Kerberos unconstrained delegation is one of those Active Directory configurations that can sit quietly for years and still create a disproportionate amount of risk. It is often introduced to make a ...
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based ...
Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance.
A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into ...
An unknown miscreant is using "TerminalFix" to trick unsuspecting users into running PowerShell commands that infect their ...
Microsoft says TerminalFix uses fake Cloudflare CAPTCHAs to trigger PowerShell and deploy a reverse-tunnel backdoor for internal network access.
ScreenConnect abuse shows worm-like propagation of a four-stage VBScript chain; ConnectWise advises disabling file transfers ...
SPECTRE backdoor, deployed by Chinese-speaking hacker group UAT-10147, blinds CrowdStrike Falcon, SentinelOne, and Microsoft ...
CVE-2026-62911 Exchange Server flaw lets attackers seize all mailboxes with no password: nearly 22,000 servers remain unpatched worldwide three weeks after Microsoft's August fix shipped, 85 percent ...
Hackers used Sliver, credential theft, and Active Directory attacks to compromise a US organization and expand access.
A fraudulent Claude desktop app distributes RevStealer malware targeting crypto wallets and password managers, then deletes ...
DOJ reviews a TCS-linked Massachusetts tech job posting seeking an H-1B worker, raising questions about immigration status, ...