Archive
All articles, newest first. Page 17.

ZDI-26-573: Pre-Auth Linux Kernel KSMBD Vulnerability Scores CVSS 9.3
A critical flaw in the in-kernel KSMBD SMB server allows unauthenticated out-of-bounds reads leading to information disclosure and pot…

Ransomware Q2 2026: 2,139 Victims and Payment Rate Crashes to 23%
Ransomware isn't slowing down — it's fragmenting. Q2 2026 saw 93 active groups, up from 71 at the start of the year. The top-10 share…

Rubrik Zero Labs Unveils RPE: From Word Document to Shell on Copilot
Remote Prompt Execution turns prompt injection into full enterprise identity compromise on Microsoft 365 Copilot. The five-stage chain…

Attackers Shut Down Polish Turbine via Private APN: First Real-World OT Case
CERT Polska documented the first real-world attack on critical infrastructure through a misconfigured private cellular APN. A Polish c…

DeadLock: The Ransomware Using Polygon to Evade Infrastructure Seizures
DeadLock leverages Polygon smart contracts to rotate proxy servers and host its data leak site, rendering the infrastructure-seizure s…

Mustang Panda Arms CoolClient with Signed Rootkit: EDR in the Kernel Crosshairs
HoneyMyte deploys msagent.sys, a kernel-mode rootkit driver signed with an expired 2013 certificate. It hides processes, files, and C2…

AmnesiaStealer: The macOS Malware That Hijacks Victim Browser Sessions in Real Time
Jamf Threat Labs has documented AmnesiaStealer, a Rust-based macOS infostealer that clones the victim's Chromium profile, launches it…

ShieldBreak: Zero-Day Exploit Targets Windows Defender for SYSTEM Privilege Escalation
Nightmare Eclipse released ShieldBreak, a zero-day exploit achieving SYSTEM privileges on fully patched Windows via Microsoft Defender…

Generative AI as a Cyber Force Multiplier: Three North Korean Groups, Three Tactics
Famous Chollima (47% of state-backed tech attacks), Kimsuky (HelloDoor malware with AI assistance), and APT45 (recursive prompting): t…

Clop Claims Theft of Technical Data from 43 Organizations; Shell Investigates
The Clop group stole technical data from 43 organizations by exploiting CVE-2026-12569 in PTC Windchill. Shell is investigating a pote…

CVE-2026-62911: Exchange Authentication Bypass Enables Full Mailbox Takeover
Discovered at Pwn2Own by Orange Tsai, ZDI-26-534 hits on-premises Exchange with a CVSS 8.0 score. Microsoft released the patch after 8…

SafePal Breach Exposes 39,798 Customers: Wallet Secure, Supply Chain Not
SafePal disclosed a data breach on August 16, 2026, exposing order details for nearly 40,000 customers. The incident stemmed from an a…

ZDI-26-575: TOCTOU in Linux Kernel Net Scheduler Enables Local Privilege Escalation
A TOCTOU race condition in the Linux kernel's Net Scheduler packet classifier API allows local privilege escalation. The fix introduce…

Cisco ISE: Authenticated RCE in invokeScript With Root Escalation Path
CVE-2026-20147 enables authenticated remote code execution as the iseadminportal user on Cisco Identity Services Engine, with a docume…

NGINX WebDAV: Pre-Auth RCE Disclosed in ZDI-26-578
The ZDI-26-578 advisory reveals a critical RCE flaw in the NGINX HTTP DAV module. It is exploitable without authentication via an inte…

WordPress 7.0.3 Fixes Login XSS That Can Lead to RCE via Social Engineering
CVE-2026-64638 is a pre-authentication reflected XSS in the WordPress login screen, discovered by pwn.ai using AI-assisted systems. Ex…

NVIDIA Transformers4Rec Exposed to RCE: ML Checkpoint Turns Weapon
A deserialization flaw in NVIDIA's ML library enables remote code execution via malicious checkpoints. A documented discrepancy betwee…

dnsmasq: DNSSEC Bug Enables Unauthenticated Remote DoS
A vulnerability in dnsmasq's NSEC/NSEC3 DNSSEC record parsing allows remote denial-of-service attacks without authentication. The flaw…

Criminals Buy Expired Domains to Inherit Reputation and Traffic
A single threat actor spent nearly $7 million on over 10,000 expired domains, weaponizing their inherited trust signals for illegal st…
Beacon CRM: The Cloud Revealed as a Lock With the Key Left in the Door
Beacon CRM confirmed the total theft of its customer database covering 1,500+ UK charities. The cause: an AWS access key exposed in pu…

CVE-2026-65400: From Patch to Exploit in 4 Hours on macOS Screen Sharing
The Dutch NCSC confirms active exploitation of CVE-2026-65400: a pre-authentication bypass in macOS Screen Sharing granting root acces…

Keyv Compromised: Malware Exploits Signed Provenance and AI Agent Config Files
The August 4, 2026 supply chain attack on keyv delivered malware with valid SLSA attestations and OIDC provenance signatures. AI agent…

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
The Greatness phishing-as-a-service toolkit has integrated device code phishing, abusing the OAuth 2.0 Device Authorization Grant to b…

CVE-2026-3854: One git push RCE in GitHub, 88% of GHES instances exposed
Wiz Research disclosed a critical RCE in GitHub Enterprise Server exploitable with a single git push command. GitHub patched GitHub.co…