A critical deserialization bug in on-prem SharePoint (CVSS 9.8) came under attack right after Microsoft’s record Patch Tuesday. Stolen machine keys keep intruders in even after patching.
An attacker used a $1.12M flash loan to drain about $1.65M from Allbridge’s Solana pools. The bridge is paused and liquidity providers are told to withdraw.
Google has shipped an out-of-band security update for Chrome. At least one of the patched flaws is already being used in attacks — don’t put this one off.
The EU’s cybersecurity rules cover far more organisations than many expect — from hospitals to emergency services. A look at who is affected by NIS2 and KRITIS.
The well-known onchain investigator calls hardware wallets unreliable and suggests a stripped-down iPhone used only for signing. A look at his arguments.