Search/eclipse
Vendor

eclipse

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
theia
Connections
230 relationships
New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender
The security researcher known as Nightmare Eclipse has released another Microsoft Defender zero-day exploit, right after Microsoft’s record-breaking September 2026 patches. Dubbed ‘ShieldCrash’, the exploit targets fully patched Windows systems for privilege escalation. The proof-of-concept (PoC) exploit code demonstrates an arbitrary file read with System privileges, according to Nightmare Eclipse, also known as Chaotic Eclipse, Infinite Nightmare, and MSNightmare. However, the underlying vulnerability can be exploited to gain full System privileges, allowing attackers to drop the SAM database, the researcher says. Nightmare Eclipse also notes that the fresh zero-day is a bypass for ShieldBreak, the Microsoft Defender privilege escalation exploit dropped on the August 2026 Patch Tuesday. ShieldBreak in turn was released as a bypass for Microsoft’s patches against RoguePlanet, a race condition bug dropped as a zero-day on June 2026 Patch Tuesday. Microsoft patched RoguePlanet (CVE-2026-50656) on July 19. It acknowledged ShieldBreak on August 14 and rolled out fixes for it on September 3. The bug is tracked as CVE-2026-69414. Nightmare Eclipse says that Microsoft’s patches for ShieldBreak are incomplete, and that the security defect can still be exploited, releasing ShieldCrash as proof. SecurityWeek has emailed Microsoft for a statement on the fresh zero-day exploit and will update this article if the company responds. According to SOCRadar CISO Ensar Seker, ShieldCrash raises concerns mainly because it exposes a weakness in Microsoft’s patching of the underlying vulnerability’s attack paths. “When researchers can bypass successive fixes for RoguePlanet and ShieldBreak, it suggests the underlying security boundary or attack surface may require a more comprehensive redesign rather than another narrowly targeted patch,” Seker said. He advises security teams to monitor Microsoft’s guidance and Defender intelligence updates, enable tamper protections, restrict admin access and local execution paths, and look for any suspicious process behavior associated with Defender-related mechanisms. “Microsoft should also assess the complete vulnerability class and related code paths, not only the specific condition demonstrated by this latest proof of concept,” Seker added. Related: Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits Related: Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days Related: Android’s September 2026 Updates Patch 180 Vulnerabilities Related: Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day
securityweek.comSep 10, 2026extracted
Serial Microsoft 0-day hunter drops yet another Defender exploit
SYSTEMS d-Matrix drinks the Nvidia Kool-Aid with NVLink Fusion and MGX rack designsAI infrastructure startup joins Qualcomm, Arm, Marvell, Amazon, Fujitsu, and MediaTek as NVLink true believers ai and ml Anthropic reveals fourth likely crime committed by its AIClaude's Felony Bench rap sheet is now as long as OpenAI's SYSTEMS Samsung to help fortify OpenAI's semiconductor supply chainSemiconductor supply chains are hard, but Samsung offers OpenAI relief in many forms spanning compute and memory AI+ML Google DeepMind rises above the AI scrum with genome atlasSee, AI can be used for good ... or at the very least, a useful distraction from the bad AI and ML Amazon ropes Qualcomm into something, something AI, networking chipsMulti-generation chip collab is more buzzwords than compute Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career Switzerland tests a FOSS escape route from Microsoft 365Swiss Army sticks a knife in American cloud apps with its own FOSS push Feel peak Windows was 7? You might like Kumander LinuxDebian and Xfce – solid, sensible choices – with a pretty skin Canonical shuttering some of its legacy chat channelsThe Ubuntu Pastebin went in June, IRC gets demoted next Audacity audio-editing app no longer looks like it's from the early 2000sThe FOSS tool for audio editing has a fresh coat of paint, and new features to boot Haiku OS rises / Beta 6 sails open web / Virtual winds fly fastA real alternative to running some kind of FOSS Unix clone Offshoots of cancelled TrueNAS Core upgrade to FreeBSD 15Exeunt zVault stage right; enter FreeCORE and BSDnas
theregister.comSep 9, 2026extracted
September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor
