Search results

  1. Depov

    CVE-2026-42897 Microsoft Exchange: 0-day XSS in OWA - from crafted-writing to session capture

    There is no patch - only a temporary mitigation. CISA adds CVE to the Financial Exploited Vulnerabilities catalog on May 15 with a deadline of May 29. 14 days to respond. For SOC teams that are accustomed to detecting Exchange-incidents on server IOCs - web-slopes, anomalous IIS processes, a...
  2. Depov

    The Reason No One Is Safe

  3. Depov

    Gemini decided that the request to send an SMS from someone else's locked phone is normal if you press two buttons at the same time

    Artificial intelligence functions are increasingly integrated into smartphones, but together with convenience can open unexpected ways of bypassing the protection. Android 16 found an error that allows Gemini to send messages from a locked device without entering a PIN code. The problem arises...
  4. Depov

    False genius syndrome. AI Tips Have Made People Be Miserable More Often, But Believing More

    AI is increasingly prompting a ready-to-date response where a person would have to admit a lack of knowledge, and, as it was recently revealed, such assistance can reduce the reliability of conclusions. Experts from universities in France and Italy found that access to the advice of a language...
  5. Depov

    75 stolen signatures of DigiCert and Trojans of 2008. Hackers have found a new way to bypass Windows protection

    Cybercriminals found a way to turn Windows’s trust in digital signatures into a weapon and used an infected computer of an employee DigiCert to intercept the company’s customer certificates. Behind the attack was the Chinese band GoldenEye Dog, which then signed with stolen certificates its own...
  6. Depov

    Cunning hacker placed 537 000 advertising domains in a locker the size of a flash drive - and all this for a funny $ 5

    The Egyptian developer ZedAxis has assembled an advertising filter on the ESP32-C3 microcontroller, which blocks more than 537 thousand domains and costs about $ 5. The device works as a backup server of domain names for a home network. The main filtering of the developer is performed...
  7. Depov

    Fans of Linux in mourning. Windows 11 was three times faster in local artificial intelligence

    A powerful laptop for $5400 unexpectedly showed how different Windows 11 and Linux use the same iron. In the tasks related to artificial intelligence, the Microsoft system significantly ahead of Ubuntu and CachyOS, but when encoding video, both Linux builds convincingly took revenge. Phoronix...
  8. Depov

    Root without a password. The hole in SonicWall allowed to run anything on behalf of the superuser

    A VPN gateway often becomes the first entry point into the inner network, and in the summer of 2026, attackers used two unknown vulnerabilities of SonicWall Secure Mobile Access to gain full control over the devices. The attack was discovered after suspicious attempts to enter and move over the...
  9. Depov

    CVE-2026-42809 Apache Polaris: cloud hijacking credentials through staged table creation

    Four critical CVE in one service in one day. On May 4, 2026, Apache Polaris received security advisory, from which data engineers had to get in mood. CVE-2026-42809 from this bundle - the most indicative: CVSS 9.4 (CRITICAL according to CVSS 4.0), vector AV:N/AC:L/AT:N/PR:L/UI:N. The...
  10. Depov

    APT attacks on network equipment: how FSB Center 16 ten years comprehates routers

    In August 2025, the FBI through IC3 rolled out awarning: the cyber-operations of the Russian FSB from the Center 16division pulled configuration files from thousands of network devicesin the critical infrastructure sectors. Two vectors - SNMP andseven-year-old CVE-2018-0171in Cisco Smart...
  11. Depov

    Linux Kernel Privilege Escalation 2026: Fragnesia and Dirty Frag

    Four critical LPE in two weeks of May 2026. All in the page cache Linux kernel. All - without race condition, without kernel panic, with a probability of success close to 100%. And all found with LLM. Not some experimental code - combat exploits to obtain root shell from an ordinary user...
  12. Depov

    SaaS Security: Decerction Platform Compromise and Customer Data Protection

    According to Crowd Strike Global Threat Report 2025, 75% of the incurs in 2024 used valid accounting data, and IBM X-Force records an increase in credential-based attacks by 71% year-year. Earlier in the morning - in SIEM falls an alterth: the service account of the SaaS platform, inactive for...
  13. Depov

    Windows servers are stuck without updates. Microsoft Recognizes Large-Small Failure WSUS

    Windows corporate servers began waiting hours for updates or lose communication with Microsoft services. The company confirmed a large-scale failure in the work of Windows Server Update Services, which affected many versions of Windows 10, Windows 11 and Windows Server. Administrators have...
  14. Depov

    Thousands of actions, zero human intervention. AI agents hacked Hugging Face

    The hacker attack on Hugging Face has shown that autonomous systems based on artificial intelligence are already able to independently look for weaknesses, secure in the infrastructure and move between internal networks. The company found an invasion in early July and said that the attacker...
  15. Depov

    The uprising of the machines began in the ring: how the first tournament on fights without the rules of robot terminators T800

    In Shenzhen held a freestyle combat tournament between full-size humanoid robots. The cars beat each other with their hands and feet, performed reversals, fell, again rose and continued the fight. In one of the battles, the robot received a kick at the level of his head and lost it, but even...
  16. Depov

    How Hollywood Ruined Hacking

  17. Depov

    How Locked Phones Get Cracked In Seconds

  18. Depov

    Verizon DBIR 2026: exploiting vulnerabilities – number one vector and what to do with this pentester

    At an external pentest in early 2025, I received an shell on the corporate network through a VPN gateway with a CVE from the CISA KEV catalog. From the first scan to access, three hours. No phishing, no leaked passwords. Unpatughed edge-device at the perimeter, standard Nuclei-fine template...
  19. Depov

    CVE-2026-7411: Path Traversal -> RCE in Eclipse BaSyx - toptest industrial API

    CVE-2026-7411 in Eclipse BaSyx Java Server SDK - from those bugs that make you think about the state of security in the entire Industry 4.0 stack. An unauthenticated attacker through one HTTP request to the Submodel API records files in the host directory and receives full code execution...
Top Bottom