• Microsoft has disclosed a critical security flaw affecting SQL Server, officially tracked as CVE-2026-21262. Released on March 10, 2026, this elevation of privilege vulnerability exposes organizations to significant risks by allowing malicious actors to gain unauthorized control over enterprise database environments. With a maximum severity rating of “Important” and a CVSS 3.1 score of 8.8, […]

    The post Microsoft SQL Server Zero-Day Exposes Privilege Escalation Risk for Users appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft Corp. today pushed security updates to fix at least 77 vulnerabilities in its Windows operating systems and other software. There are no pressing “zero-day” flaws this month (compared to February’s five zero-day treat), but as usual some patches may deserve more rapid attention from organizations using Windows. Here are a few highlights from this month’s Patch Tuesday.

    Image: Shutterstock, @nwz.

    Two of the bugs Microsoft patched today were publicly disclosed previously. CVE-2026-21262 is a weakness that allows an attacker to elevate their privileges on SQL Server 2016 and later editions.

    “This isn’t just any elevation of privilege vulnerability, either; the advisory notes that an authorized attacker can elevate privileges to sysadmin over a network,” Rapid7’s Adam Barnett said. “The CVSS v3 base score of 8.8 is just below the threshold for critical severity, since low-level privileges are required. It would be a courageous defender who shrugged and deferred the patches for this one.”

    The other publicly disclosed flaw is CVE-2026-26127, a vulnerability in applications running on .NET. Barnett said the immediate impact of exploitation is likely limited to denial of service by triggering a crash, with the potential for other types of attacks during a service reboot.

    It would hardly be a proper Patch Tuesday without at least one critical Microsoft Office exploit, and this month doesn’t disappoint. CVE-2026-26113 and CVE-2026-26110 are both remote code execution flaws that can be triggered just by viewing a booby-trapped message in the Preview Pane.

    Satnam Narang at Tenable notes that just over half (55%) of all Patch Tuesday CVEs this month are privilege escalation bugs, and of those, a half dozen were rated “exploitation more likely” — across Windows Graphics Component, Windows Accessibility Infrastructure, Windows Kernel, Windows SMB Server and Winlogon. These include:

    CVE-2026-24291: Incorrect permission assignments within the Windows Accessibility Infrastructure to reach SYSTEM (CVSS 7.8)
    CVE-2026-24294: Improper authentication in the core SMB component (CVSS 7.8)
    CVE-2026-24289: High-severity memory corruption and race condition flaw (CVSS 7.8)
    CVE-2026-25187: Winlogon process weakness discovered by Google Project Zero (CVSS 7.8).

    Ben McCarthy, lead cyber security engineer at Immersive, called attention to CVE-2026-21536, a critical remote code execution bug in a component called the Microsoft Devices Pricing Program. Microsoft has already resolved the issue on their end, and fixing it requires no action on the part of Windows users. But McCarthy says it’s notable as one of the first vulnerabilities identified by an AI agent and officially recognized with a CVE attributed to the Windows operating system. It was discovered by XBOW, a fully autonomous AI penetration testing agent.

    XBOW has consistently ranked at or near the top of the Hacker One bug bounty leaderboard for the past year. McCarthy said CVE-2026-21536 demonstrates how AI agents can identify critical 9.8-rated vulnerabilities without access to source code.

    “Although Microsoft has already patched and mitigated the vulnerability, it highlights a shift toward AI-driven discovery of complex vulnerabilities at increasing speed,” McCarthy said. “This development suggests AI-assisted vulnerability research will play a growing role in the security landscape.”

    Microsoft earlier provided patches to address nine browser vulnerabilities, which are not included in the Patch Tuesday count above. In addition, Microsoft issued a crucial out-of-band (emergency) update on March 2 for Windows Server 2022 to address a certificate renewal issue with passwordless authentication technology Windows Hello for Business.

    Separately, Adobe shipped updates to fix 80 vulnerabilities — some of them critical in severity — in a variety of products, including Acrobat and Adobe Commerce. Mozilla Firefox v. 148.0.2 resolves three high severity CVEs.

