Hostile SIMs exploit spec-compliant commands
Malicious SIM cards can force phones to leak files, drop to 2G, or crash—by abusing standard SIM commands.
30 results for “research”
Malicious SIM cards can force phones to leak files, drop to 2G, or crash—by abusing standard SIM commands.
Marcus Hutchins, who halted WannaCry, recounts his path from malware author to security researcher.
Recent research shows passkey protections can be bypassed without breaking the underlying cryptography.
PortSwigger's HTTP Terminator, guided by a human, finds novel vulnerability classes and hundreds of live targets.
New research reveals how the NatJack attack class exploits fundamental design flaws in NAT, bypassing standard network protections.
Researchers identified a new technique dubbed INTERRUPT INJECTION that exploits timing gaps to bypass existing CPU branch protections.
Researchers reveal that vulnerabilities in AI agent foundations allow prompt injection to bypass critical trust boundaries.
Researchers identified a post-exploitation toolkit concealed within Oracle database schema objects to bypass endpoint security tools.
New research reveals widespread security flaws in baseboard management controllers across major global server manufacturers.
Security researchers uncovered vulnerabilities in WebKit that allow websites to bypass Apple's Private Relay and view IP addresses.
New research shows that the choice of AI orchestration framework can increase agent compromise rates by more than 2.6 times.
The University of Kentucky’s Economic Development Collaborative is set to host an August event focused on aligning AI with industry.
Researchers identify a sophisticated phishing campaign using brand impersonation to deploy remote access malware on Windows.
Researchers identified three methods to compromise passkeys, highlighting vulnerabilities in Google's synchronization process.
Threat actors are breaking malicious projects into small, fragmented tasks to circumvent AI safety guardrails, according to research.
Researchers are tracking a sophisticated campaign against Central Asian governments involving custom OctLurk and SilkLurk malware.
Researchers have identified a threat actor using the DeepSeek AI model to automate the lifecycle of cyberattacks on exposed servers.
Researchers report a rise in AI-driven malware and evolving social engineering, marking a shift in how attackers scale operations.
New research shows AI-discovered flaws are exploited at the same rate as traditional ones, debunking 'vulnpocalypse' fears.
The OT security firm adds $1.52 million in seed funding to its coffers to scale research and operations for its AI-driven platform.
Learn how security researchers and developers use proof of concept demonstrations to validate vulnerabilities and improve software resilience.
Researchers used AI agents to uncover remote code execution vulnerabilities in Redis, prompting seven urgent security releases.
Researchers identify a recurring security flaw where AI agents blindly execute commands based on predictable, hallucinated names.
Researchers find top AI models consistently inventing identical, non-existent library names that attackers could potentially weaponize.
New research details how threat actors are ditching delayed credential harvesting for live, session-based account hijacking.
Researchers have uncovered an Iran-linked campaign using fake VPNs and media players to deploy spyware against specific user groups.
The research lab is seeking a $1 billion valuation to develop AI agents capable of automating complex office workflows.
Researchers report that compromised hotel network gateways are redirecting business travelers to sophisticated phishing portals.
Researchers demonstrate that macOS fails to revalidate web-downloaded applications after they have been modified by users.
Researchers detail how malicious GPU workloads could trigger cascading power grid failures through high-frequency electrical modulation.