Cybersecurity
Curated coverage and analysis in this editorial area.

Windows: win32kfull Driver Bug Allows Escalation to SYSTEM
Microsoft released a fix on August 11, 2026 for CVE-2026-62712, a vulnerability in the win32kfull driver that allows code running with…

CVE-2026-54984: RCE in Windows ICC Parser, but the Vector Is Local
Microsoft patched CVE-2026-54984, an RCE vulnerability in the Windows color management component. The CVSS indicates a local attack ve…

Red Hat ACM: Subscription Controller Becomes Bridge for Total Privilege Escalation
A vulnerability in Red Hat Advanced Cluster Management allows users with edit permissions on a single namespace to gain full cluster-a…

Kenwood DNR1007XR: Firmware Update Flaw Enables Root RCE via Symlink Following
A vulnerability in the Kenwood DNR1007XR firmware update process allows a physically present attacker to achieve arbitrary code execut…

Local Malware Bypasses Google Passkeys: The Flaw Is in Chrome, Not FIDO2
Palo Alto Networks Unit 42 research demonstrates that local malware can bypass FIDO2 passkeys in Chrome on Windows using three techniq…

Aeternum: The Botnet Loader That Uses Polygon as C2
Unit 42 analyzes Aeternum, a C++ botnet loader that moves command-and-control entirely onto the public Polygon blockchain. On August 1…

Trend Cleaner One Pro: Cleanup Service Turned Weapon for Arbitrary File Deletion
ZDI-26-496 reveals a vulnerability in Cleaner One Pro's Junk Files Cleanup service that allows a local attacker to delete arbitrary fi…

Apple Patches CVE-2026-20700: Zero-Day in dyld Survived Two Decades in iOS
Apple has fixed CVE-2026-20700, a zero-day memory corruption vulnerability in the dyld dynamic linker that existed in iOS for over a d…

TONTOU: The AMD Attack Exposing the Gap Between Linux Patches and Vendor Disclosure
The TONTOU attack bypasses Spectre-v2 mitigations on AMD Zen 1–4 processors. The Linux kernel received a fix on June 2, 2026, but AMD'…

Cisco FMC Under Attack: Static Credentials Exploited, No Workaround Available
CVE-2026-20316 in Cisco Secure Firewall Management Center involves hard-coded static credentials, confirmed active exploitation, and n…

Battering RAM: $50 Physical Attack Bypasses SGX and SEV-SNP on DDR4 Systems
A sub-$50 DDR4 interposer compromises confidential computing. Vendors classify physical attacks as out of scope. Article based on a si…

The Microsoft 365 Account Takeover That Leaves No Trace
Proofpoint tracks active campaigns since September 2025 that abuse Microsoft's OAuth 2.0 device authorization grant flow. MFA is bypas…