    For a complete breakdown of all the patches Microsoft released today, check out the SANS Internet Storm Center’s Patch Tuesday post. Windows enterprise admins who wish to stay abreast of any news about problematic updates, AskWoody.com is always worth a visit. Please feel free to drop a comment below if you experience any issues apply this month’s patches.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cal AI faces data breach claims after hackers post alleged data of 3 million users, including emails, health details, and subscriptions.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • HONOLULU—“What happens when you concentrate on one [AI] model and all of a sudden that model isn’t available to you?” That’s the reality that U.S. Indo-Pacific Command is living right now, its resources and requirements director said here Monday.

    The audience, after a beat, laughed cautiously at the realization that Bob Stephenson was likely referring to Anthropic’s Claude model.

    “It happens,” Stephenson said Monday at the Pacific Operational Science & Technology conference. “You know, I actually started thinking about this last September. We were working on a plan to be more model-neutral in our workforce. Now we’re just going faster.”

    More than a year ago, INDOPACOM integrated AI throughout its headquarters. Less than two weeks ago, President Trump directed federal agencies to stop using tools by Anthropic. And on Monday, the company sued the Pentagon, Defense Secretary Pete Hegseth, and others, claiming illegal retaliation.

    Stephenson, moderating a panel focused on advanced partnerships for multi-domain command and control, described his own “AI journey.” 

    “My challenge right now is: I’m trying—if you understand the seven functions of joint warfare…those things all happen simultaneously.”

    “If you’re going to send a ship into position to launch a missile…you have to worry about, does it have enough fuel to get there? Is it going to have to be refueled when it gets back? What about reloading? What’s the status of the launcher? What’s the status of the weapon? And so on and so forth. And so these things all interact. So we’re trying to use AI to create agentic workflows to allow us to do this at scale.”

    On the other side of the world, in Central Command, he said, “They’re executing about 1,000 fires a day. That’s a lot. That’s what we think, that’s what modern warfare looks like. They’re working really hard to try to stay up with this, and they’re using some AI tools that actually worked well for us.”

    Panelist Paul Gaertner, project leader for integrated command, control, communications and computing for the Australian Department of Defense, told the audience that he is worried about both under-trusting and over-trusting AI.

    Stephenson said he shares that concern. But when asked about allowing autonomous forms to manage themselves and mitigate their own risk, he said the answer is “sort of.”

    “My boss tells us that in offensive weapons, there must be human agency,” Stephenson said, referring to commander Adm. Sam Paparo. But for defensive weapons, “the criteria varies. If somebody is shooting at you, there’s much more latitude” in having systems to automatically defend against the threat.

    Stephenson, who retired from the Navy in 2003 after 30 years of service, noted that the U.S. has had autonomous weapons systems since he was a captain. 

    “There is a need for autonomy. There is a desire for autonomy at the edge, but with some of them, every weapon we have has a failsafe. We obviously don’t want to unleash a swarm that’s just going to fly around and go after the wrong thing. So there will be limits,” he said. But “we have these things called torpedoes that we have shot for, you know, a year or two, they worked out this thing called anti-circular run that kept the torpedo from zigzagging around” and coming back to “attack the thing that shot it. So think of a similar constraint for autonomous systems.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • ShinyHunters claims to have stolen data from 400 firms via Salesforce portals and is threatening to leak the information unless ransom demands are paid.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • China-linked hackers targeted Qatar using fake war news lures to spread PlugX backdoor malware and spy on military and energy sectors.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Senate has confirmed President Donald Trump’s pick to lead Cyber Command and the National Security Agency in a dual-hatted capacity, giving the signals intelligence and hacking titans their first permanent leader in almost a year.

    Gen. Joshua Rudd was confirmed in a 71-29 vote on Tuesday, three months after he was nominated to the position. NSA and Cyber Command have been without a permanent leader since far-right activist Laura Loomer pushed for the firing of the post’s previous occupant, Gen. Timothy Haugh, last April. Since then, Lt. Gen. William Hartman has led the agency in an acting capacity.

    On Monday, the first procedural hurdle to Rudd’s confirmation cleared in a 68-28 vote. The nominee to lead Cyber Command and the NSA usually moves through the Senate without such a vote, but Senate Majority Leader John Thune, R-S.D., bypassed a hold from Sen. Ron Wyden, D-Ore., to confirm Rudd after Wyden pledged to block the nominee over concerns about his experience.

