Track CVEs, attack groups, malware, vendors and training in one place.
CybersecurityBoard.com brings together vulnerability intelligence, security news, MITRE ATT&CK group profiles, cyber events, certifications, training, products, companies and service providers.
CVE-2021-24092 is a privilege escalation vulnerability in Microsoft Defender's BTR.sys driver, disclosed by SentinelLabs researcher Kasif Dekel in February 2021. It allowed a local non-administrator to overwrite arbitrary files by placing a hard link…
A set of improper neutralization of special elements vulnerabilities in Cisco Secure Workload could allow command, OS, and argument injection. CVSS score…
Multiple improper access control vulnerabilities in Cisco Secure Workload could allow privilege escalation and bypasses. CVSS score 10.0, fixed in versions 3.10.9.1…
Improper authentication vulnerabilities in Cisco Secure Workload could allow authentication bypass and reliance on untrusted inputs. CVSS score 10.0, fixed in versions…
Improper restriction of operations within memory buffers in Cisco Secure Workload could allow buffer overflows and out-of-bounds writes. CVSS score 7.5, fixed…
Check Point Research has disclosed a technique that abuses Microsoft Defender's own legitimately signed boot-time remediation driver, BTR.sys, to perform arbitrary kernel-level…
AvNeutralizerBlack Hat USA 2026Boot Time Removal ToolBTR_CLI
The U.S. government has issued a joint advisory warning of an active threat targeting critical infrastructure organizations using AI-generated exploit scripts. The…
Researchers at the University of Massachusetts Amherst have demonstrated a novel attack, dubbed "Zombie Card," that can revive expired Visa contactless credit…
Cybersecurity researchers have disclosed two denial-of-service (DoS) attack techniques, collectively named "CDN Tsunami," that exploit how major content delivery networks (CDNs) convert…
Suspected Russian cyber espionage groups are abusing legitimate authentication flows, including Google OAuth and WhatsApp device linking, to hijack accounts across Europe…
RedShell is the Linux beacon component of RedC2 4.0, providing interactive shell access, system discovery, data collection, persistence, and network pivoting. It…
Cybersecurity researchers at Trend Micro's TrendAI have uncovered a set of 14 trojanized npm packages that masquerade as legitimate calendar and streak…
RedC2 is a cross-platform command-and-control framework for Windows, macOS, and Linux, marketed on cybercrime forums and sold via Red Offsec. It features…
Researchers from UC Berkeley, the Ethereum Foundation, and NYU Shanghai presented a two-turn attack at USENIX Security 2026 that succeeded against Grok…
ISO/IEC 27001:2022 is an international information security management standard. Its Annex A includes access control and identity management controls that organizations can…
Red Agent is an LLM-driven component of RedC2 that translates natural-language prompts into framework beacon commands, enabling operators to execute complex post-exploitation…
DoFun is the manufacturer of Android-based automotive head unit firmware that was exploited by MoYu Group to distribute malware through built-in updaters.…
SentinelLabs is the research arm of SentinelOne, a cybersecurity company. It focuses on vulnerability research, threat hunting, and the discovery of advanced…
Seven malicious Firefox extensions use threat actor-controlled Supabase projects to dynamically serve phishing or decoy content, abusing the platform's infrastructure.
The 37 sports-score shell extensions share a hard-coded credential for API-Sports, a legitimate sports data service, indicating coordinated infrastructure.