Windows Hello Under the Microscope: Where Microsoft's Login Hits Its Limits
The BSI has dissected Windows Hello for Business in a 169-page report, revealing where Microsoft's biometric login is vulnerable under administrator privileges.
News, guides and insights on hosting, security and IT.
The BSI has dissected Windows Hello for Business in a 169-page report, revealing where Microsoft's biometric login is vulnerable under administrator privileges.
Three containerd vulnerabilities, including CVE-2026-5348 with a CVSS score of 9.4, put Kubernetes environments at risk of host command execution and sensitive…
The Hollowbyte vulnerability in OpenSSL lets attackers permanently block server memory with 11-byte packets, causing denial-of-service conditions.
Two chainable vulnerabilities in WordPress allow unauthenticated code execution on the web server and are already being actively exploited.
A critical flaw (CVE-2026-42533) in Nginx enables unauthenticated heap buffer overflows, denial-of-service attacks, and potentially remote code execution.
A flaw in the Microsoft 365 Moodle plugin lets attackers impersonate other users and potentially gain administrator access by exploiting the UPN-based authenti…
Broadcom patches seven CVEs in VMware Avi Load Balancer, including a critical flaw that lets unauthenticated attackers gain full access to the controller.
Eset discovered eleven vulnerable UEFI shims signed by Microsoft that have made Secure Boot bypassable for over a decade, enabling bootkit infections on a wide…
The macOS malware CrashStealer disguises itself as Apple's CrashReporter and steals passwords, keychain data, and crypto wallets.