Cybersecurity
Cybersecurity collects analysis on vulnerabilities, exploits, patch management, ransomware, supply chain, AI security and threat intelligence. These articles help IT professionals, developers and security analysts follow operational threats, vendor updates and technical trends.

HAMLOCK: Invisible AI Backdoor Spans Chip and Software
Researchers demonstrate HAMLOCK, a supply-chain attack that splits a neural-network backdoor between minimal software weight changes (…

ZDI-26-356: Apache Reverse Proxy Betrayed by AJP Backend
CVE-2026-34032 in mod_proxy_ajp lets a compromised AJP backend read out of bounds, with potential escalation to RCE via vulnerability…

Adobe Acrobat Reader: UAF in Annotation Parser Enables RCE via Malicious PDF
CVE-2026-27220: use-after-free in Adobe Acrobat Reader DC's Annotation parser, CVSS 7.8. Patch available, no known in-the-wild exploit…

ShinyHunters Hits 100+ Universities with Oracle Zero-Day
CVE-2026-35273 in PeopleSoft EMHub: unauthenticated RCE, CVSS 9.8, 68% of victims in higher education. CISA mandates patch by June 15.

X.Org Server: Root LPE via XkbSetCompatMap; Patch Released
CVE-2026-33999 in X.Org Server enables local privilege escalation to root. Discovered by ZDI, the fix follows a coordinated disclosure…

Maine Disables Breach Notification Portal After Fake Discord and VRChat Disclosures
Maine's government portal automatically published data breach notifications without verification, facilitating the spread of misinform…

LangGraph Vulnerability Chain Grants RCE via AI Agent Persistence
Check Point Research has uncovered a SQL injection and deserialization chain in LangGraph that enables RCE on self-hosted deployments.…

Europol and DOJ Dismantle AudiA6: A Critical Hub for Ransomware Money Laundering Smashed
In a major operation on June 10, 2026, authorities arrested two administrators in Georgia and seized 25 domains and 30+ servers. The A…

Algorithmic Exploitation: How TikTok and Instagram Reels Amplify Vidar Malware
ReversingLabs research reveals threat actors are using fake Spotify Premium tutorials to distribute the Vidar infostealer via PowerShe…

Microsoft Patches Actively Exploited Exchange Zero-Day, Mandates Dual-Layer Defense
Microsoft has released a permanent patch for CVE-2026-42897, an XSS zero-day in Exchange OWA. Despite the update, the EEMS mitigation…

Windows Narrator Braille: LPE Hidden in the Accessibility Path
CVE-2026-48565: Local escalation to SYSTEM via brlapi, the Windows Braille service frequently overlooked by enterprise patching cycles.

CVE-2026-3886: QEMU virtio-gpu Integer Overflow Enables Guest-to-Host Escape
An integer overflow in QEMU’s virtio-gpu driver allows local privilege escalation from guest to host with a CVSS score of 8.8. The ups…