Securing Windows Named Pipes: Defending Interprocess Communication from Local Privilege Escalation

Interprocess communication (IPC) on Microsoft Windows relies heavily on named pipes for exchanging structured data between local services, administrative tools, and user-space applications. Because named pipes function across session boundaries and provide network accessibility via SMB, they represent a persistent target for adversaries seeking local privilege escalation (LPE), lateral movement, and defense evasion. New defensive […]

SynkLoader Malware Uses Microsoft Teams Phishing and Fake Lock Screens to Infiltrate Corporate Networks

A previously undocumented malware family named SynkLoader has surfaced in targeted social engineering campaigns across corporate Microsoft Teams environments. Discovered by security researchers at Expel, the attack chain begins with direct messages from external Microsoft 365 tenants impersonating internal IT helpdesk staff and culminates in a fake Windows lock screen designed to capture domain passwords. […]

SafePal Data Breach Exposed Customer Records, But Not the Keys That Matter

SafePal, the cryptocurrency hardware wallet provider, confirmed a data breach that exposed personally identifiable information for roughly 39,798 customers. The good news, and it is genuinely reassuring: wallet seed phrases, private keys, passwords, and financial account data were not part of what leaked. The company states no evidence exists that the incident compromised access to […]

US government authorizes private security firms to hack overseas cybercriminals

The Trump administration has issued a National Security Presidential Memorandum authorizing private security firms to conduct offensive cyber operations against overseas criminal organizations. The program, managed by the National Coordination Center under the Homeland Security Task Force, marks the first time the US government has formally delegated offensive cyber authority to the private sector. Under […]

DeadLock ransomware uses blockchain to shrug off takedowns

Ransomware groups have spent years moving their leak sites around the internet, hopping from domain to domain as takedowns land. DeadLock tries to remove the weak point entirely. It spreads its command structure across a blockchain, so there is no single server for police to seize and no domain name to sinkhole. How it stays […]

Critical LoadMaster Command Injection Is Under Active Attack, Patch Now

If you run Progress LoadMaster (or the Kemp-branded versions of it), this is a patch-this-week story, not a note-for-later story. CISA has confirmed that a critical command injection vulnerability in the load balancer is being actively exploited in the wild, and the agency has added it to the Known Exploited Vulnerabilities catalog. That KEV listing […]

Metabase SQL injection zero-day is being exploited for data theft

A critical Metabase vulnerability is being actively exploited in the wild to steal customer data, and at least two well-known companies have already confirmed they were hit. Framework Computer and the accounting platform Tally both disclosed breaches tied to the flaw, which is an unauthenticated SQL injection in Metabase versions 1.58 and newer. If you […]

TONTOU CPU Attack Bypasses Spectre v2 Fixes and Leaks Kernel Secrets

Eight years after Spectre upended assumptions about CPU security, a new attack from MIT CSAIL shows the mitigations we built to contain it still have holes. TONTOU, short for time-of-neutralization to time-of-use, bypasses Spectre v2 defenses on AMD and Intel CPUs and has been demonstrated leaking Linux password hashes straight out of kernel memory. It […]

Kremlin Hackers Exploit Max-Severity Exchange Flaw to Backdoor Unpatched Networks

Russian state hackers are actively exploiting a maximum-severity flaw in Microsoft Exchange Server to backdoor unpatched networks, according to Proofpoint researchers. The attacks are notable less for the vulnerability itself and more for what happens when it is triggered: opening an email is enough to get you compromised, and the resulting backdoor survives both credential […]

Hermes AI Agent Weaponized in Thai Finance Ministry Cyberattack

Attackers used the Hermes AI agent to automate post-exploitation activities against Thailand’s Ministry of Finance, marking one of the first documented cases of an AI agent being weaponized in a real-world state-targeted cyberattack. Security researchers at Hunt.io discovered the artifacts on a compromised C2 server. The operator installed Hermes Agent (by Nous Research), switched off […]