-
Security researchers have disclosed a local privilege escalation vulnerability in the Linux kernel related to the Reliable Datagram Sockets (RDS) zero-copy send path. This vulnerability could let an unprivileged local attacker gain root privileges. It …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Microsoft has expanded its incentives for security researchers focusing on Dynamics 365 and Power Platform, offering rewards ranging from $1,250 to $60,000 for qualifying vulnerabilities. The program prioritizes flaws that have a direct and demonstrabl…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat actors are moving from using artificial intelligence as a productivity aid to deploying autonomous agentic systems that can execute major portions of an intrusion with minimal human intervention. Google Threat Intelligence Group (GTIG) has docum…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat actors are increasingly weaponizing Microsoft’s Volume Shadow Copy Service (VSS) for two distinct objectives: removing recovery options before ransomware deployment and extracting credential material from protected Windows files. The shift means…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The UK government has started implementing passkey authentication for GOV. UK One Login,UK One Login, providing over 23 million users with a faster and more secure way to access public services. This initiative aims to reduce reliance on passwords and …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
In August 2026, automated threat activity targeting exposed Vite development servers increased significantly. Attackers aimed to extract cloud credentials, environment files, and infrastructure state data by exploiting a critical file-read vulnerabilit…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat actors hijacked HBO Max’s verified Reddit account, u/hbomax, and used its trusted advertising identity to distribute 108 malicious ClickFix advertisements in a coordinated 48-hour malvertising campaign. The operation, tracked as PasteSwitch, del…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat actors exploited the critical FortiGate SSL-VPN vulnerability CVE-2024-21762 to target the Thai broadband provider Triple T Broadband (3BB). They gained access to its internal environment and deployed MeshCentral remote management agents for per…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Cisco has released security updates to address a critical SQL injection vulnerability in the Cisco Secure Email Gateway. This vulnerability can be exploited remotely and without authentication, allowing attackers to execute arbitrary commands with root…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly identified Cyclops Blink variant has resurfaced on compromised Cisco Secure Firewall Management Center (FMC) appliances, adding active internal-network scanning and programmable packet-sniffing capabilities to an already mature modular implant….
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


