Security News

165 posts

/sctphantom-linux-kernel-sctp-root/sctphantom-linux-kernel-sctp-root.png
Linux Kernel SCTP Flaw Let Local Users Gain Root for 18 Years

August 10, 2026

An AI found a hole in the Linux kernel that sat open for 18 years, then wrote the exploit that turns a local user into root. The machines were not …

/macos-screen-sharing-pre-auth-rce/macos-screen-sharing-pre-auth-rce.png
macOS Screen Sharing Flaw Let Attackers Take Over a Mac Without a Password

August 9, 2026

Anyone on your network could take over a Mac with Screen Sharing turned on. All it took was the target’s IP address. The login check handed back an old …

/css-webmail-keylogger-outlook/css-webmail-keylogger-outlook.png
Outlook CSS Attack Fakes a Microsoft Sign In to Steal Your Password

August 8, 2026

CSS in an email put a fake Microsoft sign-in over a live Outlook inbox and read the password letter by letter. Opening the message is enough. Outlook, Gmail, …

/ai-labs-models-escaped-cyber-evaluations/ai-labs-models-escaped-cyber-evaluations.png
OpenAI Anthropic and Meta Admit Their Models Hacked Companies During Safety Testing

August 7, 2026

OpenAI, Anthropic and Meta have admitted the same thing in three weeks. Their own models ended up outside the test environment. They broke into at least 5 …

/chaindrop-npm-worm-keyv/chaindrop-npm-worm-keyv.png
ChainDrop Worm Steals Your Keys the Moment You Run npm Install

August 5, 2026

A worm dumped 1,300 stashes of stolen developer keys into public GitHub repos in a day. You ran npm install. That was all. The poison sat in a library npm hands …

/passkey-malware-attack-chrome/passkey-malware-attack-chrome.png
Google Password Manager Passkeys Hijacked by Malware on Windows

August 4, 2026

One 32-byte key protects the passkeys synced to your Google account. On Windows, a researcher lifted it out of Chrome’s memory and signed into a crypto …

/microsoft-copilot-word-ai-worm/microsoft-copilot-word-ai-worm.png
Microsoft Copilot Can Turn a Word File Into an AI Worm That Spreads by Itself

August 3, 2026

A researcher hid white text in a Word file and turned Microsoft Copilot into a worm that rewrites your documents and copies itself into every file it touches. …

/coldcard-seed-entropy-bitcoin-theft/coldcard-seed-entropy-bitcoin-theft.png
Coldcard Wallets Built Guessable Keys and Lost 70 Million Dollars in 41 Minutes

August 2, 2026

An attacker emptied 1,196 Bitcoin wallets in 41 minutes and took 70 million dollars. The owners did nothing wrong. Their hardware wallet had been quietly …

/ntfs3-linux-kernel-cve-pavitra-jha/ntfs3-linux-kernel-cve.png
NTFS3 Kernel Bugs Let a Malicious Disk Corrupt Linux Memory

August 1, 2026

A sixteen-year-old spotted two memory bugs in the Linux kernel’s NTFS driver. That is the code that reads Windows disks. Both rated 7.8 HIGH. Then the …

/ipmi-bmc-password-hash-exposed-servers/ipmi-bmc-password-hash-exposed-servers.png
IPMI Flaw Leaks Password Hashes From 24,650 Exposed Servers

July 30, 2026

A flaw more than 20 years old just left 36,872 servers reachable straight from the internet. Not the websites they run, the servers themselves, through the one …

/medusahvnc-hidden-desktop/medusahvnc-hidden-desktop.png
MedusaHVNC Hijacks Your Bank From a Hidden Windows Desktop You Never See

July 28, 2026

An attacker can open your bank in your own browser, on a second desktop you will never see, and move money while your screen shows nothing wrong. It is called …

/shared-ai-chats-exposed-search-engines/shared-ai-chats-exposed-search-engines.png
Shared AI Chats Are Sitting Exposed on Search Engines

July 27, 2026

Shared AI Chats Exposed on Search Engines. Grok alone leaked around 370,000 of them. Anthropic pulled the leaked Claude share links out of Google over the …

/bitchat-bluetooth-mesh-messaging/bitchat-bluetooth-mesh-messaging.png
Bitchat Is a Bluetooth Mesh Chat That Needs No Internet

July 26, 2026

There is a messaging app with more than 25,000 stars on GitHub that works with no internet. Your phone talks straight to other phones over Bluetooth, and your …

/hermeticreader-adobe-whatsapp-flaw/hermeticreader-adobe-whatsapp-flaw.png
HermeticReader Turned Adobe Acrobat Into a WhatsApp Spy on 329 Million Browsers

July 25, 2026

An Adobe extension on roughly 329 million browsers had a flaw the researchers named HermeticReader, and it let any web page you opened read your WhatsApp Web. …