September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor September 2026 Patch Tuesday is here, with Microsoft delivering another record-breaking number of patches, including those for two vulnerabilities that have been exploited as zero-days. Another “new normal” is the anonymous security researcher Nightmare Eclipse publishing a zero-day proof-of-concept exploit targeting Microsoft software mere hours after Microsoft drops its Patch Tuesday fixes. This time around it’s ShieldCrash, which ostensibly bypasses the patch for CVE-2026-69414 (aka ShieldBreak), a privilege escalation bug in Microsoft Defender (i.e., the Microsoft Malware Protection Engine). The flaws exploited in zero-day attacks CVE-2026-81963, in the Windows Update Stack (the component used for installing Windows updates), affects various Windows 11 versions and Windows Server 2025. Caused by improper link resolution before file access and improper access control, the flaw allows authenticated attackers (with low privileges) to gain SYSTEM privileges on a vulnerable system. Satnam Narang, senior staff research engineer at Tenable, noted that there have been seven privilege escalation flaws in Windows Update Stack since 2022, but this is the first zero-day and the first to be exploited. The flaw was reported by Microsoft’s Threat Intelligence Centre (MSTIC), but details about the attacks in which it was exploited are still not public. Dustin Childs, head of threat awareness at TrendAI’s Zero Day Initiative, says he doubts that the automatic update process itself is compromised, and that it’s more likely that CVE-2026-81963 is being combined with a code execution bug to spread malware or ransomware. CVE-2026-85880 is another privilege escalation (to SYSTEM) bug, in the Windows Advanced Local Procedure Call. It affects Windows 10 and older Windows Server versions (2012, 2016, 2019 and 2022). It was reported by Proofpoint threat researchers but, again, we don’t know how widely it’s been exploited. But, since both of these bugs are being leveraged by attackers, implementing these fixes should be a priority for all organizations. “This class of flaw has historically appeared in post-compromise tooling used by both commodity malware and targeted intrusion operators as a reliable final step from user-mode to kernel-mode control,” CrowdStrike noted. Other vulnerabilities of note According to Childs, organizations should also prioritize patching a cluster of 20 bugs that affect most supported Windows versions and could be classified as wormable. “In each of these cases, a remote, unauthenticated attacker could get arbitrary code execution on affected systems with no user interaction,” he pointed out. “We haven’t seen a global worm in years, but with a DNS flaw [CVE-2026-69730] acting as the spiritual successor to SigRed, that reality could change fast.” CVE-2026-69676, an authentication bypass flaw in Kerberos that could lead to remote code execution, is classified as Exploitation More Likely. “An authenticated attacker with low-level access sends a crafted request and executes code on the server, no user interaction,” Childs explained. “‘The server’ here means a domain controller, and any authenticated attacker means any domain user. So the realistic read is: one phished workstation account, one crafted request, code execution on the DC. That’s a domain-compromise primitive, and Microsoft expects to see it exploited.” Finally, among the more likely to be exploited flaws is also CVE-2026-80093, a privilege escalation vulnerability in Windows Cloud Files Mini Filter Driver. Though successful exploitation of this vulnerability requires an attacker to win a race condition, technical details are already public. The good news is that patches for all of these and the above mentioned actively exploited flaws are all bundled in the cumulative security updates and monthly rollups for the various Windows versions, so applying them fixes them all in one fell swoop. Setting Windows updates aside for a moment, Childs also advises prioritizing updating: Microsoft Exchange Server, to fix a RCE flaw that can be triggered by Exchange Server processing an email with a malicious Visio attachment (CVE-2026-55007) Microsoft SharePoint Server, to fix a variety of bugs Why prioritization matters more than patch counts “One of the most important things to recognize across the recent rise in Patch Tuesday releases is that while the number of vulnerabilities being patched is rising, the number of vulnerabilities that can and will affect most organizations remains quite low,” Narang told Help Net Security. AI-assisted vulnerability discovery in 2026 is creating larger haystacks, but it isn’t finding more needles. It’s critical that organizations understand which vulnerabilities actually apply to them, whether they pose a threat by being reachable and exploitable, and prioritize remediation based on this risk context.” Tyler Reguly, Associate Director of Security R&D at Fortra, says that the huge number of vulnerabilities patched by Microsoft merely shows that the company is being proactive. “We need to remember that these large CVE counts are a good thing as we’re reducing attack surface before attackers get a chance to find and utilize the vulnerabilities. Eventually, all those long-standing, hard to find vulnerabilities will be fixed and Patch Tuesday will return to its typical