All posts tagged: flaws

Hackers are abusing unpatched Windows security flaws to hack into organizations

Hackers are abusing unpatched Windows security flaws to hack into organizations

Hackers have broken into at least one organization using Windows vulnerabilities published online by a disgruntled security researcher over the last two weeks, according to a cybersecurity firm. On Friday, cybersecurity company Huntress said in a series of posts on X that its researchers have seen hackers taking advantage of three Windows security flaws, dubbed BlueHammer, UnDefend, and RedSun.  It’s unclear who the target of this attack is, and who the hackers are. BlueHammer is the only bug among the three vulnerabilities being exploited that Microsoft has patched so far. A fix for BlueHammer was rolled out earlier this week.  It appears that the hackers are exploiting the bugs by using exploit code that the security researcher published online.  Earlier this month, a researcher who goes by Chaotic Eclipse published on their blog what they said was code to exploit an unpatched vulnerability in Windows. The researcher alluded to some conflict with Microsoft as the motivation behind publishing the code.  “I was not bluffing Microsoft and I’m doing it again,” they wrote. “Huge thanks to …

Researchers find major flaws in the historical clinical trials used to justify spanking

Researchers find major flaws in the historical clinical trials used to justify spanking

A recent study suggests that there is no experimental evidence proving physical punishment is an effective way to discipline children. The findings indicate that alternative, non-physical strategies are just as effective at encouraging child cooperation, without the potential risks associated with spanking. The research was published in the journal Child Abuse & Neglect. Spanking remains a widely practiced form of discipline, considered normative and socially acceptable in many cultures. Despite disapproval from some health organizations, it is estimated that globally, two out of every three children aged two to four years have been spanked. Scientists conducted the new study in response to ongoing debates about the merits of physical punishment. Recently, some academics published a commentary arguing that strict experimental trials provide evidence that spanking is an effective way to enforce child compliance. These proponents claimed that laws banning physical discipline are misguided and that spanking should remain an available option for parents. “We explored this topic because a recent invited commentary in a psychiatry journal advocated use of spanking as a means of enforcing …

The Louvre heist: Security flaws and deeper cracks at France’s top museum – France in focus

The Louvre heist: Security flaws and deeper cracks at France’s top museum – France in focus

An emblematic monument of French culture, the Louvre Museum embodies nearly 9,000 years of history and houses more than 600,000 works of art across over 70,000 square metres of gallery space. It is the most visited museum in the world, welcoming around nine million visitors each year – well beyond the capacity for which it was originally designed. In recent years, the institution has been shaken by a series of crises, including a major robbery, fraud and labour tensions. On October 19, 2025, the unthinkable happened: robbers entered the museum through a window in the Apollo Gallery and stole the French Crown Jewels, worth an estimated €88 million. The theft exposed serious security weaknesses within the institution. Five months later, David Desclos returned to the scene. The former burglar had been invited to the Louvre in 2020 to record a podcast. Standing near the balcony used by the thieves, he expressed his frustration: “Bars have been installed on that single window, but when you look around, the place is like Swiss cheese. There are no bars …

VPN flaws allowed Chinese hackers to compromise dozens of Ivanti customers, says report

VPN flaws allowed Chinese hackers to compromise dozens of Ivanti customers, says report

In February 2021, software giant Ivanti discovered that Chinese hackers had breached the network of Pulse Secure, one of its subsidiaries that provided VPN appliances to dozens of companies and government agencies around the world, according to new reporting by Bloomberg. The hackers exploited a secret backdoor they had planted in Pulse Secure’s VPN software, Bloomberg reported, citing Ivanti’s chief security officer at the time and other sources. The backdoor allowed the hackers to gain access to 119 other unnamed organizations that used the company’s same VPN product. Mandiant was reportedly aware of the breaches as well, alerting Ivanti that hackers had exploited the bug to breach European and U.S. military contractors.  The previously unreported breach is the latest example of how acquisitions, layoffs, and cost-cutting driven by private equity firms helped to compromise the quality and security of Ivanti’s most critical technologies. After private investment giant Clearlake Capital Group acquired Ivanti in 2017, Bloomberg reported rounds of cuts — particularly in 2022 — affecting employees who had deep institutional knowledge of the company’s products and …