-
A recently patched vulnerability in MECCHA CHAMELEON allowed attacker-controlled Steam Workshop maps to write files to arbitrary locations on Windows systems, potentially resulting in remote code execution once the victim restarted their device. Securi…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat actors are actively exploiting a critical vulnerability in the Super Forms WordPress plugin, allowing them to upload PHP backdoors and gain remote code execution. This flaw, tracked as CVE-2026-14894, affects Super Forms versions 6.3.313 and ear…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Plex has urged users to promptly update their Plex Media Server and Plex Desktop software following the release of fixes for several undisclosed security issues in older versions. The recommended versions are Plex Media Server 1.43.3 and Plex Desktop 1…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat actors have repurposed an AI prompt-injection technique known as ASCII smuggling to evade email security controls at massive scale, hiding invisible Unicode characters within financial phishing lures. Microsoft observed the activity reach more t…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Chinese-speaking threat operators have been observed using Claude, Qwen and DeepSeek-powered AI agents as operational components in a second intrusion campaign targeting government, political, education and industrial organizations across Asia. The cam…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
TP-Link has released security updates for two vulnerabilities found in its Archer AX55 v4 wireless router. These vulnerabilities could allow attackers on the local network to crash a key networking service, potentially execute code, or steal administra…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A Microsoft 365 email security-control bypass that lets attackers submit unauthenticated messages posing as internal users by leaving one SMTP field blank. The technique targets Exchange Online’s RejectDirectSend setting and does not represent a vulner…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Google has released an urgent update for Chrome Stable to address CVE-2026-85046, a high-severity type confusion vulnerability in the V8 JavaScript and WebAssembly engine that is actively being exploited. This flaw can allow remote attackers to execute…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A recently released proof-of-concept, named FalconFlank, claims to reveal a local privilege escalation vulnerability in the CrowdStrike Falcon Sensor on Windows. CrowdStrike is actively investigating these claims and has advised customers to turn off t…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
North Korea-linked Contagious Interview operators have expanded their developer-targeting malware delivery operation beyond booby-trapped Git hooks and coding repositories, using trojanized macOS applications distributed as disk images and installer pa…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


