Security News

105 posts

/configconfusion-google-no-bounty/configconfusion-google-no-bounty.png
Google Told the Researcher Nice Catch Then Refused to Pay and Never Fixed It

June 23, 2026

Google told a security researcher his bug was a nice catch, lined up his payout, then eleven days later called it harmless and refused to pay a cent. The flaw …

/usbliter8-iphone-bootrom-exploit/usbliter8-iphone-bootrom-exploit.png
Usbliter8 Breaks the iPhone XS and 11 and Apple Cannot Patch It

June 21, 2026

usbliter8 takes control of the iPhone XS and iPhone 11 before iOS even loads, and no update Apple ships can ever close it. The flaw lives in the SecureROM, the …

/fortibleed-fortinet-credential-leak/fortibleed-fortinet-credential-leak.png
FortiBleed Cracks Open 80,000 Fortinet Firewalls And Thousands Used 123456

June 20, 2026

FortiBleed Fortinet credential leak. Attackers can log into more than 80,000 corporate firewalls right now, and on 2,645 of them the password was 123456. The …

/openbsd-pap-empty-password-bypass/openbsd-pap-empty-password-bypass.png
OpenBSD Let Attackers Log In With an Empty Password for 27 Years

June 17, 2026

A 27-year-old flaw in OpenBSD let attackers bypass its PPP login with nothing more than an empty username and an empty password. Hand a vulnerable system a …

/optinmonster-supply-chain-backdoor/optinmonster-supply-chain-backdoor.png
OptinMonster Supply Chain Attack Hits 1.2 Million WordPress Sites

June 16, 2026

1.2 million WordPress sites were caught in a supply chain attack last week, where the admin’s own login quietly created a secret account and planted a …

/atomic-arch-aur-malware/atomic-arch-aur-malware.png
Hackers Hijacked 400 Arch Linux AUR Packages to Install Malware

June 13, 2026

More than 400 packages in the Arch User Repository (AUR) were hijacked this week, and the attacker never broke into a single system to do it. They took over …

/greatxml-bitlocker-bypass/greatxml-bitlocker-bypass.png
GreatXML Turns Windows Defender's Offline Scan Into a BitLocker Bypass

June 12, 2026

Nightmare-Eclipse is back again, this time with a BitLocker bypass called GreatXML that runs straight through Microsoft’s own antivirus. On a Windows …

/miasma-worm-ai-coding-agents/miasma-worm-ai-coding-agents.png
The Miasma Worm Hid in Microsoft's Code and Ran the Moment You Opened It

June 11, 2026

GitHub disabled 73 of Microsoft’s own repositories in 105 seconds, after a worm called Miasma planted a credential stealer inside Microsoft’s Azure …

/rogueplanet-windows-defender-zero-day/rogueplanet-windows-defender-zero-day.png
RoguePlanet Windows Defender Zero Day Hands Any User Full SYSTEM Control

June 10, 2026

Nightmare-Eclipse is back, with a new exploit called RoguePlanet. Windows 10 and 11 have a new zero-day that lets a user with no rights take complete control of …

/nftables-root-use-after-free/nftables-root-use-after-free.png
One Character in nftables Hands Any Linux User Root

June 9, 2026

One extra character in the Linux kernel hands a normal user root. A single ! that does not belong inside nftables, the firewall built into Debian and Ubuntu by …

/internet-explorer-webbrowser-rce/internet-explorer-webbrowser-rce.png
Internet Explorer Can Still Take Over a Fully Patched Windows PC in 2026

June 8, 2026

Internet Explorer can still take over a fully patched Windows machine, years after Microsoft retired it in 2022. The code that ran it was never removed from …

/chromium-background-fetch-botnet/chromium-background-fetch-botnet.png
Google Leaked the Chrome Bug That Turns Your Browser Into a Botnet

June 7, 2026

A single visit to one website can quietly turn your browser into part of a botnet, and the working code to do it is now still sitting out in the open. It …

/home-proxy-network/home-proxy-network-residential-proxy.png
Your Home Devices Are Being Turned Into Proxies for the AI Industry

June 6, 2026

Your phone, your TV, your router, anything in your home with an internet connection can be put to work crawling the web for the AI industry, and nothing on the …

/http2-bomb-remote-dos/http2_bomb.png
HTTP/2 Bomb Takes Down nginx Apache IIS Envoy and Cloudflare

June 3, 2026

A new exploit called HTTP/2 Bomb lets one ordinary home computer take down nginx, Apache, Microsoft IIS, Envoy and Cloudflare Pingora, the web servers behind a …

/meta-ai-instagram-account-takeover/meta-ai-instagram-account-takeover.png
Hackers Took Over Instagram Accounts By Asking Meta's AI Support Bot

