Exploiting Unauthenticated API Gateways in AWS September 21, 2026 sara.pearlman@guidepointsecurity.com BLOG 5 min. Over the past year, GuidePoint’s Threat and Attack Simulation (TAS) team has ...
The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume ...
How the Java Cryptography Architecture works: providers, the Cipher, MessageDigest and Signature classes, plus ML-KEM and ...
This follow-up report details how UNC6240 (ShinyHunters) is mass-exploiting Oracle PeopleSoft (CVE-2026-35273) by bypassing WAF rules via a single URL-encoded character, providing full analysis of the ...
Explore how Model Context Protocol (MCP) is transforming AI-driven identity and security automation, and learn the best practices for mitigating risks ...
Microsoft has uncovered an Azure-focused destructive campaign tied to Storm-3168, also known as JADEPUFFER, in which ...
A newly disclosed active exploitation of a critical local privilege escalation flaw in Veeam Agent for Microsoft Windows that enables attackers to elevate low-privileged access to NT AUTHORITYSYSTEM ...
A critical local privilege escalation flaw in Veeam Agent for Microsoft Windows has gained attention following the release of ...
A Veeam Agent flaw lets local users gain SYSTEM privileges. A public PoC is available, raising the risk of exploitation.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results