cadence. Until that happens, prioritization is key and gift cards for extra coffee for your admins would likely be appreciated,” he noted. Still, the number of one-off patches has also risen, and he advises organizations to consider whether their processes are designed to handle major changes and potential patching bottlenecks. “Right now, if you are in charge of teams managing patches, you are probably struggling with what to do. Support your team, be aware of the difficulties they face, and ask them how things can be improved,” he commented. “If you still prioritize based on CVSS, you are hurting your organization and your employees. If you are constantly flip-flopping as guidance changes, you are putting your organization at risk and jeopardizing employee happiness. You are essentially steering a ship through rough waters, and you need a steady hand to accomplish that. If you keep the ship on course, your team will be able to do the rest.” Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
helpnetsecurity.comSep 9, 2026extracted
New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access
An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. ShieldCrash is described as a bypass for the ShieldBreak Defender privilege escalation flaw patched on Thursday, which itself . According to Nightmare Eclipse, the ShieldCrash proof-of-concept exploit lets attackers gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems, but will not give them write access to the compromised systems. "Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak. While Microsoft fixed several things to prevent re-exploiting the issue, they missed a spot where ShieldBreak can still be exploited," they said. "This PoC demonstrates an arbitrary file read as SYSTEM with September 2026, all supported windows versions are affected. I might rework this later into a full SYSTEM PoC but for now I'm dropping this skeleton PoC because I'm feeling a bit lazy." Nightmare Eclipse released these zero-day exploits as part of an ongoing dispute with Microsoft over the company's bug bounty and vulnerability disclosure practices. Microsoft responded with warnings of legal action against anyone engaging in "malicious activity causing real harm" to its customers, prompting many to believe that the company was directly threatening the security researcher. Since April, the anonymous security researcher has disclosed a long string of zero-day flaws, including the ShieldBreak, LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend zero-days targeting Microsoft Defender, BitLocker, and other Windows components. While Microsoft fixed the ShieldBreak, RoguePlanet, YellowKey, GreenPlasma, and MiniPlasma flaws, the other vulnerabilities disclosed by Nightmare Eclipse still lack an official patch. A Microsoft spokesperson was not immediately available to comment when BleepingComputer reached out earlier today about the ShieldCrash zero-day. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comSep 9, 2026extracted
Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed
The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher reported last month. "Microsoft has failed to properly patch ShieldBreak CVE-2026-69414," Chaotic Eclipse said. "Under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak. While Microsoft fixed several things to prevent re-exploiting the issue, they missed a spot where ShieldBreak can still be exploited." The PoC demonstrates an arbitrary file read as SYSTEM with the latest version of Windows installed. All supported versions of the desktop operating system are said to be impacted. The development comes days after Redmond shipped an update to the Microsoft Malware Protection Engine to plug CVE-2026-69414. The issue has been patched in Malware Protection Engine version 1.1.26080.3. It does not require any customer action and does not affect systems that have disabled Microsoft Defender. "In response to a constantly changing threat landscape, Microsoft frequently updates malware definitions and the Microsoft Malware Protection Engine," the tech giant said. "In order to be effective in helping protect against new and prevalent threats, antimalware software must be kept up to date with these updates in a timely manner." "For enterprise deployments as well as end users, the default configuration in Microsoft antimalware software helps ensure that malware definitions and the Microsoft Malware Protection Engine are kept up to date automatically. Product documentation also recommends that products are configured for automatic updating." In recent weeks, Chaotic Eclipse has also released PoC exploits for four vulnerabilities impacting CrowdStrike Falcon Sensor (FalconFlank), Kaspersky (HardBreacher), Avast Antivirus (PrettyPrague), and NVIDIA (GreenSection). Both HardBreacher and PrettyPrague have since been patched by the respective security vendors, while CrowdStrike told The Hacker News that it's investigating the report.