    “The country needs an NSA director with experience in U.S. signals intelligence activities around the world. General Rudd does not have that experience,” Wyden’s written floor remarks said.

    Rudd comes from a less traditional background than past military leaders who have led the two organizations. Up until now, he served as the deputy commander of U.S. Indo-Pacific Command, and has spent his career largely in special operations and joint command roles. Some former officials and China analysts view Rudd’s Indo-Pacific background as relevant to U.S. cyber operations involving Beijing.

    In his nomination hearings, he told senators that his experience consuming and acting on cyber intelligence qualifies him to serve in the position. 

    “I’m confident that the incredible talent at Cyber Com-NSA will provide great advice,” Rudd told the Senate Armed Services Committee in January. “I’m confident that, if confirmed, I can continue to lead and enable those two organizations to provide the best support to our combat commanders in the joint force, writ large.”

    As director, he’ll be the face of some of the nation’s most secretive electronic spying activities. In April, a powerful foreign spying tool used often by NSA, Section 702 of the Foreign Intelligence Surveillance Act, will expire unless renewed by lawmakers.

    “What I’ve experienced in my career is that this provides the warfighter, the decision-maker, [with] the ability to have critical insight into threats that enables decision making,” Rudd told members of the Senate Intelligence Committee in a separate January hearing when asked about 702. He said he knows the law has “saved lives here in the homeland.”

    The upcoming midterm elections are also top-of-mind for observers of the intelligence agency and digital combatant command. Both units have played a major role in protecting the nation from foreign interference attempts on election outcomes.

    But over the last year, the Trump administration has closed or shrank many agencies and offices that track election threats, including the Office of the National Cyber Director’s Foreign Malign Influence Center and the FBI’s Foreign Influence Task Force. Trump has long been a skeptic of the intelligence community, especially due to its assessments that concluded Russia sought to help him win the 2016 election.

    “The electoral process is fundamental to our democratic values, and Americans writ large, and I’ve committed throughout my career to serve to defend and uphold those values,” Rudd told the Senate intelligence panel. “Any foreign threat to the electoral process should be viewed as a national security concern.”

    He will also have to contend with declining morale inside NSA, as well as workforce cuts that were influenced by Trump 2.0 efforts to shed government bloat and spending waste.

    “General Rudd is a war hero with a lifetime of service to our nation. He is the right choice to lead the protection of our nation from cyberattacks by Iran, Russia, and China,” Sen. Tom Cotton, R-Ark., who chairs the Senate Intelligence Committee, said in a statement after Rudd was confirmed.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers are calling attention to a new campaign where threat actors are abusing FortiGate Next-Generation Firewall (NGFW) appliances as entry points to breach victim networks.  The activity involves the exploitation of recently disclosed security vulnerabilities or weak credentials to extract configuration files containing service account credentials and network topology

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Apparent Russia-linked hacking collectives backing Iran have been observed joining the cyber activity unfolding alongside the U.S.-Israel war against Iran, though analysts have mixed views on whether their involvement represents a meaningful escalation or little more than online noise.

    The outlook on such “hacktivist” groups — hackers who attempt to penetrate systems and steal information for political activism — comes days after The Washington Post reported that Russia is supplying Iran with intelligence to help target U.S. forces in the Middle East and adds another dimension to the already complex cyber and information environment surrounding the war.

    One well-known pro-Russia group dubbed “NoName057(16)” recently claimed massive distributed denial-of-service attacks against Israeli defense contractors and also claimed to have gained full access to the human-machine interfaces of Israeli water management systems, said Kathryn Raines, a cyber threat intelligence team lead at cybersecurity firm Flashpoint. But company analysts have not verified these claims, she said.

    Distributed denial-of-service hacks, known colloquially as “DDoS” attacks, overwhelm websites with large amounts of artificial internet traffic to stop legitimate users from accessing them.

    CrowdStrike has similarly observed a surge in pro-Iran hacktivists with ties to Russia. In the first few days after the war broke out on Feb. 28, one Russia-aligned hacktivist group the company dubs “Z-Pentest” claimed responsibility for compromising several U.S.-based entities, said Adam Meyers, the company’s head of counter adversary operations. 

