KerberLoss and ResetNightmare: Kerberos Can Fail Without Stealing a Ticket
Two Active Directory logic flaws presented at Black Hat show how SPN handling and password reset behavior can enable downgrade, disruption, and domain takeover.
In-depth red team tactics, blue team strategy — and privacy-first security tools that run entirely in your browser. No accounts. No telemetry. No data leaves your machine.
Two Active Directory logic flaws presented at Black Hat show how SPN handling and password reset behavior can enable downgrade, disruption, and domain takeover.
Seven ClamAV parser vulnerabilities can crash scanning processes, and Cisco products inherit the exposure. Defenders need to verify scanner health, not only malware verdicts.
Cisco says attackers are exploiting a remote denial-of-service flaw in ASA and FTD VPN services. Here is how to prioritize, detect, and contain it.
Attackers are exploiting a macOS Screen Sharing authentication flaw against exposed Macs. Patch, remove VNC exposure, and investigate before treating it as a routine update.
MOVEit, GoAnywhere, Cleo, Accellion — the same extortion playbook keeps working on enterprise file-transfer software. Here's the structural reason why, and what to do about it.
A domain that looks pixel-perfect in your browser's address bar can still be fake. Here's how homograph and Punycode phishing exploits Unicode lookalike characters — and how to catch it.
Evil twin access points clone trusted Wi-Fi networks to intercept traffic and steal credentials. Here's how the attack works, why WPA3 doesn't fully stop it, and how to detect and defend against it.