thehackernews.comSep 9, 2026extracted
Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day
Adobe has released patches for more than 170 vulnerabilities across its products, including urgent hotfixes for a critical-severity flaw in Adobe Commerce and Magento Open Source that has been exploited in the wild as a zero-day. Tracked as CVE-2026-75650 (CVSS score of 10/10), the flaw is a code injection issue that can be exploited without authentication for remote code execution (RCE). “Adobe is aware of CVE-2026-75650 being exploited in the wild,” the company notes in its advisory. Adobe also published a KB article with details on the update. The security defect was patched on Monday, after cybersecurity firm Sansec warned over the weekend that hackers have been exploiting a zero-day flaw in Commerce/Magento to hack online stores. Attackers started exploiting the issue, dubbed StyleSmuggler, on September 4, injecting code that would be executed by triggering Magento’s standard ‘Payment Transaction Failed Reminder’, without user interaction. According to Sansec’s updated report, several threat actors have been targeting the vulnerability to deploy backdoors and web shells. Commerce/Magento should apply Adobe’s fixes as soon as possible and rotate their encryption keys and all credentials protected with those keys, including administrative passwords, database credentials, integration tokens, OAuth secrets, SSH and deploy keys, and API keys. “Rotate those at the source, not only inside Magento. Rotating the encryption key on its own does not invalidate anything an attacker already read,” Sansec notes. On Tuesday, Adobe released patches for eight additional Commerce vulnerabilities, including two critical-severity privilege escalation flaws and six high-severity security bypass and privilege escalation bugs. The company also released urgent patches for CVE-2026-82004 (CVSS score of 10/10), an OS command injection defect in Campaign Classic leading to arbitrary code execution. Fresh ColdFusion security updates were also assigned a priority 1 rating, as they address two critical-severity code execution security weaknesses: CVE-2026-48273 (CVSS score of 9.9/10) and CVE-2026-75746 (CVSS score of 9.1/10), and seven high- and medium-severity issues. Adobe recommends that all priority 1 updates be applied within three days after they were released. On Tuesday, Adobe also rolled out fixes for 107 vulnerabilities in Experience Manager, 32 flaws in Acrobat Reader, 8 in Photoshop, 3 in Illustrator, and 1 in Animate. Fixes were also rolled out for Photoshop Mobile. Adobe says it is not aware of any of the newly resolved vulnerabilities being exploited in attacks, aside from the Commerce/Magento zero-day. Additional information can be found on Adobe’s security advisories page. Related: SAP Patches Critical Extended Passport Processing Vulnerability Related: MikroTik Patches Critical Flaws Chained to Hack Routers Related: N-able Patches Critical Zero-Day in N-central Related: Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits
securityweek.comSep 8, 2026extracted
SAP Patches Critical Extended Passport Processing Vulnerability
SAP released 20 new and updated security notes on Tuesday, including one that resolves a critical-severity memory corruption vulnerability. Tracked as CVE-2026-44756 (CVSS score of 10/10), the critical bug is described as a memory corruption issue in Extended Passport (EPP) Processing. Missing boundary validations during the deserialization of EPP data could trigger unsafe memory behavior during the processing of externally supplied length fields, application security firm Onapsis explains. Dubbed OVERPASS, the security defect can be exploited by unauthenticated attackers to run arbitrary system commands, recover database credentials and password hashes, read the live sessions of logged-in users, and modify data, including configurations and SAP binaries. According to Onapsis, the flaw resides in the SAP kernel code and impacts various components, as EPP is used for tracing within multiple SAP applications. Furthermore, it explains that the vulnerability is triggered as soon as a new user session is opened, from client to server, over several communication protocols, and the vulnerable functionality is implemented by default between ABAP systems. “Because EPP is processed as the session opens, every SAP control that decides who may do what, including user locks, roles, authorization objects, and logon policies, is evaluated later than the point where the flaw is reached. None of them is in the attacker’s way,” Onapsis explains. Additionally, it says, the bug can be reached via at least three vectors, including web requests, the SAP GUI protocol, and Remote Function Call (RFC) connections. “The affected components run under the operating system account that owns the SAP installation, so code execution under it is equivalent to owning the SAP system outright,” Onapsis says. SAP products that rely on the vulnerable kernel code include S/4HANA, ERP, Business Suite (ECC), NetWeaver, Web Dispatcher, BW/4HANA, Enterprise Portal, PI/PO, Solution Manager, and others. According to Onapsis, there are no indicators that the vulnerability has been exploited in the wild. SAP makes no mention of its in-the-wild exploitation either. Three other critical flaws were resolved with SAP’s fresh patches: CVE-2026-58240 (missing authentication check in NetWeaver), CVE-2026-76969 (credential disclosure in multitenant applications using Cloud Application