Security News

129 posts

/microsoft-copilot-word-ai-worm/microsoft-copilot-word-ai-worm.png
Microsoft Copilot Can Turn a Word File Into an AI Worm That Spreads by Itself

August 3, 2026

A researcher hid white text in a Word file and turned Microsoft Copilot into a worm that rewrites your documents and copies itself into every file it touches. …

/coldcard-seed-entropy-bitcoin-theft/coldcard-seed-entropy-bitcoin-theft.png
Coldcard Seed Flaw Drained 70 Million in Bitcoin From 1,196 Wallets

August 2, 2026

An attacker emptied 1,196 Bitcoin wallets in 41 minutes and took 70 million dollars. The owners did nothing wrong. Their hardware wallet had been quietly …

/ntfs3-linux-kernel-cve-pavitra-jha/ntfs3-linux-kernel-cve.png
NTFS3 Kernel Bugs Let a Malicious Disk Corrupt Linux Memory

August 1, 2026

A sixteen-year-old spotted two memory bugs in the Linux kernel’s NTFS driver. That is the code that reads Windows disks. Both rated 7.8 HIGH. Then the …

/ipmi-bmc-password-hash-exposed-servers/ipmi-bmc-password-hash-exposed-servers.png
IPMI Flaw Leaks Password Hashes From 24,650 Exposed Servers

July 30, 2026

A flaw more than 20 years old just left 36,872 servers reachable straight from the internet. Not the websites they run, the servers themselves, through the one …

/medusahvnc-hidden-desktop/medusahvnc-hidden-desktop.png
MedusaHVNC Hijacks Your Bank From a Hidden Windows Desktop You Never See

July 28, 2026

An attacker can open your bank in your own browser, on a second desktop you will never see, and move money while your screen shows nothing wrong. It is called …

/shared-ai-chats-exposed-search-engines/shared-ai-chats-exposed-search-engines.png
Shared AI Chats Are Sitting Exposed on Search Engines

July 27, 2026

Shared AI Chats Exposed on Search Engines. Grok alone leaked around 370,000 of them. Anthropic pulled the leaked Claude share links out of Google over the …

/bitchat-bluetooth-mesh-messaging/bitchat-bluetooth-mesh-messaging.png
Bitchat Is a Bluetooth Mesh Chat That Needs No Internet

July 26, 2026

There is a messaging app with more than 25,000 stars on GitHub that works with no internet. Your phone talks straight to other phones over Bluetooth, and your …

/hermeticreader-adobe-whatsapp-flaw/hermeticreader-adobe-whatsapp-flaw.png
HermeticReader Turned Adobe Acrobat Into a WhatsApp Spy on 329 Million Browsers

July 25, 2026

An Adobe extension on roughly 329 million browsers had a flaw the researchers named HermeticReader, and it let any web page you opened read your WhatsApp Web. …

/karr-alarm-bluetooth-car-theft/karr-alarm-bluetooth-car-theft.png
KARR Car Alarm Bluetooth Flaw Exposes 2.2 Million Cars to Silent Theft

July 23, 2026

The alarm bolted into your car to protect it can now be used to steal it. A person standing a few steps away pulls out a phone, and your doors pop open. More …

/exploitarium-github-zero-day-dump/exploitarium-github-zero-day-dump.png
Exploitarium Dropped 204 Live Exploits for curl libssh2 and Nmap With No Warning

July 22, 2026

Someone published 204 exploit files on GitHub for software you almost certainly use, and told the vendors nothing. The makers found out the same way the …

/nginx-map-regex-rce/nginx-map-regex-rce.png
Nginx Map Regex Flaw Lets One Request Take Over a Server

July 21, 2026

For 15 years, a single crafted web request could quietly take over an nginx server, the software that receives and routes incoming traffic for roughly a third …

/7-zip-xz-heap-overflow/7-zip-xz-heap-overflow.png
7-Zip Carried a Hidden Code Execution Flaw in Its XZ Files for Eight Years

July 20, 2026

You opened an archive in 7-Zip, and the code that let it take over your machine had been sitting there since 2018. It was quietly patched on June 25. You were …

/legacyhive-windows-user-profile-hive/legacyhive-windows-privilege-escalation.png
LegacyHive Reopens a Windows Privilege Hole Microsoft Closed 11 Years Ago

July 19, 2026

For weeks he promised that July 14 would shatter Microsoft’s bones. Patch Tuesday came, Microsoft closed a record 622 holes, and hours later he dropped …

/wordpress-wp2shell-rce/wordpress-wp2shell-rce.png
WordPress Let One Request Read Your Database for 227 Days

July 18, 2026

A hole in WordPress handed your database to someone who never logged in. For 227 days it took one request. It needed no password and no plugin, just an address …

/secure-boot-shim-bypass/secure-boot-shim-bypass.png
Microsoft Signed 11 Files That Bypass Secure Boot

