Skip to content

Latest alerts

RSS feed

UNC6671 Vishing Campaign: Stolen SaaS Credentials

The UNC6671 vishing campaign targets enterprise employees by calling their personal mobile numbers and guiding them to spoofed login pages. Stolen credentials and MFA tokens are then used to access and exfiltrate data from SaaS platforms.

Enterprise Open Source: Growing Up Hard Way

Open source isn’t disappearing—it’s being conscripted. Enterprise Open Source will split the ecosystem into projects that can prove ongoing viability and those that won’t fit regulated needs.

SCTP Phantom Linux bug: update to prevent root

Een oude use-after-free in Linux’ SCTP-netwerkcode kan in specifieke situaties leiden tot root op de host. Onderzoekers melden bovendien pogingen om containers te ontsnappen, waarna een kernelupdate dringend is.

AI-Assisted HTTP Terminator Uncovers Desync Tactics

PortSwigger’s AI-Assisted HTTP Terminator generated and proved new HTTP desynchronization techniques by testing thousands of authorized targets. The work also surfaced a patched Apache Traffic Server zero-day and a broader attack concept.