
KB5124008 update may break Windows 11 domain trust
Microsoft is investigating reports that the Windows 11 KB5124008 update can sever Active Directory trust on some Enterprise devices.
Deep-dive analysis, hands-on tutorials, and cutting-edge threat intelligence from industry practitioners.

Microsoft is investigating reports that the Windows 11 KB5124008 update can sever Active Directory trust on some Enterprise devices.
Bad actors used stolen Ribon app credentials to inject malicious scripts into merchant sites, leaking personal shopper details but not payment cards.

The npm package ‘indexed‑btree’, masquerading as ‘sorted‑btree’, runs a hidden BTree.set() routine that gathers system info and sends it to Slack, Telegram and an Ethereum contract.

Hacktron leveraged Claude Opus 5 to combine a libheif RCE bug in Discourse with an OpenAI SSO flaw, briefly hijacking staff ChatGPT and Codex accounts and accessing an internal repo.

Vectra AI unveiled Ascent, a partner program aimed at expanding AI‑focused security services.

China‑origin APT‑Q‑95 has begun compromising Russian companies, using stolen VPN credentials to infiltrate Microsoft Exchange servers and install the GhostContainer backdoor.

Researchers uncovered 13 npm modules that pull the WeaselBiscuit JavaScript stealer, exfiltrating Chrome extension data on Windows, macOS and Linux.