Categoria : Security

image_pdfimage_print

During her time with the U.S. Secret Service, Hazel Cerra found herself at the precipice of the rise of cybercrime. Cerra noticed how digital evidence was becoming increasingly prevalent with each investigation. “I volunteered for technical assignments and pursued opportunities to build expertise in cyber investigations and critical systems protection,” Cerra says. Taking initiative paid ..

Leggi tutto

China’s military procurement system has suspended or permanently barred more than a dozen of the country’s leading cybersecurity vendors since 2024, according to new research from threat intelligence group Natto Thoughts.  The findings, based on public notices from the military procurement network cross-referenced with corporate disclosures and Chinese media reports, identify at least 21 enforcement ..

Leggi tutto

Nearly a dozen Unified Extensible Firmware Interface (UEFI) shim bootloaders signed by Microsoft allow attackers to bypass Secure Boot protections, ESET warns. Small, trusted pieces of software bridge a computer motherboard’s UEFI firmware and the operating system, typically a Linux distribution, enabling the machine to boot with Secure Boot enabled. By using Microsoft-signed UEFI shim ..

Leggi tutto

Modern cargo vessels are becoming floating distributed data centers. A single ship spends weeks at sea exchanging data with cloud platforms, fleet management systems, cargo-monitoring applications, and shore-based operations centers. Thousands of connected devices run at once across the vessel and its cargo. That connectivity improves visibility and control, but it also creates a security ..

Leggi tutto

Nightmare Eclipse, the disgruntled security researcher who has been dropping zero-day exploits targeting Microsoft products, released another unpatched Windows vulnerability this week, right on the July 2026 Patch Tuesday. The fresh exploit, named LegacyHive, is a local privilege escalation bug in the Windows User Profile Service that allows an attacker to load other users’ hives, ..

Leggi tutto

An unpatched vulnerability in Cursor on Windows can be triggered for code execution when a developer opens a repository in the application, Mindgard reports. Cursor is one of the most popular AI-assisted development environments, with more than 7 million active users. The security defect, Mindgard says, is straightforward: when opening a repository, Cursor would automatically ..

Leggi tutto

The US Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday urged immediate hardening of Microsoft SharePoint servers in light of recently disclosed zero-day vulnerabilities. The freshest of the exploited flaws is CVE-2026-56164, a privilege escalation issue that can be exploited remotely without authentication, and which was resolved with Microsoft’s July 2026 Patch Tuesday updates. On ..

Leggi tutto