Programming Model (CAP)), and CVE-2026-66768 (improper access control in NetWeaver). The missing authentication issue, dubbed S4GET, could allow remote, unauthenticated attackers to register unauthorized components and perform actions without authorization. The bug resides in SAP’s modern kernel, and every S/4HANA 2025 and earlier release is affected, Onapsis says. Five of the security notes released on SAP’s September 2026 security patch day address high-severity flaws in ABAP Developer Tools, Integration Suite, NetWeaver Business Client, NetWeaver, and Commerce Cloud (Search And Navigation). Related: N-able Patches Critical Zero-Day in N-central Related: MikroTik Patches Critical Flaws Chained to Hack Routers Related: Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits Related: Sangoma Switchvox Vulnerability Exploited in the Wild
securityweek.comSep 8, 2026extracted
N-able Patches Critical Zero-Day in N-central
IT software firm N-able has rolled out an urgent fix for an unauthenticated remote code execution (RCE) vulnerability in its N-central endpoint management platform that has been exploited as a zero-day. Tracked as CVE-2026-86218 (CVSS score of 10/10), the security defect was discovered after N-able patched two other flaws in N-central, namely CVE-2026-86206 and CVE-2026-86207 “This critical zero-day vulnerability, CVE-2026-86218, could allow pre-authenticated access to the N-central server if exploited,” N-able warns. While no action is required for N-central hosted environments, as the patches were deployed server-side, users of on-premises N-central instances should immediately apply the 2026.3 HF4 hotfix, the company says. “Review your logs for scanning activity. We’ve observed scans originating from the IP range 23.234.64.0/18 attempting to exploit this vulnerability. Check your logs for any connections from this range,” N-able also notes. Administrators are also advised to check their deployments for newly created user accounts they don’t recognize. “At this time, we have no confirmations that this vulnerability has been exploited in production environments, but unpatched systems remain at risk,” N-able says. The hotfix for the exploited zero-day supersedes the previously released patches for CVE-2026-86206 and CVE-2026-86207, two bugs that Huntress flagged as potentially chained together in the wild to bypass authentication and compromise N-central production environments. “However, due to limited historical logging available directly on the appliance, we cannot definitively confirm which specific exploit the threat actor used to achieve their compromise, nor can we rule out the use of alternative vulnerabilities,” Huntress said on Saturday. The cybersecurity firm observed attacks targeting N-central’s underlying API and appliance logs starting on September 4, 2026. Related: Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits Related: Adobe Commerce Zero-Day Exploited to Backdoor Online Stores Related: Modified ScreenConnect Clients Used in Worm-Like Campaign Related: Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
securityweek.comSep 8, 2026extracted
Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits
The security researcher known as Nightmare Eclipse has dropped three zero-day exploits targeting products from Avast, CrowdStrike, and Nvidia. Also known as Chaotic Eclipse, Infinite Nightmare, and MSNightmare, the security researcher came to fame for a series of zero-day exploits targeting Microsoft’s products, but has recently moved to other vendors as well. In late August, Nightmare Eclipse released a privilege escalation zero-day in a Kaspersky endpoint security product. Dubbed HardBreacher, the exploit has been patched by Kaspersky on August 31. Within a short window last week, Nightmare Eclipse dropped three new zero-day exploits, dubbed PrettyPrague, FalconFlank, and GreenSection. The PrettyPrague proof-of-concept (PoC) code, the researcher says, targets the Avast sandbox to spawn a shell with full system privileges, and may also affect other GenDigital products, including AVG and Norton. “Gen was recently made aware of a security vulnerability affecting a subset of Gen products, including Avast Antivirus, that could allow an attacker to elevate their system privileges. We immediately initiated our security response procedures and have fixed the issue. We take all security matters seriously and encourage users to keep their products up to date to ensure they are protected,” a GenDigital spokesperson said, responding to a SecurityWeek inquiry. FalconFlank exploits a bug in the Office malicious macros remediation feature of CrowdStrike Falcon Sensor for privilege escalation, the researcher says. “We are actively investigating these claims and advise customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting. Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. We refer customers to the FalconFlank Tech Alert in the CrowdStrike support portal,” CrowdStrike told SecurityWeek. The GreenSection exploit, Nightmare Eclipse says, targets an out-of-bounds memory write affecting a shared global memory section used by multiple Nvidia user-mode components. “While this bug does not get SYSTEM privileges immediately, it can be used cross user to user boundary easily or even compromise the dwm.exe process. I didn’t look deeply into it, but I’d be happy to see someone making a full exploit out of it,” Nightmare Eclipse notes. “We are aware of reports describing a proof-of-concept that demonstrates improper access controls on a shared memory section used by certain NVIDIA GPU display driver components on Windows. NVIDIA is reviewing the reported behavior through our established security and product engineering processes. NVIDIA takes reports of this nature seriously and is actively investigating to determine the root cause, affected configurations, and appropriate remediation,” an Nvidia spokesperson said. Security researcher Kevin Beaumont said late last week that the Avast, CrowdStrike, and Kaspersky exploits work. *updated with statement from Nvidia Related: VMware Workstation and Fusion Updates Patch Critical Vulnerability Related: Google Patches 6th Chrome Zero-Day of 2026 Related: Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability
