Security News

105 posts

/ghostlock-smb-file-lock-ransomware/featured-image.png
GhostLock Delivers Ransomware Impact on Windows Without Touching a Single File

May 11, 2026

GhostLock locks every shared file on any Windows network in minutes using nothing but a standard login, and every security tool watching stays completely …

/pamdoora-linux-ssh-backdoor/featured-image.png
PamDOORa Steals SSH Credentials on Linux by Hiding Inside PAM Where No Antivirus Looks

May 10, 2026

A backdoor called PamDOORa targets Linux systems through PAM and steals SSH credentials from every user who logs in. It leaves no trace in process lists, …

/dirty-frag-linux-root/featured-image.gif
Dirty Frag Gives Root Access on Every Major Linux Distribution

May 8, 2026

A new Linux zero-day called Dirty Frag gives any local user full root access on every major Linux distribution, and right now no distribution has a patched …

/vm2-sandbox-escape/featured-image.png
vm2 Node.js Sandbox Escape 12 Critical Vulnerabilities Two Without a Patch

May 7, 2026

Twelve critical vulnerabilities were just published for vm2, a Node.js security library that sits inside millions of applications. Three of them score a perfect …

/chrome-gemini-nano-silent-install/featured-image.png
Google Chrome Silently Installs a 4 GB AI Model on Your Machine Without Asking

May 6, 2026

Google Chrome installed a 4 GB AI model on your machine without asking. The pitch is that it runs locally, keeping your data off Google’s servers. The AI …

/microsoft-edge-cleartext-passwords/featured-image.png
Microsoft Edge Stores Every Saved Password in Cleartext Memory at Startup

May 5, 2026

Microsoft Edge loads every saved password into memory the moment the browser opens. They sit there in plain readable text for the entire session, even for sites …

/digicert-breach-defender-cerdigent-false-positive/featured-image.png
DigiCert Hacked With a Screensaver File and Defender Flagged Root Certificates as Malware

May 4, 2026

Microsoft Defender deleted DigiCert root certificates from Windows machines worldwide and flagged them as Trojan:Win32/Cerdigent.A!dha. Those certificates tell …

/hashcat-cracks-the-cracker-cve-2026/featured-image.png
Hashcat 7.1.2 Has Three Unpatched Vulnerabilities That Can Compromise Your Machine

May 3, 2026

Hashcat v7.1.2 has three unpatched vulnerabilities, all rated 9.8 out of 10. The tool that security professionals use to crack passwords can be used to crack …

/cpanel-authentication-bypass-cve-2026-41940/featured-image.png
cPanel Authentication Bypass CVE-2026-41940 Gave Attackers 64 Days of Root Access

May 1, 2026

For 64 days, attackers had root access to cPanel servers managing over 70 million websites, and nobody had to know a single password to get in. A crafted HTTP …

/copy-fail-linux-kernel-cve-2026-31431/featured-image.png
Copy Fail CVE-2026-31431: Nine Years of Root Access Hidden in the Linux Kernel

April 30, 2026

Since 2017, every major Linux distribution has been shipping a flaw that hands root access to any local user. The exploit is a 732-byte Python script that uses …

/github-rce-cve-2026-3854/featured-image.png
GitHub RCE CVE-2026-3854: One Semicolon, Millions of Private Repositories

April 29, 2026

GitHub RCE CVE. A semicolon broke GitHub. One character in a push option field, and a security researcher was running code on the backend servers that store …

/phantomrpc-windows-privilege-escalation/featured-image.png
PhantomRPC: Windows Has a Privilege Escalation Problem Microsoft Won't Fix

April 28, 2026

Last week at Black Hat Asia in Singapore, a Kaspersky researcher publicly demonstrated PhantomRPC: five separate ways to take any standard Windows service …

/fast16-pre-stuxnet-cyber-sabotage/featured-image.png
Fast16: The Cyberweapon That Predates Stuxnet by Five Years

April 26, 2026

For 21 years, a cyberweapon called fast16 sat completely undetected. This one did not destroy machines or blow things up. It corrupted the math. Scientists …

/bing-rce-cve-2026-33819/featured-image.png
Microsoft Bing CVSS 10.0: CVE-2026-33819 Remote Code Execution Explained

April 25, 2026

Bing had a CVSS 10.0 vulnerability in its backend infrastructure, the same infrastructure that powers Edge, Windows Search, and Copilot integrations across …

/bitwarden-cli-supply-chain-attack/featured-image.png
Bitwarden CLI Backdoored on npm for 93 Minutes

April 24, 2026

Bitwarden’s CLI was backdoored and pushed to npm on April 22, 2026. It was live for 93 minutes. Every developer who installed it during that window has to …

