Archive
All articles, newest first. Page 4.

IDScan Confirms Breach: 153 Million Driver's Licenses for Sale on Dark Web
IDScan.net has confirmed a data breach exposing millions of identity documents. The dark web service Nexus was selling them with trace…

Midnight Blizzard Used Claude AI to Automate the Malware Evasion Loop
Anthropic disrupted a GTG-20006 operation attributed to Midnight Blizzard: AI agents autonomously modified and recompiled malware to r…

PAPPL Raster Bug Enables Unauthenticated Remote Code Execution on Linux Print Servers
ZDI-26-656 discloses a heap buffer overflow in PAPPL that allows unauthenticated remote code execution when allow_remote=true. The fla…

Microsoft: Vishing on Employee Personal Phones to Breach M365
Storm-3032 and Storm-3121 are calling employees on their personal cell phones to steal Microsoft 365 credentials. The lack of logs on…

VirtualBox VirtioSCSI Memory Bug Opens Guest to Hypervisor
CVE-2026-71132: A memory initialization flaw in VirtualBox's VirtioSCSI device enables information disclosure with scope change. Oracl…

TrendAI Apex One: TmccCore Flaw Allows Local Root Escalation
CVE-2025-71414 in the TmccCore component of Apex One enables local privilege escalation to root. A patch was released in February 2026…

Adobe Photoshop: RCE via DICOM JPEG (CVE-2026-75862) Patched in APSB26-130
An integer overflow in Adobe Photoshop's DICOM JPEG parser enables remote code execution. CVE-2026-75862 carries a CVSS 7.8 rating and…

OpenAI Codex: RCE via .git/config, Patch Available
CVE-2026-19593 enables remote code execution in OpenAI Codex Desktop by exploiting Git configuration. A patch is available: here's wha…

Adobe Acrobat Reader: DigSig Bug Enables RCE via PDF, Urgent Patch Released
On September 10, 2026, Adobe patched CVE-2026-81973, a Use-After-Free vulnerability in the digital signature component of Acrobat Read…

CVE-2026-19397: Unauthenticated RCE in ASUS Control Center Express Agent
A critical flaw in the ASUS Control Center Express Agent exposes managed workstations to unauthenticated remote code execution via a p…

MantaxOtax: The Android Ransomware That Controls, Spies On, and Torments Victims
Zimperium zLabs discovered MantaxOtax, a hybrid Android malware combining AES ransomware with full-spectrum spyware, remote device con…

NI LabVIEW: Integer Overflow in VI File Parsing Exposes Sensitive Data
CVE-2026-18445 affects VI file parsing in NI LabVIEW. The ZDI-26-630 advisory details an integer overflow requiring user interaction t…

PivotC2: The Native FortiGate RAT That Hit 178 Devices
Russian-speaking threat actors are exploiting CVE-2025-25249 to deploy PivotC2, a specialized FortiGate RAT. CISA mandates forensic tr…

Chrome's Seventh 2026 Zero-Day: CISA Mandates Patch by September 23
Google has fixed CVE-2026-87491, an actively exploited zero-day in Chrome's V8 engine. CISA added the flaw to its Known Exploited Vuln…

Backblaze Symlink Flaw in bzreports Allows System File Overwrite
A vulnerability in the Backblaze Personal Computer Backup service lets a local attacker render a Windows system unbootable. Tracked as…

ZDI-26-623: Linux Kernel Advisory Without CVE Complicates Risk Management
On September 9, 2026, Trend Micro published advisory ZDI-26-623, a use-after-free vulnerability in the Linux kernel that allows local…

Azure Entra ID: OAuth Device Code Grant Flaw Exposes Arbitrary Tenant Data
ZDI advisory ZDI-26-629 discloses a pre-disclosure vulnerability in the Azure Entra ID OAuth Device Code Grant endpoint. Unauthenticat…

VirtualBox 7.2.12: VMSVGA Race Condition Enables Hypervisor Escape
Oracle has patched a vulnerability in the VirtualBox 7.2.12 VMSVGA device that allows a local attacker with elevated guest privileges…

VMware Workstation: VMXNET3 Bug with CVSS 9.3 Breaks Hypervisor Isolation
CVE-2026-59346: An integer overflow in the VMXNET3 driver allows code execution on the physical host by anyone controlling a guest VM.…

Proxmox VE 7: Scans and Brute Force Exploit a Logging Blind Spot
A SANS ISC diary documents brute-force attacks against Proxmox VE 7 where an authentication endpoint returns HTTP 200 even on failed l…

GIMP: RCE Flaw in PSP Files Discovered, Update Available
The CVE-2026-4153 vulnerability in GIMP's PSP file parsing allows arbitrary code execution via an integer overflow. The CVSS 7.8 ratin…

WatchGuard FireWare OS: Pre-Auth RCE in Endpoint Service
On September 9, 2026, the ZDI-26-632 advisory disclosed a critical vulnerability in WatchGuard FireWare OS. The flaw resides in the En…

Oracle Outside In: RCE via WPS File, Patch Released September 9, 2026
ZDI-26-638 documents a remote code execution vulnerability in the WPS parser of Oracle Outside In Technology 8.5.8. The CVSS score is…

Flowise: Critical RCE in CSV Agent, Component Removed from Codebase
CVE-2026-70477 with CVSS 9.8 in Flowise's CSV_Agent component: unauthenticated prompt injection leads to remote code execution. The ve…