top of page
Search


Ransomware attacks targeted at weekends and holidays
Most ransomware attacks occur during weekends and holidays, times of distraction or disruption when the majority of SOCs are not adequately staffed. A new report from Semperis finds that 52 percent of surveyed organizations in the US, UK, France, Germany, Italy, Spain, Singapore, Canada, Australia and New Zealand were targeted at holidays or weekends. Alarmingly, 78 percent of companies cut security operation centre (SOC) staffing by 50 percent or more during holidays and w
Nov 23, 2025


New Attack Combines Ghost SPNs and Kerberos Reflection to Elevate Privileges on SMB Servers
A sophisticated privilege escalation vulnerability in Windows SMB servers, leveraging Ghost Service Principal Names (SPNs) and Kerberos authentication reflection to achieve remote SYSTEM-level access. Microsoft designated this as CVE-2025-58726 , an “SMB Server Elevation of Privilege” flaw impacting all Windows versions absent enforced SMB signing. According to Semperis, the issue persists in environments with default Active Directory (AD) configurations, underscoring Kerber
Oct 29, 2025


Quick Share’s Security Leap: Android’s File-Sharing Shield
In the ever-evolving landscape of mobile technology, Google’s Quick Share is poised for a significant security upgrade. According to recent reports, the file-sharing feature could soon integrate with Android’s Advanced Protection Program, potentially revolutionizing how users safeguard their data during transfers. This development comes amid growing concerns over unauthorized access and file theft in an increasingly connected world. The rumor, first highlighted by Android Aut
Oct 27, 2025


Forbes: ‘Midnight In The War Room’ And The Unsung Heroes Of Cybersecurity
If you ask Dr. Chase Cunningham whether we’re in a cyber war, he won’t hedge.“We’ve already had our cyber Pearl Harbor,” he told me. “It just didn’t happen in a single day.” That line lingered with me because it’s not hyperbole. Cunningham, one of the featured voices in Midnight in the War Room , knows what he’s talking about. The new documentary—produced by Semperis —offers an unfiltered look at the modern cyber battlefield and the people trying to hold the line. It’s raw,
Oct 15, 2025


Semperis unveils Ready1 to boost identity crisis recovery
Semperis has introduced Ready1 for Identity Crisis Management to support organisations in recovering from identity-based cyberattacks and resuming normal business operations. Ready1 brings together several of Semperis' existing offerings, including Active Directory Forest Recovery (ADFR), Disaster Recovery for Entra Tenant (DRET), and Identity Forensics and Incident Response (IFIR), alongside its enterprise crisis management system. The new product is aimed at enhancing opera
Oct 8, 2025


Vulnerability in Windows RPC protocol: Spoofing and impersonation attacks reported
SafeBreach experts have disclosed details of a vulnerability in the Windows Remote Procedure Call (RPC) protocol, patched by Microsoft in the July 2025 update. The flaw, CVE-2025-49760 , allowed an attacker to conduct spoofing attacks and impersonate a legitimate server using the Windows storage mechanism. Ron Ben Yizak discussed the discovery at the DEF CON 33 conference. Read more.
Sep 20, 2025


Cohesity Partners with Semperis on Active Directory
Cohesity and Semperis Announce Groundbreaking Offering that Unifies Data and Identity Resilience Cohesity and Semperis today announced a new product, Cohesity Identity Resilience, powered by Semperis, to defend enterprises’ critical Identity infrastructure, including Microsoft Active Directory assets from cyberattacks. Now available for purchase from Cohesity, the solution is the strongest of its kind in the market, enabling companies to proactively harden defenses, recover r
Sep 16, 2025


New Win-DoS Flaws Could Weaponize Windows Domain Controllers for DDoS Attacks
A newly discovered attack method could allow hackers to crash public Windows domain controllers (DCs) worldwide and weaponize them for...
Aug 10, 2025


Hackers Hijacked Google’s Gemini AI With a Poisoned Calendar Invite to Take Over a Smart Home
For likely the first time ever, security researchers from Safebreach have shown how AI can be hacked to create real-world havoc, allowing...
Aug 5, 2025


Safebreach research shows Google Calendar invites let researchers hijack Gemini to leak user data
By sending a calendar invite with an embedded prompt injection, often hidden in the event title, attackers can potentially exfiltrate...
Aug 3, 2025


Ransomware Attacks Escalate to Physical Threats Against Executives
Ransomware actors are resorting to extreme measures to pressure victims into paying demands, including threats of physical harm to...
Jul 30, 2025


KT and HEQA Security Partner to Deploy Quantum Key Distribution for Telecom Infrastructure
Korea Telecom (KT) , a major telecommunications provider, has initiated a collaboration with HEQA Security , a company specializing in...
Jun 27, 2025


nOAuth Vulnerability Still Affects 9% of Microsoft Entra SaaS Apps Two Years After Discovery
New research has uncovered continued risk from a known security weakness in Microsoft's Entra ID , potentially enabling malicious actors...
Jun 24, 2025


Semperis adds detection for dMSA attacks in Windows Server
S emperis has announced new detection capabilities in its Directory Services Protector platform in collaboration with Akamai to address...
Jun 9, 2025


Semperis Named Ransomware Protection Business of the Year by Australian Cyber Awards
“Semperis is honored to be recognised as the Ransomware Protection Business of the Year, particularly among such an esteemed group of...
May 15, 2025


Enterprises struggle with serious gaps in cyber response plans
A new survey of 1,000 businesses across the UK, UK, Europe and the Asia-Pacific region reveals a worrying disconnect between...
May 13, 2025


*NEW* SAFEBREACH PROPAGATE
Gain Visibility Beyond the Breach Augment your breach and attack simulation (BAS) deployment with automated attack path validation...
Apr 30, 2025


Semperis Is Now a Preferred Vendor on the California SLP
Today, identity-related attacks—which target critical identity systems such as Microsoft Active Directory (AD), Entra ID, and...
Apr 17, 2025


SafeBreach leverages Visa Threat Intelligence for payment fraud prevention
SafeBreach, a breach and attack simulations company, has expanded its collaboration with Visa to leverage the company’s Threat...
Apr 10, 2025


Water and Electricity Companies Suffer Severe Damage from Cyber-Attacks
80 percent of operators were targeted multiple times. More than half of cyber-attacks experienced by critical services disrupted...
Apr 4, 2025
bottom of page
