Articles

  • 1 week ago | darkreading.com | Jai Vijayan

    Multiple attackers are actively exploiting a recently patched Windows vulnerability that exposes authentication credentials, despite Microsoft releasing a fix for it in March. CVE-2025-24054 is an NTLM (for NT LAN Manager) hash disclosure spoofing vulnerability that Microsoft identified as being of moderate severity and something that attackers were less likely to exploit, even though it requires only minimal user interaction to trigger.

  • 1 week ago | darkreading.com | Jai Vijayan

    The maintainers of the Apache Roller open source blogging platform patched a maximum severity bug that allowed continued access to the app even after a user changed their password. The issue had to do with insufficient session expiration, a vulnerability that occurs when a system or app fails to invalidate an existing user's active session after a password change.

  • 1 week ago | darkreading.com | Jai Vijayan

    The tendency of code-generating large language models (LLMs) to produce completely fictitious package names in response to certain prompts is significantly more widespread than commonly recognized, a new study has shown. Researchers at the University of Texas at San Antonio (UTSA), the University of Oklahoma, and Virginia Tech recently analyzed 16 widely used code-generating LLMs and two prompt datasets to get an understanding of the scope of the package hallucination problem.

  • 2 weeks ago | darkreading.com | Jai Vijayan

    After weeks of carefully worded denials, Oracle on April 7 appears to have notified an unknown number of its customers of a breach involving two servers containing usernames and passwords. A supposed copy of Oracle's breach notification appeared on social media this week, but the company has yet to confirm to Dark Reading whether it indeed issued the advisory to customers — or how widely disseminated it was.

  • 2 weeks ago | darkreading.com | Jai Vijayan

    For the second time in 2025, Microsoft has dropped a security update stuffed with fixes for more than 100 vulnerabilities, setting up Windows admins for yet another all-hands-on-deck patching marathon. Microsoft's April Patch Tuesday update addresses 126 vulnerabilities, including a zero-day flaw that attackers are already exploiting in the wild and 11 others deemed more likely to be targeted in the future.

Contact details

Socials & Sites

Try JournoFinder For Free

Search and contact over 1M+ journalist profiles, browse 100M+ articles, and unlock powerful PR tools.

Start Your 7-Day Free Trial →

X (formerly Twitter)

Followers
5K
Tweets
1K
DMs Open
No
Jaikumar Vijayan
Jaikumar Vijayan @jaivijayan
9 Jun 23

https://t.co/ndeIsPFBlj

Jaikumar Vijayan
Jaikumar Vijayan @jaivijayan
4 Oct 22

https://t.co/yS6xXo76XP

Jaikumar Vijayan
Jaikumar Vijayan @jaivijayan
16 Sep 22

https://t.co/L872zmf0VV