A proof-of-concept exploit for the critical Active Directory vulnerability CVE-2025-21293, discovered in September 2024, allows low-privilege attackers to escalate to SYSTEM-level privileges. It exploits excessive permissions in the “Network Configuration Operators” group, enabling malicious DLL execution via Performance Counters. Microsoft patched the vulnerability in January 2025, urging organizations to update promptly to mitigate risks.
Abandoned AWS S3 Buckets Can be Reused to Hijack Global Software Supply Chain
WatchTowr Labs has identified a security flaw in abandoned AWS S3 buckets that could allow attackers to hijack software supply chains, potentially leading to large-scale