July 15, 2026

Some malware loads before Windows even starts, before your antivirus exists. It survives a full reinstall, and 11 files signed by Microsoft are all it takes. …

/ionstack-android-root-one-link/ionstack-android-root-one-link.png
IonStack Turns One Link Into Full Root on Your Android Phone

July 9, 2026

IonStack You tap one link, and root is already running on your Android 17 phone. You never download a file or approve a permission box because the page does the …

/windows-gdid-tracking/windows-gdid-tracking.png
Windows Hands Your Name to the Police Through One Hidden Number

July 8, 2026

You are completely anonymous and think no one can trace you. But Windows put a permanent number on your machine, it never turns off, and that number is where …

/trojpix-air-gap-attack/trojpix-air-gap-diagram.png
TrojPix Steals Data From Air Gapped Computers Through the Screen

July 7, 2026

TrojPix pulled a file off a computer that connects to nothing. 8.1 megabits a second. 208 meters away. Straight through a 30 cm concrete wall. It went out over …

/jadepuffer-ai-ransomware/jadepuffer-ai-ransomware.png
JADEPUFFER Is the First Ransomware Attack Run Entirely by an AI Agent

July 5, 2026

JADEPUFFER is the first documented ransomware operation run by an AI agent. The agent broke in, stole credentials, jumped to a second target, encrypted a …

/fatfs-sd-card-jailbreak/fatfs-sd-card-jailbreak.png
FatFs Flaw Lets One SD Card Take Over Millions of Devices

July 4, 2026

Millions of devices read an SD card with one small piece of code called FatFs, and researchers just found seven ways to break it. The worst one hands the whole …

/phantom-squatting-ai-domains/phantom-squatting-ai-domains.png
Phantom Squatting Lets Hackers Buy the Fake Websites Your AI Invents

July 1, 2026

Your AI assistant just sent you to a login page that did not exist a few weeks ago, and the person who registered it is already collecting the passwords people …

/winrar-rar-startup-folder-attack/winrar-rar-startup-folder-malware.png
WinRAR Can Still Drop Malware Into Your Startup Folder a Year After the Patch

June 30, 2026

You unzipped a file with WinRAR, the way you always do. Nothing on screen looked wrong. The next morning you logged in and malware was already running, and the …

/gitea-act-runner-container-escape/gitea-docker-container-escape.png
Your Gitea Docker Runner Gives Up Root Even With Privileged Mode Off

June 28, 2026

A Docker container on a Gitea build runner can break out to root on the host, the setting built to stop that does nothing, and there is no patch yet. CVSS 9.9. …

/pedit-cow-linux-root/pedit-cow-linux-kernel-root.png
Pedit COW Turns a Normal Linux User Into Root While the Disk Stays Clean

June 27, 2026

A flaw in the Linux kernel called pedit COW lets a regular, unprivileged user rewrite /bin/su in memory and become root, while the copy on disk never changes …

/configconfusion-google-no-bounty/configconfusion-google-no-bounty.png
Google Told the Researcher Nice Catch Then Refused to Pay and Never Fixed It

June 23, 2026

Google told a security researcher his bug was a nice catch, lined up his payout, then eleven days later called it harmless and refused to pay a cent. The flaw …

/usbliter8-iphone-bootrom-exploit/usbliter8-iphone-bootrom-exploit.png
Usbliter8 Breaks the iPhone XS and 11 and Apple Cannot Patch It

June 21, 2026

usbliter8 takes control of the iPhone XS and iPhone 11 before iOS even loads, and no update Apple ships can ever close it. The flaw lives in the SecureROM, the …

/fortibleed-fortinet-credential-leak/fortibleed-fortinet-credential-leak.png
FortiBleed Cracks Open 80,000 Fortinet Firewalls And Thousands Used 123456

June 20, 2026

FortiBleed Fortinet credential leak. Attackers can log into more than 80,000 corporate firewalls right now, and on 2,645 of them the password was 123456. The …

/openbsd-pap-empty-password-bypass/openbsd-pap-empty-password-bypass.png
OpenBSD Let Attackers Log In With an Empty Password for 27 Years

June 17, 2026

A 27-year-old flaw in OpenBSD let attackers bypass its PPP login with nothing more than an empty username and an empty password. Hand a vulnerable system a …

/optinmonster-supply-chain-backdoor/optinmonster-supply-chain-backdoor.png
OptinMonster Supply Chain Attack Hits 1.2 Million WordPress Sites

June 16, 2026

1.2 million WordPress sites were caught in a supply chain attack last week, where the admin’s own login quietly created a secret account and planted a …

/atomic-arch-aur-malware/atomic-arch-aur-malware.png
Hackers Hijacked 400 Arch Linux AUR Packages to Install Malware

June 13, 2026

More than 400 packages in the Arch User Repository (AUR) were hijacked this week, and the attacker never broke into a single system to do it. They took over …