securityweek.comSep 7, 2026extracted
Researcher Publishes CrowdStrike Privilege Escalation Zero Day
A security researcher has published details of what appears to be a zero-day privilege escalation exploit in CrowdStrike. The individual, identified by their online moniker “Nightmare Eclipse” (aka Infinite Nightmare, MSNightmare) posted the details to GitHub on September 3. “FalconFlank is a zero-day privilege escalation that abuses the Office malicious macros remediation in CrowdStrike Falcon Sensor. Obviously by the time I drop this CrowdStrike would already have detections for it so if you want to test you either have to add it to the exclusions or obfuscate the PoC and change the dll load technique,” they wrote. “As of now it works in a fully updated Windows 11 25H2 / Windows Server 2025 with CrowdStrike Falcon – Phase 3 Optimal Protection + needs ‘Microsoft Office file malicious macro removal’.” A statement from CrowdStrike urged customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting while the firm investigates the case. "Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings,” it added. “We refer customers to the FalconFlank Tech Alert in the CrowdStrike support portal." That portal is only accessible for customers with a dedicated account, and there has not yet been a CVE assigned to the bug. The Nightmare Continues Security researcher Kevin Beaumont confirmed that FalconFlank works, while also highlighting that the same researcher also published zero-days exploiting Kaspersky and Avast. “An open secret amongst security researchers is most cybersecurity products are crap at cybersecurity,” he wrote on Mastadon. “From VPN products being one of the top causes of ransomware group entry, ../.. path traversal bugs, EDR products which brick PCs and are trivial to bypass and exploit etc.. It's a wild world out there.” Oliver Spence, CEO of CybaVerse, agreed that security products can themselves be a risk to organizations. “How do we fix this? Vendors need to take greater responsibility for ensuring their products are secure, continually testing for weaknesses and remediating vulnerabilities quickly,” he argued. “Otherwise, customers will continue to face the financial and operational penalties of these weaknesses in the very products they depend on to secure them.” NightmareEclipse was previously responsible for the “Exploitarium” dump of over 30 proof-of-concept exploits in open source projects, including the Linux kernel, Libssh2, FFmpeg, Gogs, and Gitea. Infosecurity has reached out to CrowdStrike for additional comment.
infosecurity-magazine.comSep 7, 2026extracted
New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges
An anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets attackers escalate privileges on up-to-date Windows systems. Nightmare Eclipse says the new vulnerability (which has yet to be assigned a CVE ID) affects devices running the latest versions of Windows 11 and Windows Server, as well as CrowdStrike's endpoint security platform. Successful exploitation allows attackers to spawn a command prompt with SYSTEM privileges by abusing CrowdStrike Falcon's Office malicious macros remediation feature. "FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in Crowdstrike Falcon Sensor, obviously by the time I drop this Crowdstrike would already have detections for it so if you want to test you either have to add it to the exclusions or obfuscate the PoC and change the dll load technique," Nightmare Eclipse said. "As of now it works in a fully updated windows 11 25H2 / Windows Server 2025 with Crowdstrike Falcon." When BleepingComputer asked for more details about this vulnerability, a CrowdStrike spokesperson said the company is investigating the researcher's claims and advised customers to disable the Microsoft Office Windows policy setting that toggles the security software's File Suspicious Macro Removal feature. "We are actively investigating these claims and advise customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting," the spokesperson told BleepingComputer. "Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. We refer customers to the FalconFlank Tech Alert in the CrowdStrike support portal." Although the company also shared this link to the tech alert regarding the FalconFlank zero-day exploit, the advisory is not public, and customers can access it only if they have an account on CrowdStrike's support portal. CrowdStrike has yet to reply to a second email asking for a copy of the FalconFlank tech alert and whether a CVE ID has been assigned to the FalconFlank flaw. Kaspersky, Avast, Nvidia, and Microsoft zero-days This week, Nightmare Eclipse has also released privilege escalation zero-day exploits for Kaspersky Antivirus for Endpoint (named HardBreacher) and