D-Link Router Flaws Let Local Users Seize Admin Access
D-Link fixed a DIR-X1860Z flaw that lets a local-network user set a new admin password; the similar DIR-X1860 has no update path.
Read article →Reader view
Choose the default article length.
Page 3 of 10
D-Link fixed a DIR-X1860Z flaw that lets a local-network user set a new admin password; the similar DIR-X1860 has no update path.
Read article →Recovered tooling shows how forged WebDAV requests exposed nuclear records and credentials, with specific version, request-pattern, and signing-key checks for defenders.
Read article →Five exposed SecFlow workspaces linked Claude, Qwen and DeepSeek to Asian government and education intrusions involving credential theft, webshells, and implants.
Read article →Microsoft observed fake IT support sessions progress from Teams remote control to a persistent JavaScript implant and WinRM movement toward domain controllers.
Read article →Chrome 152.0.7977.82/.83 fixes an exploited V8 type-confusion flaw. Google has not disclosed the attackers, targets, exploit chain, or scale.
Read article →A server tied to The Gentlemen exposed TukTuk C2, a credential-stealing prompt, EDR-killer research, exfiltrated Jira data, and healthcare credentials.
Read article →Fortinet traced one stolen AWS administrator key through a new IAM user, Marketplace agreements, and billable Bedrock model calls.
Read article →A fail-open agent dashboard exposed one public-model key for three weeks, while noisy usage signals and absent spend limits delayed recognition.
Read article →Socket found 19 browser extensions using automatic updates, rotating command servers and injected modules to steal wallet secrets, sessions and passwords.
Read article →SonicWall confirmed active attacks against two SMA1000 flaws and told customers to hotfix, seek an IoC review, and rebuild systems when compromise is found.
Read article →Mandiant traced BREEZE COMET from vishing, rogue branch hardware and stolen cloud credentials to payment APIs used for hundreds of fraudulent transfers.
Read article →Ten malicious npm releases used trusted publishing, two install-time launch paths, and a credential-stealing worm. Defenders must isolate hosts before rotating tokens.
Read article →CISA confirms exploitation of a critical Artifactory flaw and requires federal forensic triage. Self-hosted operators have six fixed-version floors to verify.
Read article →A crafted workspace can steer Kiro 0.7.45 from reading a local secret to placing it in a Powers registry request. Amazon fixed the reported behavior in 0.8.140.
Read article →Fire Ant hid tunnels on Cisco routers, injected TACACS servers, and planted Linux backdoors. Sygnia's artifacts support checks of routers, authentication servers, and Linux hosts.
Read article →CISA confirmed exploitation of a 2019 SQL Server flaw and now requires affected systems to be patched after evidence preservation and forensic triage.
Read article →