How an LLM Beat Ivanti’s Own Scanners to a Critical Bug
An Ivanti LLM vulnerability discovery turned up a perfect 10 flaw in Sentry, and attackers pounced within a day.
Stay updated with the latest cybersecurity news, threat intelligence, and industry updates from secure.com.
An Ivanti LLM vulnerability discovery turned up a perfect 10 flaw in Sentry, and attackers pounced within a day.
Attackers used SonicWall SMA zero days to break into VPN gateways, steal logins, and prep ransomware
Two FortiSandbox flaws are under active attack, and CISA gave federal agencies until Sunday to patch.
Text salting is helping more than a million phishing emails walk past AI email filters, and the trick is older than the filters.
TuxBot v3 is an IoT botnet built with LLM help. Researchers found the AI safety disclaimer still sitting in the shipped source code.
Researchers traced 1,628 sandbox sessions back to the Kratos phishing kit, and the tell was two SVG files nobody thought to look at.
Two npm supply chain attacks hit developer machines in five days, and one of them walked through a hole that had been documented since April.
Spirals ransomware went from web shell to full network encryption in less than 24 hours, and researchers think the crew is just getting started.
The LegacyHive Windows zero-day has working exploit code, no CVE, no patch, and it runs fine on machines you updated yesterday.
Five new Windows RDP vulnerabilities let attackers read leftover memory from remote sessions, and the scraps they find are worth more than the bugs themselves.
CISA warns that three SharePoint flaws are actively exploited, and patching alone will not evict attackers who already stole your machine keys.
Microsoft warns that ShinyHunters Salesforce OAuth abuse is stealing CRM data without tripping a single login alarm.