GenDigital Avast Antivirus (PrettyPrague), as well as a denial-of-service zero-day for Nvidia (named GreenSection) that will crash the system. Cybersecurity expert Kevin Beaumont confirmed on Thursday that the privilege escalation exploits released by Nightmare Eclipse this week are real and work. Nightmare Eclipse has also disclosed multiple zero-day exploits targeting multiple Microsoft products since April, including Microsoft Defender, BitLocker, and various other Windows components. These Microsoft zero-days are known as LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend. While the LegacyHive, RoguePlanet, YellowKey, GreenPlasma, and MiniPlasma flaws have since been fixed, the other security flaws remain zero-days and are still awaiting an official patch. After Nightmare Eclipse disclosed the first zero-days, Microsoft responded with warnings of legal action against people engaging in "malicious activity causing real harm to our customers," prompting many to believe that the company was directly threatening the security researcher. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comSep 4, 2026extracted
Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC
The disgruntled security researcher known as Nightmare Eclipse (aka Chaotic Eclipse, Infinite Nightmare, and now also MSNightmare) is moving away from their singular Microsoft vendetta and on to other vendors. On Thursday, they dropped a new zero-day bug called FalconFlank that affects CrowdStrike’s Falcon endpoint security platform - albeit with a Windows link. According to the prolific zero-day hunter, FalconFlank is a privilege escalation vulnerability that abuses the Microsoft Office malicious macros remediation feature in CrowdStrike Falcon. This is an automated security tool built into the platform that inspects Microsoft Office documents. If it finds any potentially harmful macros, the feature strips the suspect code and - hopefully - prevents malicious code or other dangerous payloads from executing when users open the document. “We are actively investigating these claims and advise customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting,” a CrowdStrike spokesperson told The Register. “Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. We refer customers to the FalconFlank Tech Alert in the CrowdStrike support portal.” The proof-of-concept (PoC) exploit works on fully updated Windows 11 25H2 and Windows Server 2025 systems running CrowdStrike Falcon with Phase 3 - Optimal Protection as well as the malicious macro removal feature enabled, Nightmare Eclipse said in a GitHub README. “Obviously by the time I drop this Crowdstrike would already have detections for it so if you want to test you either have to add it to the exclusions or obfuscate the PoC and change the dll load technique,” they wrote. Security sleuth Kevin Beaumont confirmed this exploit works, along with several others Nightmare released over the past week. Beaumont told us that he’s not surprised to see Nightmare digging into other, non-Microsoft zero-days. “Kinda makes sense they’d branch out to other vendors as there’s problems across the endpoint security space with the quality of the security products in terms of…security unfortunately,” Beaumont told The Register. “Hopefully it causes cybersecurity vendors to up their game, stop hyping hypothetical AI attacks, and instead make their own products secure for customers.” FalconFlank follows other vulnerabilities in various endpoint and antivirus products that Nightmare has found and published in the last several days. These include HardBreacher, an elevation of privileges bug in Kaspersky’s endpoint antivirus product. “So the problem is now leaking outside of Microsoft,” Nightmare said when they published the HardBreacher PoC last week. “There was poll held against either finding a bug in the home or commercial version and the poll results were the commercial version. At the time of writing this, the proof of concept works in a fully patched windows 11 25H2 & Kaspersky for Endpoint v14.0.0.504.” Beaumont confirmed that Nightmare’s HardBreacher exploit code works, as does a PoC for an elevation of privileges vuln in Gen Digital’s Avast antivirus software. This zero-day, named PrettyPrague, “will dump the SAM database by abusing a vulnerability in Avast Sandbox and spawn a full SYSTEM shell,” according to the researcher. "Gen was recently made aware of a security vulnerability affecting a subset of Gen products, including Avast Antivirus, that could allow an attacker to elevate their system privileges," Gen Digital told The Register. "We immediately initiated our security response procedures and are actively developing a patch. We take all security matters seriously and are committed to addressing this issue swiftly." Kaspersky did not immediately respond to The Register’s requests for comment. Nightmare also recently released an Nvidia memory corruption zero-day vulnerability dubbed GreenSection, but according to Beaumont, this one just crashes the system. Nvidia did not respond to our inquiries.® Updated to add at 0905 PT on September 4, 2026 "Kaspersky has resolved the HardBreacher issue. The corresponding fix is delivered via an automatic update, or users can trigger a database update manually," the company told The Register. "During our investigation into the reported issue, we identified an opportunity to enhance our existing behavior-based detections to ensure overall stability and prevent system freezes under certain configurations."
