10/29

Exploiting Ghost SPNs and Kerberos Reflection for SMB Privilege Elevation

https://www.semperis.com/blog/exploiting-ghost-spns-and-kerberos-reflection-for-smb-server-privilege-elevation/
Exploiting Ghost SPNs and Kerberos Reflection for SMB Privilege Elevation

Edit fiddle - JSFiddle - Code Playground

https://jsfiddle.net/yo0a24dj/
Edit fiddle - JSFiddle - Code Playground

Active Exploits Hit Dassault and XWiki — CISA Confirms Critical Flaws Under Attack

https://thehackernews.com/2025/10/active-exploits-hit-dassault-and-xwiki.html
Active Exploits Hit Dassault and XWiki — CISA Confirms Critical Flaws Under Attack

Microsoft sued for allegedly tricking millions into Copilot M365 subscriptions

https://www.bleepingcomputer.com/news/microsoft/microsoft-sued-for-allegedly-tricking-millions-into-copilot-m365-subscriptions/
Microsoft sued for allegedly tricking millions into Copilot M365 subscriptions

New physical attacks are quickly diluting secure enclave defenses from Nvidia, AMD, and Intel - Ars Technica

https://arstechnica.com/security/2025/10/new-physical-attacks-are-quickly-diluting-secure-enclave-defenses-from-nvidia-amd-and-intel/
New physical attacks are quickly diluting secure enclave defenses from Nvidia, AMD, and Intel - Ars Technica

Experts Reports Sharp Increase in Automated Botnet Attacks Targeting PHP Servers and IoT Devices

https://thehackernews.com/2025/10/experts-reports-sharp-increase-in.html
Experts Reports Sharp Increase in Automated Botnet Attacks Targeting PHP Servers and IoT Devices