June 2, 2026

Hackers took over some of the most valuable accounts on Instagram over the weekend by asking Meta’s own AI support bot to hand them the keys, and it …

/nightmare-eclipse-microsoft-zero-day-war/nightmare-eclipse-microsoft-zero-day-war.png
Six Working Windows Zero Days and the Researcher Microsoft Called a Criminal

May 31, 2026

Six working Windows attacks are sitting in the open right now, three of them already seen in a real intrusion, and the researcher who published them did it …

/frost-ssd-browser-spying/featured-image.png
FROST Lets a Website See Which Sites and Apps You Have Open by Timing Your SSD

May 30, 2026

FROST lets a website time your SSD and see which sites and apps you have open, even ones running in a different browser. It needs no malware and nothing to …

/badhost-starlette-cve-2026-48710/featured-image.png
BadHost Breaks Into FastAPI and vLLM With a Single Character

May 27, 2026

BadHost is one character in an HTTP header that bypasses authentication on FastAPI, vLLM, LiteLLM, and the Python MCP SDK. They all run on Starlette. Starlette …

/ghost-cms-cve-2026-26980/featured-image.png
Ghost CMS SQL Injection Stole Admin Keys From 700 Websites With One Request

May 26, 2026

A SQL injection vulnerability in Ghost CMS has turned Harvard University, Oxford University, and DuckDuckGo into malware distribution platforms. Visitors arrive …

/google-api-key-23-minutes/featured-image.png
Google API Keys Keep Working for 23 Minutes After You Delete Them

May 23, 2026

Google tells you the key is gone. It keeps working for 23 more minutes. When you delete a Google API key, a dialog appears that says the following: “Once …

/ghosttree-ntfs-defender-bypass/featured-image.png
GhostTree Makes Windows Defender Stop Scanning With Two Lines of Code

May 21, 2026

GhostTree makes Windows Defender stop scanning. Two lines of code, no admin rights, and malware sitting right next to it goes completely undetected. A Varonis …

/voidstealer-chrome-abe-bypass/featured-image.png
VoidStealer Steals Chrome Master Key Using a Debugger Trick

May 20, 2026

Chrome keeps saved passwords locked behind one master key. VoidStealer steals that key using a tool Chrome cannot block. It does not need administrator rights, …

/reaper-shub-macos-stealer/featured-image.png
Reaper Bypasses Apple Security to Steal macOS Passwords and Hijack Crypto Wallets

May 19, 2026

Reaper swipes macOS passwords and crypto wallets, backdoors the machine, and pretends to be Apple, Microsoft, and Google in the same attack. Apple shipped an …

/miniplasma-windows-zero-day-system-access/featured-image.png
MiniPlasma Windows Zero Day Gives Any User SYSTEM Access on a Fully Patched Machine

May 18, 2026

A Windows zero-day called MiniPlasma gives any standard user full SYSTEM access on a fully patched machine. Microsoft patched it in December 2020, assigned it …

/gtig-ai-zero-day/featured-image.png
Google Catches the First AI Built Zero-Day and Stops a Mass Attack Before It Starts

May 17, 2026

Google caught a criminal group that used AI to find a zero-day in a popular web admin tool and had a working exploit ready for a mass attack against thousands …

/ssh-keysign-pwn-cve-2026-46333/featured-image.png
ssh-keysign-pwn Lets Any Linux User Steal SSH Keys and Password Hashes Without Root

May 16, 2026

ssh-keysign-pwn is a newly disclosed Linux kernel vulnerability that gives any unprivileged local user direct access to the SSH host private keys of a server …

/yellowkey-bitlocker-bypass-winre/featured-image.png
YellowKey Bypasses BitLocker on Windows 11 Using Nothing But a Folder on a USB Stick

May 15, 2026

A folder copied to a USB stick is enough to bypass BitLocker encryption on Windows 11 and Windows Server 2022 and 2025, giving an attacker with a few minutes of …

/nginx-rift-cve-2026-42945/featured-image.png
NGINX Has Had This Bug Since 2008 and One Request Is Enough to Trigger It

May 14, 2026

NGINX Rift: An 18-year-old memory corruption bug in NGINX, the web server running on roughly one-third of all websites globally, lets an unauthenticated …

/windows-dns-rce-2026/featured-image.png
A Critical Windows DNS Flaw Lets Attackers Run Code on Any Machine Without Logging In

May 13, 2026

Microsoft patched a critical heap buffer overflow in the Windows DNS Client. An attacker needs no account and no help from the person sitting at the machine to …

/macsync-clickfix-claude/featured-image.png
MacSync Malware Spreads Through Claude.ai and Replaces Your Crypto Wallet Apps

May 12, 2026

MacSync is spreading through Google ads that lead directly to claude.ai. The installation guide there was written by Claude itself. One Terminal command and the …