Live

Cybersecurity

The latest Cybersecurity coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 8:48 PM
Latest Most Read Breaking
Sort
Cyber Defense · Cyber Threats

Exfiltration by Admin Tool: How Attackers Weaponize DBeaver, Navicat, and sqlcmd

Attackers are ditching custom malware in favor of something far stealthier: the database management tools your IT team uses every day. Recent incident response investigations reveal a disturbing...

Advertisement
Bitwarden · Browser Security

Bitwarden PDF XSS Flaw (CVE-2025-5138) Exposes Passwords: Users Urged to Patch Immediately

A critical cross-site scripting vulnerability in Bitwarden’s PDF file handling can allow attackers to hijack user vaults by simply uploading a malicious document. Tracked as CVE-2025-5138, the flaw...

SE Security Desk·61w ago
Active Directory · Ad Delegation Risks

91% of AD Environments Vulnerable to Windows Server 2025 BadSuccessor Exploit

A dangerous privilege escalation vulnerability nestled inside Windows Server 2025’s delegated Managed Service Account (dMSA) architecture hands attackers a trivially exploitable path to full Active...

SE Security Desk·61w ago
Active Directory · Ad Permissions Audit

Windows Server 2025’s dMSA Opens a Silent Domain Takeover Path – Here’s the Fix

Attackers can now hijack entire Windows domains by exploiting a fundamental design flaw in the new delegated Managed Service Accounts (dMSAs) introduced with Windows Server 2025, security experts...

SE Security Desk·61w ago
Ai Risks · Ai Vulnerabilities

Rising AI Workloads Crack Hybrid Cloud Security: 70% Deem Public Cloud Risky, Breaches Hit 55%

The rapid integration of artificial intelligence into business operations has triggered an unprecedented surge in cyber threats, with breach rates climbing to 55% and 70% of IT leaders now labeling...

AI AI & Copilot Desk·61w ago
Cloud Security · Cve-2025-30733

Oracle TNS Flaw CVE-2025-30733: Memory Leak Exposes Sensitive Data Over Network Without Authentication

Oracle's April 2025 Critical Patch Update fixes a startling memory leak in the Transparent Network Substrate (TNS) listener that can spill sensitive system data to unauthenticated remote users....

SE Security Desk·61w ago
Active Directory · Active Directory Attack

SharpSuccessor Exploit Weaponizes Windows Server 2025 dMSA Flaw for Instant Domain Admin

A new proof-of-concept tool named SharpSuccessor is now publicly available, providing attackers with an automated method to exploit a critical privilege escalation vulnerability in Windows Server...

SE Security Desk·61w ago
Cert-in · Cloud Security

CERT-In Warns of Active Exploits: Critical Microsoft Vulnerabilities Threaten Millions of Indian Windows Users

On May 15, 2025, the Indian Computer Emergency Response Team (CERT-In) issued a stark warning to millions of Windows users across the country: multiple critical vulnerabilities in Microsoft’s...

SE Security Desk·61w ago
Antivirus Bypass · Cybersecurity

Defendnot Exploits Undocumented Windows API to Silently Disable Microsoft Defender

{ "title": "Defendnot Exploits Undocumented Windows API to Silently Disable Microsoft Defender", "content": "A newly developed proof-of-concept tool named Defendnot can disarm Microsoft Defender,...

SE Security Desk·61w ago