Search results

  1. Depov

    DLP protection against insiders: policy adjustment for email, messengers and cloud

    On the DLP audit in one financial company, I saw a classic picture:the system stood, the policies were included, the licenses were paid- and the VIP client manager for three months merged the statementson the accounts through the personal Gmail without a single ailelet.The reason is banal: the...
  2. Depov

    Writes code and does not squander the budget. What is behind the new model GPT-5.6 Sol

    The costs of artificial intelligence are becoming no less important for companies than its capabilities, and OpenAI decided to bet on economy. The new GPT-5.6 Sol model spends 54% fewer tokens when it writes and checks the software code on its own, said the head of the company Sam Altman in an...
  3. Depov

    A regular card reader in a laptop – and access to memory bypassing Windows protection. We talk about the vulnerability that Realtek could not close fo

    The usual card reader in the laptop was able to interfere with the work of RAM bypassing Windows and protective equipment. The ZwClose specialist showed how the vulnerability in the Realtek driver allows an unprivileged program to access the physical memory of the computer through the mechanism...
  4. Depov

    CUPS RCE vulnerability: full analysis of the CVE-2024-47176 chain and print spooler part 1

    Tens of thousands of hosts with CUPS stuck on the Internet at the time of disclosure CVE-2024-47176 - a significant part of them took connections without authentication on UDP 631. When I reproducing this chain in the Docker Lab with cups-browsed 2.0.1, less than two minutes passed from the...
  5. Depov

    Analysis of malicious documents: analysis of the Macra of Office and exploits in PDF with the extraction of payload

    According to the IBM X-Force Thread Intelligence Index 2025, the Instylizers ranked first among all categories of malwarmers for 2024 - 32% of the samples found. The main delivery channel has not changed: a phishing email with an attachment of .docm or .pdf. And according to CrowdStrike Global...
  6. Depov

    15 years in the Linux kernel. Just one press gives your smartphone under the full control of intruders

    Even one click on the link is able to run a chain of operation of vulnerabilities, which overcomes several levels of smartphone protection at once. Nebula Security introduced IonStack is a test exploit for Android 17 that combines two previously unknown vulnerabilities and allows you to gain...
  7. Depov

    Do you still believe the antivirus? Artificial intelligence has learned to create a lumen that has no two identical copies

    Threat analysis specialists from time to time face tools where artificial intelligence acts not as an auxiliary element, but a full-fledged developer of malicious infrastructure - this is the case recorded when studying the new payload delivery system. Walmart Global Tech analysts who...
  8. Depov

    Prepare a place on the disk. Algorithms will overwhelm Windows with 11 gigabytes of new fixes

    The race between developers and attackers has noticeably accelerated, so Microsoft intends to include more security fixes in the monthly Windows 11 updates. The company has begun to increasingly use artificial intelligence to find and correct vulnerabilities in the early stages. Microsoft...
  9. Depov

    How Hackers Hack Wi-Fi In Seconds

  10. Depov

    Non-Human Identities Life Cycle Management: Continging, Rotation and Review Automation Through Policy-as-code

    Attacking chain via NHI: Why the Standard IAM Doesn't Close Machine Identifiers Standard IAM is built around human identity lifecycle: the HR system creates a record, IGA departments accounts, the manager conducts access review, when firing, accounts are deactivated. For NHI, this cycle breaks...
  11. Depov

    Vulnerabilities of Smart Buildings and ICS Security: Three UDP Packages to Root on EnOcean SmartServer

    The business logic of attacking smart buildings: a physical impact through a digital vector Why a BMS Controller? It's not about data theft or the encryption. Attacks on building automation systems are beaten in physics. EnOcean SmartServer IoT is an edge controller that pulls the control logic...
  12. Depov

    Network traffic gives more than the address of the wallet. Browser extensions tie a person to his crypt

    A browser crypto wallet can reveal much more than the user-selected address. Experts of the University of Leuven found that popular extensions allow you to link several accounts of one owner, track its transitions between sites and compare conventional Internet activity with the state of...
  13. Depov

    10 "critical" and the way to other people's files. What was found in the fresh Adobe ColdFusion patch

    In a fresh update, Adobe closed a set of dangerous vulnerabilities, some of which could allow the code to be executed on the server. The issues affect Adobe ColdFusion 2025 until updating 9 inclusive and ColdFusion 2023 before the update 20 inclusive. In the bulletin APSB26-68, the...
  14. Depov

    Prompt injections of the new generation, sleeping teams and fake markers. In CrowdStrike found new ways to ban artificial intelligence to say “no”

    CrowdStrike has expanded its classification of attacks, in which attackers implement malicious instructions in queries to AI. Experts have added 18 new techniques, and the general list now includes more than 200 technicians. The update shows how quickly the attacks on systems with artificial...
  15. Depov

    CVE-2026-41089: Windows Netlogon RCE – from CLDAP stack overflow to domain controller capture

    One UDP-package on port 389 - and you are SYSTEM on the domain controller. No login, no password, no click from the user. On May 12, 2026, Microsoft as part of the Patch Tuesday closed the stack buffer overflow in Windows Netlogon - CVE-2026-41089 with CVSS 9.8 (Critical). After 17 days, the...
  16. Depov

    Critical infrastructure cyber risks assessment: methodology and frameworks for OT/ICS

    At risk assessment substation 110 kV we found a history server route directly to the corporate network. VLANs existed, ACL between Level 3 and Level 4 according to Purdue - none. CVSS has shown a single known vulnerability on this server to 6.5, Medium. In IT-context - a reasonable priority...
  17. Depov

    I Hacked A Website With ONE Command

  18. Depov

    GhostApproval: One cloned repository – and the hacker is already in your SSH

    AI assistants for programming should speed up the developer’s work, but the new Wiz find shows the reverse side of autonomous agents: one failed repository request can open access to files outside the working folder and lead to the execution of code on the developer’s machine. Wiz...
  19. Depov

    The blue screen of death is no longer scary. In Windows 11 will be a button of reboots via the Internet

    Microsoft is testing a new Windows 11 recovery feature that can save users from one of the most unpleasant situations: complete reinstallation of the system after a download failure. A new mechanism called Cloud Rebuild allows you to reinstall Windows, even if the computer no longer starts. To...
Top Bottom