/karr-alarm-bluetooth-car-theft/karr-alarm-bluetooth-car-theft.png
KARR Car Alarm Bluetooth Flaw Exposes 2.2 Million Cars to Silent Theft

July 23, 2026

The alarm bolted into your car to protect it can now be used to steal it. A person standing a few steps away pulls out a phone, and your doors pop open. More …

/exploitarium-github-zero-day-dump/exploitarium-github-zero-day-dump.png
Exploitarium Dropped 204 Live Exploits for curl libssh2 and Nmap With No Warning

July 22, 2026

Someone published 204 exploit files on GitHub for software you almost certainly use, and told the vendors nothing. The makers found out the same way the …

/nginx-map-regex-rce/nginx-map-regex-rce.png
Nginx Map Regex Flaw Lets One Request Take Over a Server

July 21, 2026

For 15 years, a single crafted web request could quietly take over an nginx server, the software that receives and routes incoming traffic for roughly a third …

/7-zip-xz-heap-overflow/7-zip-xz-heap-overflow.png
7-Zip Carried a Hidden Code Execution Flaw in Its XZ Files for Eight Years

July 20, 2026

You opened an archive in 7-Zip, and the code that let it take over your machine had been sitting there since 2018. It was quietly patched on June 25. You were …

/legacyhive-windows-user-profile-hive/legacyhive-windows-privilege-escalation.png
LegacyHive Reopens a Windows Privilege Hole Microsoft Closed 11 Years Ago

July 19, 2026

For weeks he promised that July 14 would shatter Microsoft’s bones. Patch Tuesday came, Microsoft closed a record 622 holes, and hours later he dropped …

/wordpress-wp2shell-rce/wordpress-wp2shell-rce.png
WordPress Let One Request Read Your Database for 227 Days

July 18, 2026

A hole in WordPress handed your database to someone who never logged in. For 227 days it took one request. It needed no password and no plugin, just an address …

/secure-boot-shim-bypass/secure-boot-shim-bypass.png
Microsoft Signed 11 Files That Bypass Secure Boot

July 15, 2026

Some malware loads before Windows even starts, before your antivirus exists. It survives a full reinstall, and 11 files signed by Microsoft are all it takes. …

/ionstack-android-root-one-link/ionstack-android-root-one-link.png
IonStack Turns One Link Into Full Root on Your Android Phone

July 9, 2026

IonStack You tap one link, and root is already running on your Android 17 phone. You never download a file or approve a permission box because the page does the …

/windows-gdid-tracking/windows-gdid-tracking.png
Windows Hands Your Name to the Police Through One Hidden Number

July 8, 2026

You are completely anonymous and think no one can trace you. But Windows put a permanent number on your machine, it never turns off, and that number is where …

/trojpix-air-gap-attack/trojpix-air-gap-diagram.png
TrojPix Steals Data From Air Gapped Computers Through the Screen

July 7, 2026

TrojPix pulled a file off a computer that connects to nothing. 8.1 megabits a second. 208 meters away. Straight through a 30 cm concrete wall. It went out over …

/jadepuffer-ai-ransomware/jadepuffer-ai-ransomware.png
JADEPUFFER Is the First Ransomware Attack Run Entirely by an AI Agent

July 5, 2026

JADEPUFFER is the first documented ransomware operation run by an AI agent. The agent broke in, stole credentials, jumped to a second target, encrypted a …

/fatfs-sd-card-jailbreak/fatfs-sd-card-jailbreak.png
FatFs Flaw Lets One SD Card Take Over Millions of Devices

July 4, 2026

Millions of devices read an SD card with one small piece of code called FatFs, and researchers just found seven ways to break it. The worst one hands the whole …

/phantom-squatting-ai-domains/phantom-squatting-ai-domains.png
Phantom Squatting Lets Hackers Buy the Fake Websites Your AI Invents

July 1, 2026

Your AI assistant just sent you to a login page that did not exist a few weeks ago, and the person who registered it is already collecting the passwords people …

/winrar-rar-startup-folder-attack/winrar-rar-startup-folder-malware.png
WinRAR Can Still Drop Malware Into Your Startup Folder a Year After the Patch

June 30, 2026

You unzipped a file with WinRAR, the way you always do. Nothing on screen looked wrong. The next morning you logged in and malware was already running, and the …

/gitea-act-runner-container-escape/gitea-docker-container-escape.png
Your Gitea Docker Runner Gives Up Root Even With Privileged Mode Off

June 28, 2026

A Docker container on a Gitea build runner can break out to root on the host, the setting built to stop that does nothing, and there is no patch yet. CVSS 9.9. …

/pedit-cow-linux-root/pedit-cow-linux-kernel-root.png
Pedit COW Turns a Normal Linux User Into Root While the Disk Stays Clean

June 27, 2026

A flaw in the Linux kernel called pedit COW lets a regular, unprivileged user rewrite /bin/su in memory and become root, while the copy on disk never changes …