Aggregator
九月暂停更新说明
AI vs. AI: Detecting an AI-obfuscated phishing campaign
Microsoft Threat Intelligence recently detected and blocked a credential phishing campaign that likely used AI-generated code to obfuscate its payload and evade traditional defenses, demonstrating a broader trend of attackers leveraging AI to increase the effectiveness of their operations and underscoring the need for defenders to understand and anticipate AI-driven threats.
The post AI vs. AI: Detecting an AI-obfuscated phishing campaign appeared first on Microsoft Security Blog.
NIST Issues Broad Agency Announcement for Proposals to Advance Microelectronics Technologies
AI vs. AI: Detecting an AI-obfuscated phishing campaign
Microsoft Threat Intelligence recently detected and blocked a credential phishing campaign that likely used AI-generated code to obfuscate its payload and evade traditional defenses, demonstrating a broader trend of attackers leveraging AI to increase the effectiveness of their operations and underscoring the need for defenders to understand and anticipate AI-driven threats.
The post AI vs. AI: Detecting an AI-obfuscated phishing campaign appeared first on Microsoft Security Blog.
How One Bad Password Ended a 158-Year-Old Business
SolarWinds fixed a critical RCE flaw in its Web Help Desk software
Feds Tie ‘Scattered Spider’ Duo to $115M in Ransoms
Feds Tie ‘Scattered Spider’ Duo to $115M in Ransoms
CVE-2025-10892 | Google Chrome up to 140.0.7339.185 V8 integer overflow
CVE-2025-10891 | Google Chrome up to 140.0.7339.185 V8 integer overflow
CVE-2025-10890 | Google Chrome up to 140.0.7339.185 V8 information disclosure
CVE-2025-39890 | Linux Kernel up to 6.6.93/6.12.33/6.15.2 wifi ath12k_service_ready_ext_event memory leak
CVE-2025-39889 | Linux Kernel up to 5.15.180/6.1.134/6.6.87/6.12.24/6.14.3 Bluetooth information disclosure
CVE-2024-58241 | Linux Kernel up to 6.11.5 Bluetooth privilege escalation
Hackers Can Bypass EDR by Downloading a Malicious File as an In-Memory PE Loader
A sophisticated technique that allows attackers to execute malicious code directly in memory is gaining traction, posing a significant challenge to modern Endpoint Detection and Response (EDR) solutions. This method, which involves an in-memory Portable Executable (PE) loader, enables a threat actor to run an executable within an already trusted process, effectively bypassing security checks […]
The post Hackers Can Bypass EDR by Downloading a Malicious File as an In-Memory PE Loader appeared first on Cyber Security News.
Casino company Boyd Gaming hacked, employee data stolen
The Gentleman
You must login to view this content
OnePlus OxygenOS Vulnerability Lets Apps Access SMS Data Without User Permission
A newly disclosed flaw in OnePlus OxygenOS lets any app on a device read SMS and MMS messages without asking the user. Tracked as CVE-2025-10184, the issue stems from a permission bypass in the Telephony content provider (com.android.providers.telephony). Normally, apps must hold the Android READ_SMS permission and prompt the user before accessing text messages. In […]
The post OnePlus OxygenOS Vulnerability Lets Apps Access SMS Data Without User Permission appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
The Gentleman
You must login to view this content