: these aren’t isolated incidents They’re the same attack, run twice, against different

The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI Read More »

Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

The Netherlands’ National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged. The security issue lies in macOS Screen Sharing, a built-in remote desktop feature that allows remote desktop control over a network, using the VNC protocol over TCP port 5900. Apple fixed

Hackers exploit macOS Screen Sharing flaw to deploy Monero miner Read More »

Hackers arrested over €30M bank fraud exploiting service provider flaw

Four cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at a service provider, allowing them to withdraw funds from Commerzbank customers’ bank accounts. The theft, investigated by the Brazilian and German federal police agencies, occurred over four days in November 2023 and caused losses

Hackers arrested over €30M bank fraud exploiting service provider flaw Read More »

New Evooo1Bot Linux botnet turns routers into traffic relay nodes

A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes. The malware’s capabilities extend beyond turning devices into proxy nodes and include credential theft, SSH brute-forcing, and launching distributed denial-of-service (DDoS) attacks. Since at least July, Evooo1Bot has been targeting devices from Alcatel,

New Evooo1Bot Linux botnet turns routers into traffic relay nodes Read More »