Threat actors are actively exploiting hard-coded cryptographic keys in Gladinet to bypass authentication controls and achieve unauthorized access and code execution capabilities. Two critical vulnerabilities, CVE-2025-11371 and CVE-2025-30406, have been identified as primary attack vectors affecting healthcare and technology sectors.
Security researchers have uncovered ConsentFix, a sophisticated phishing attack targeting Azure CLI users. This supply chain attack leverages compromised development tools to gain access to enterprise networks. Understanding the attack vectors and implementing proper vetting procedures is critical for organizations relying on third-party tools like the Azure CLI.
Recent findings reveal that hidden HTTP proxy behaviors in .NET can create remote code execution (RCE) vulnerabilities in applications, a critical security issue that Microsoft has yet to address. This vulnerability, identified as CVE-2025-34392, poses significant risks for developers and organizations relying on .NET frameworks. Understanding these hidden behaviors and implementing robust securit
Learn how Amazon's intervention halted APT29's malicious activities exploiting Microsoft's device code authentication. (as detailed in the original report.)
Page 51 of 54