    Those claims are also unverified, though “Western organizations should continue to remain on high alert for potential cyber response as the conflict continues and activity may move beyond hacktivism and into destructive operations,” he said.

    The United States has long supplied Ukraine with intelligence and equipment to strike Russian targets within its borders. Now, as the war unfolds in Iran, Moscow could be seizing its own opportunity for retaliation by aiding Tehran.

    “Russia is comfortable providing some proxy support to Iran, or at least taking advantage of an unstable situation,” Cynthia Kaiser, a former deputy director at the FBI’s Cyber Division, said in a LinkedIn post this weekend. “Expect exaggeration, but don't dismiss the underlying access. These groups regularly inflate the impact of their attacks for media attention. But they have caused real physical damage to critical infrastructure. Calling their bluff shouldn't mean ignoring the threat.”

    “Russia has a variety of partner engagements with Iran that could prompt Moscow to get involved in the conflict, particularly if Russia perceives that U.S. military operations dragging out would further pull the White House’s focus from Ukraine,” said Justin Sherman, founder and CEO of Global Cyber Strategies, a Washington, D.C.-based research and advisory firm.

    The Kremlin’s vast and complex cyber ecosystem allows it to leverage state elements, hired or coerced cybercriminals and patriotic hackers encouraged by propaganda to pursue its goals, Sherman said, explaining that “one of the benefits of Russia’s cyber web for the state is how the Kremlin can pick and choose its actors and capability sets as it pleases, depending on its needs.”

    In a recent case, Russian state-backed groups initiated a massive global campaign targeting the Signal and WhatsApp accounts of officials, military personnel and civil servants, Dutch intelligence said Monday.

    But Sherman said that attributing Russian-origin cyber operations is complex, and that analysts should try to examine which parts of Vladimir Putin’s government may have authorized an operation to better understand how Moscow would be aiding Iran in cyberspace.

    Some are skeptical that Russia sharing targeting intelligence would translate directly into cyber support for Tehran.

    “Russia providing intelligence assistance to the Iranian government to support kinetic strikes, and the idea of Russian cyber actors as implied by the conventional use of the phrase — i.e., those with a nexus to the Russian state — ‘joining the cyber aspect of this conflict’ are two very different things,” said Alex Orleans, a former National Security Council contractor and head of threat intelligence at Sublime Security.

    “I have not encountered Russian APTs inserting themselves into a conflict to support a third-party and I’d be surprised if they did now,” he said, referring to “advanced persistent threat” groups that are typically well-resourced, highly skilled and backed by a nation-state.

    Other analysts have not publicly attributed any hacktivist activity to a particular nation.

    “While we have observed some initial hacktivist groups supporting the Iranian regime, these activities are in the very early stages. There is currently no clear indication that this is being directed by a state actor like Russia or Iran, and it remains difficult to verify,” said John Fokker, vice president of threat intelligence at Trellix. “That said, in any geopolitical conflict, it is common practice for involved countries to provide aid in various forms.”

    Iran’s cyber capabilities have likely diminished in recent days, said Dave DeWalt, CEO of NightDragon, a venture capital firm that manages a portfolio of cybersecurity companies. 

    “We’ve been monitoring almost every actor and every indicator of compromise that we possibly can, and we've seen next to zero activity … and that’s largely because we believe that most of their cyber operations have been dismantled physically,” he said in an interview.

    Israel said last week it destroyed Iran’s cyberwarfare headquarters, though it’s not immediately clear how much effect that’s had on its cyber operations.

    “We’ve seen little activity from [Iran] globally, that doesn’t mean that it’s completely dismantled,” DeWalt said. “I don’t have full confirmation, but I would tell you it certainly looks like no other case I've seen in 20 years, where we’ve seen such silence in the digital world from [Iran].”

    Asked about whether China and Russia are sharing capabilities with Iran at this point, he said those nations may be keeping their distance, but there’s possible sharing of satellite, electronic warfare and radar-jamming services. “I would not be surprised at all,” he said.

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have discovered a new malware called KadNap that’s primarily targeting Asus routers to enlist them into a botnet for proxying malicious traffic. The malware, first detected in the wild in August 2025, has expanded to over 14,000 infected devices, with more than 60% of victims located in the U.S., according to the Black Lotus Labs team at Lumen. A lesser number of

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