Skip to content

Polymath Central

Thoughts and musings of David Greenberg, a polymath

Cybersecurity

Frontier AI: Vulnerability Management’s Systemic Revolution

August 25, 2026 Blogmaster

Vulnerability management has been a staple of security programs since the dawn of the cybersecurity discipline. The symbiotic relationship between vulnerability and patch management teams has also existed for that…

Cybersecurity

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

August 25, 2026 Blogmaster

Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del…

Cybersecurity

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

August 25, 2026 Blogmaster

Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. “While the…

Cybersecurity

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

August 25, 2026 Blogmaster

Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor…

Technology

More Details Emerge On How Trump Cronyism Ruined The Attempt To Break Up Ticketmaster

August 25, 2026 Blogmaster

Last March it was revealed that the Trump DOJ stabbed its antitrust lawsuit state partners in the back and struck a terrible settlement with Ticketmaster, scuttling a generational opportunity to…

Cybersecurity

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

August 25, 2026 Blogmaster

Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign…

Cybersecurity

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

August 25, 2026 Blogmaster

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog,…

Technology

Sony Keeps Getting Punched In The Face Over Going Disc-less In Unrelated Places

August 24, 2026 Blogmaster

If Sony thought that the outrage over its decision to make the next PlayStation entirely disc-less was going to dissipate quickly, it was wrong. There are actually multiple organic campaigns…

Cybersecurity

Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning

August 24, 2026 Blogmaster

Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients. McAfee Labs said it detected and…

Technology

Ads and tracking infiltrated TVs. Now they’re coming for monitors.

August 24, 2026 Blogmaster

Ads and tracking have turned TVs into privacy nightmares. Both are so widespread among smart TVs that I’ve written a guide for avoiding them. One recommendation in that guide is…

Posts pagination

1 … 41 42 43 … 365

Polymath Central

Thoughts and musings of David Greenberg, a polymath

Proudly powered by WordPress | Theme: Newsup by Themeansar.