/pypi-supply-chain-attack-xinference-teampcp/featured-image.png
How TeamPCP Poisoned Six Python Packages and Breached Over 1000 Organizations in Five Weeks

April 23, 2026

A group of attackers has been quietly poisoning Python packages for five weeks straight. They have exfiltrated data from over 500,000 infected machines, hit …

/aspnet-core-dataprotection-hmac-cve-2026-40372/featured-image.png
How CVE 2026 40372 Breaks ASP.NET Core Authentication

April 22, 2026

The security fix Microsoft shipped in 2010 to stop attackers from decrypting ASP.NET traffic and forging authentication cookies just got quietly broken by a …

/snipping-tool-ntlm-hash-leak/featured-image.png
Windows Snipping Tool NTLM Hash Leak CVE-2026-33829

April 21, 2026

The Windows Snipping Tool can hand your Windows password hash to an attacker through a single click on a crafted link, and what the victim sees is the familiar …

/redsun-undefend-defender-zero-days/featured-image.png
RedSun and UnDefend: Two Unpatched Windows Defender Zero-Days

April 19, 2026

Two unpatched Windows Defender zero-days have been actively exploited since April 16th, and both of them work on fully patched Windows 10, Windows 11, and …

/iterm2-cat-readme-rce-cve-2026-41253/featured-image.png
iTerm2 RCE via cat readme.txt (CVE-2026-41253)

April 18, 2026

iTerm2, the terminal emulator that ends up on almost every Mac developer’s machine, is vulnerable to a remote code execution attack that occurs when …

/microsoft-365-mailbox-rules-attack/featured-image.png
Microsoft 365 Mailbox Rules Are Being Weaponized

April 17, 2026

Microsoft 365 mailbox rules are being weaponized as a core technique behind $2.77 billion in annual Business Email Compromise losses, and attackers are creating …

/nginx-ui-mcpwn-cve-2026-33032/featured-image.png
Nginx-UI MCPwn (CVE-2026-33032): Full Server Takeover With One Unauthenticated Request

April 16, 2026

A critical vulnerability in nginx-ui has been actively exploited since March 2026, and it gives any attacker on the network full control over the nginx server …

/php-composer-command-injection-cve-2026-40261/featured-image.png
PHP Composer Command Injection CVE-2026-40261

April 15, 2026

PHP Composer Has Two Flaws That Run Arbitrary Commands on Developer Machines PHP Composer, the package manager that almost every PHP developer uses to build …

/msbuild-lolbin-fileless-attack/featured-image.png
MSBuild LOLBin: How Hackers Run Malware on Windows Without Leaving a Trace

April 14, 2026

MSBuild.exe is a LOLBin, a legitimate Windows tool being abused to run malware on fully patched machines without dropping a single file on disk, and Windows …

/docker-authorization-bypass-cve-2026-34040/featured-image.png
Docker Had a 10-Year Security Bypass Hidden in Plain Sight

April 12, 2026

Docker’s Security Layer Has Been Broken Since 2016, And The Fix Doesn’t Finish the Job. One padded HTTP request. That is all it takes to silently …

/desckvb-rat-fileless-malware-2026/featured-image.png
DesckVB RAT Uses Windows' Own Tools to Stay Hidden and Leaves Almost Nothing Behind

April 11, 2026

A Remote Access Trojan called DesckVB has been actively hitting systems throughout 2026, running almost entirely inside memory with barely anything written to …

/bluehammer-windows-defender-zero-day/featured-image.png
Windows Defender Is Being Used to Hack Windows

April 10, 2026

Windows Defender, the built-in antivirus running on every Windows machine, has a zero-day exploit with full source code sitting on GitHub. No patch, no CVE, and …

/fiber-optic-eavesdropping/featured-image.png
Fiber Optic Cables Turned Into Hidden Microphones

April 9, 2026

Fiber optic cables running through your walls can be turned into hidden microphones that record every word spoken in the room. This is not a theory anymore. …

/gpubreach-attack-nvidia-gpu/featured-image.png
GPUBreach Attack Gives Hackers a Root Shell on NVIDIA GPUs

April 8, 2026

NVIDIA GPUs with GDDR6 memory can be used to take full control of a system, including a root shell, bypassing hardware defenses that were supposed to stop …

/axios-npm-supply-chain-attack/featured-image.png
Axios npm Supply Chain Attack: How a Fake Meeting Compromised 100 Million Downloads

April 4, 2026

Axios, the JavaScript library with over 100 million weekly downloads, was compromised on March 31st. For roughly three hours, every fresh install of those two …