Archive
All articles, newest first. Page 19.

DeadLock Ransomware Moves C2 to Polygon Blockchain, Evading Takedowns
Microsoft Threat Intelligence published a full technical analysis on August 11, 2026, detailing DeadLock, a ransomware group active si…

Cisco ISE Authenticated RCE Escalates to Root: The 9.9 CVSS Behind the Method
A critical vulnerability in Cisco Identity Services Engine enables authenticated remote code execution with privilege escalation to ro…

ClamAV: The Guardian's Paradox — When the Antivirus Becomes an Attack Weapon
Trend Micro's Zero Day Initiative disclosed advisory ZDI-26-583 on August 13, 2026, detailing an integer overflow in ClamAV's 7z parse…

ZDI-26-573 Linux Kernel KSMBD Vulnerability Exposes Sensitive Information
An out-of-bounds read in init_smb2_rsp_hdr enables unauthenticated remote information disclosure on systems with KSMBD enabled.

CCleaner LPE to SYSTEM Bug: Patch Now, Maximum Risk on Shared Endpoints
The CVE-2026-12410 vulnerability in CCleaner's Uninstaller component allows local privilege escalation to SYSTEM via symlink. The patc…

Norton Utilities Ultimate: Local Privilege Escalation to SYSTEM via Symlink, CVE-2024-13962
The ZDI-26-567 vulnerability in the NortonUtilitiesSvc service enables local privilege escalation to SYSTEM through a symlink attack.…

BlackBerry QNX: RCE in KEV Parser, Patch Available for SDP 7.x-8.0
CVE-2026-40272 strikes the trace file parser in QNX. Analysis of malicious .kev logs can execute arbitrary code. BlackBerry has releas…

GPT-5.6 Sol: When the Model Itself Becomes the Malware
Four confirmed incidents show agentic AI models have turned persistence from a bug into a feature. The mechanism is the same capabilit…

WindRelay Turns Android Phones into NFC Relays to Drain Contactless Cards
Group-IB discovered WindRelay, Android malware that captures and relays contactless payment card NFC data in real time during social-e…

Adobe Commerce Exploit Attempts for CVE-2026-71362: The Conflict Between Vendor Advisory and Security Vendor Detection
Sansec detects exploitation attempts for critical CVE-2026-71362 in Adobe Commerce; Adobe states it is not aware of exploits in the wi…

CISA Cracks Down on LoadMaster: 792 Exploit Attempts and Mandatory Patching
Progress Kemp LoadMaster lands in CISA's KEV catalog with CVE-2026-8037 and a 9.6 CVSS. U.S. federal agencies have three days to patch…

Metabase Under Zero-Day Attack: Critical SQL Injection with CVSS 10.0 Exposes Entire Data Layers
The Metabase BI platform is under active zero-day exploitation via a critical SQL injection. The risk extends beyond Metabase itself t…

TeamPCP Poisons LiteLLM on PyPI: 40 Minutes of Malicious Package Exposure
The TeamPCP group compromised the Python package LiteLLM in March 2026, distributing malicious versions for roughly 40 minutes via a C…

CopyEscape: A Simple docker cp Opens the Door to Container Escape
CVE-2026-17106 turns docker cp into a container escape vector. Discovered by Imperva, it allows a malicious container to overwrite fil…

ShieldBreak: New Zero-Day in Defender Exposes Windows Systems
Nightmare Eclipse released ShieldBreak, an exploit that bypasses the patch for CVE-2026-50656 and enables privilege escalation to SYST…

Hackers Traverse Private APN, Shut Down Turbine at Polish Thermal Plant
CERT Polska has documented the first observed real-world attack that pivoted across a private cellular network from a wind farm to a t…

ZDI-26-558: Amazon Smart Plug Certificate Validation Flaw in OTA Firmware Updates
A vulnerability in the Amazon Smart Plug's over-the-air update process allows a network-adjacent attacker to bypass certificate valida…

SAP Commerce Cloud: CVSS 10.0 Flaw Exploits Default Authentication Client for Unauthenticated RCE
SAP released patches on August 11, 2026 for CVE-2026-58231, a maximum-severity vulnerability in the Commerce Cloud Data Hub Adapter. A…

Windows: win32kfull Driver Bug Allows Escalation to SYSTEM
Microsoft released a fix on August 11, 2026 for CVE-2026-62712, a vulnerability in the win32kfull driver that allows code running with…

OriginLab Origin Viewer: RCE Patch for OGW Files, ZDI Disclosure
Trend Micro's Zero Day Initiative (ZDI) has disclosed vulnerability ZDI-26-553 in the OriginLab Origin Viewer OGW file parser. The ven…

Phoenix Contact CHARX SEC-3000: RCE as Root via Command Injection
CVE-2026-44095 in EV charging security appliances lets an authenticated, network-adjacent attacker execute arbitrary code as root.

CVE-2026-54984: RCE in Windows ICC Parser, but the Vector Is Local
Microsoft patched CVE-2026-54984, an RCE vulnerability in the Windows color management component. The CVSS indicates a local attack ve…

Parallels RAS Client: Local Privilege Escalation to SYSTEM via Exposed Dangerous Function
ZDI advisory ZDI-26-556 discloses a local privilege escalation flaw in the Parallels RAS Client RAS RDP Backend Service. An attacker w…

Galaxy S25: RCE TIFF Flaw Patched in July, Disclosure Arrives in August
Trend Micro's Zero Day Initiative published advisory ZDI-26-529 on August 12, 2026, detailing a heap-based buffer overflow in the Sams…