Black Hat USA 2026 opens its Trainings program tomorrow, August 1, at Mandalay Bay Convention Center in Las Vegas — and this year, for the first time in the conference's 29-year history, the ...
Russian state hackers are using a maximum-severity vulnerability in Microsoft’s Outlook’s Exchange Server to backdoor ...
OWAReaper malware, deployed by Russian state hackers Laundry Bear against US and European government agencies and ...
OWAReaper abuses CVE-2026-42897 to steal OAuth tokens, alter mailbox permissions, and persist inside Exchange accounts.
Russian hackers exploit CVE-2026-42897 in OWA to deploy OWAReaper, a browser implant that persists through credential ...
The NCSC and partners warned of a novel phishing technique being deployed against high-profile users of Zimbra's ...
Spread the loveWhen you’re diving into the world of building a website, you’re quickly confronted with a dizzying array of ...
Usually, when an attack is done via email, the victim is required to at least download a file or click a link. In this case, a cross-site scripting (XSS) vulnerability in the Zimbra web-based email ...
Any data that enters your system from outside a trust boundary should be treated as untrusted until proven otherwise. That includes form fields, API payloads, file uploads, headers, cookies, queue ...
A newly-identified Russian state threat actor is using a novel zero-click phishing technique, likely developed with the help of an AI, to target Western users of Zimbra software products.
Spread the loveWhen you spend a significant chunk of your day online, whether it’s for work, entertainment, or staying ...