Russian state hackers are using a maximum-severity vulnerability in Microsoft’s Outlook’s Exchange Server to backdoor ...
Russian hackers exploit CVE-2026-42897 in OWA to deploy OWAReaper, a browser implant that persists through credential ...
The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor ...
The NCSC and partners warned of a novel phishing technique being deployed against high-profile users of Zimbra's ...
Elecom Wi-Fi router and access point vulnerability: JPCERT/CC and IPA confirm three CVEs including CVSS 8.6 OS command ...
A high-severity flaw in Zimbra allowed Russian criminals easy access, where they stole important secrets.
CERT-UA links UAC-0099 to a fake Notepad++ plugin that deploys BURNYBEAR and MATCHBOIL.V2, with persistence running every ...
A state-sponsored threat group, dubbed "Laundry Bear," sends "half-click" phishing emails that require a victim only to open or preview the message.
Microsoft last week released Windows 11 KB5094126 and KB5093998 as the latest Patch Tuesday updates. Following that the company also published the accompanying dynamic updates under KB5094149, ...
Microsoft has released security updates to fix an actively exploited Exchange Server vulnerability that could allow attackers to run malicious JavaScript code in users’ browsers through Outlook Web ...
Its disclosure raises questions about what security researchers should expect from vendors, and how far in advance of its publication they should notify vendors about a bug. A vulnerability in ...