Cve
Curated coverage and analysis in this editorial area.

DeadLock: The Ransomware Using Polygon to Evade Infrastructure Seizures
DeadLock leverages Polygon smart contracts to rotate proxy servers and host its data leak site, rendering the infrastructure-seizure s…

ShieldBreak: Zero-Day Exploit Targets Windows Defender for SYSTEM Privilege Escalation
Nightmare Eclipse released ShieldBreak, a zero-day exploit achieving SYSTEM privileges on fully patched Windows via Microsoft Defender…

Clop Claims Theft of Technical Data from 43 Organizations; Shell Investigates
The Clop group stole technical data from 43 organizations by exploiting CVE-2026-12569 in PTC Windchill. Shell is investigating a pote…

CVE-2026-62911: Exchange Authentication Bypass Enables Full Mailbox Takeover
Discovered at Pwn2Own by Orange Tsai, ZDI-26-534 hits on-premises Exchange with a CVSS 8.0 score. Microsoft released the patch after 8…

Cisco ISE: Authenticated RCE in invokeScript With Root Escalation Path
CVE-2026-20147 enables authenticated remote code execution as the iseadminportal user on Cisco Identity Services Engine, with a docume…

NGINX WebDAV: Pre-Auth RCE Disclosed in ZDI-26-578
The ZDI-26-578 advisory reveals a critical RCE flaw in the NGINX HTTP DAV module. It is exploitable without authentication via an inte…

WordPress 7.0.3 Fixes Login XSS That Can Lead to RCE via Social Engineering
CVE-2026-64638 is a pre-authentication reflected XSS in the WordPress login screen, discovered by pwn.ai using AI-assisted systems. Ex…

NVIDIA Transformers4Rec Exposed to RCE: ML Checkpoint Turns Weapon
A deserialization flaw in NVIDIA's ML library enables remote code execution via malicious checkpoints. A documented discrepancy betwee…

dnsmasq: DNSSEC Bug Enables Unauthenticated Remote DoS
A vulnerability in dnsmasq's NSEC/NSEC3 DNSSEC record parsing allows remote denial-of-service attacks without authentication. The flaw…

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
The Greatness phishing-as-a-service toolkit has integrated device code phishing, abusing the OAuth 2.0 Device Authorization Grant to b…

CVE-2026-3854: One git push RCE in GitHub, 88% of GHES instances exposed
Wiz Research disclosed a critical RCE in GitHub Enterprise Server exploitable with a single git push command. GitHub patched GitHub.co…

CVE-2026-17583: Three Decades of DNA Evidence at Risk of Digital Tampering
A vulnerability in Thermo Fisher software allows undetected alteration of forensic DNA files. The patch does not validate 30 years of…