theregister.comSep 3, 2026extracted
Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a privilege escalation flaw impacting Crowdstrike Falcon. "FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor," the researcher said in a GitHub README file, adding the cybersecurity company may already have detections for the flaw by now. "So if you want to test, you either have to add it to the exclusions or obfuscate the PoC and change the DLL load technique." The PoC, the researcher added, works in a fully updated Windows 11 25H2 machine or Windows Server 2025 with Crowdstrike Falcon. The Hacker News has contacted CrowdStrike for comment, and we will update the story if we hear back. The development comes days after Chaotic Eclipse released a PoC for another privilege escalation flaw impacting Kaspersky's endpoint security product for Windows (version 14.0.0.504). The exploit has been codenamed HardBreacher. "The PoC is not in the best shape at all, it is basically duct tapped, I just managed to make it work and that's all," the researcher said. "It will fail to run with error so you just have to keep rerunning it. If it succeeds, it will create a file in C:\Windows\System32\MY_SNAKE_IS_SOLID.dll with full permissions for the current user." "The interesting part about this is that Kaspersky completely loses it when you take control over the UI process, you can cause it to stop functioning, grant/block access to files it's not supposed to, if the PoC succeeds, the entire operating system becomes a hot mess." When reached for comment, Kaspersky told The Hacker News that it has resolved the HardBreacher issue. "The corresponding fix is delivered via an automatic update, or users can trigger database update manually," the company said. Last month, the researcher also published a PoC for a Microsoft Defender zero-day called ShieldBreak (aka CVE-2026-69414) that could grant an attacker the ability to run arbitrary code with NT AUTHORITY\SYSTEM privileges. It's assessed to be a patch bypass for CVE-2026-50656 (aka RoguePlanet). Microsoft has yet to release a fix. "Like its predecessors, ShieldBreak explores a different corner of the Windows operating system," LevelBlue said. "Where RedSun abused the Cloud Files API and TieringEngineService to redirect a Defender write into System32, and LegacyHive weaponized offline registry hive manipulation and the NT Object Manager namespace, ShieldBreak combines Cloud Files, Object Manager namespace manipulation, direct Windows Defender API invocation, and a timing race in the remediation path." "The result is a self-contained local privilege escalation chain in which Windows Defender's own clean engine is redirected to write an attacker-supplied DLL to C:\Windows\System32\phoneinfo.dll, followed by SYSTEM execution through the built-in Windows Error Reporting task." Shortly after, the researcher claimed that Microsoft continues to ghost them and refuses to engage in "any sort of communication," stating the company is "trying hard to paint me as some insane criminal." "I can't even report the bugs I find to their respective vendors because of the restrictions by Microsoft, all of this is of their own doing and you know, they don't even bother to check my case to figure out what's wrong," they said in a post dated August 14, 2026. "Think I will start publishing bugs for third-parties in that window where Patch Tuesday isn't released yet. I just want to live like a normal human being for once in my life, is that too much to ask for...?"
thehackernews.comSep 3, 2026extracted
WatchGuard Patches Critical Vulnerabilities
WatchGuard has released patches for over two dozen vulnerabilities, including five critical-severity flaws leading to remote code execution (RCE) and account takeover. Three of the critical bugs impact the iked process of Fireware OS, the core Internet Key Exchange (IKE) daemon that handles cryptographic key establishment and manages IPsec VPN negotiations over the IKEv1 and IKEv2 protocols. Exploitable without authentication, the three security defects are a heap buffer overflow (CVE-2026-19313), a stack-based buffer overflow (CVE-2026-19318), and a type confusion (CVE-2026-19315). Attackers could send specially crafted network traffic to trigger each of these vulnerabilities and achieve RCE, WatchGuard says. WatchGuard also patched a critical stack-based buffer overflow bug (CVE-2026-13086) in the Endpoint Protection Manager (epm) service that is used by the deprecated Mobile Security feature in Fireware OS, which could lead to RCE. Additionally, the company fixed CVE-2026-78174 in WatchGuard Dimension, which could allow low-privileged administrators to extract a super admin’s session ID and CSRF tokens and take over their account. All five security defects have a CVSS score of 9.3. Fixes for them were included in Fireware OS versions 2026.2.2, 12.12.2, and 12.5.20, and Dimension version 2.3.1. The updates also resolve seven high-severity Fireware OS vulnerabilities that could lead to denial-of-service (DoS), including six impacting the iked process, and five high-severity Dimension bugs leading to arbitrary command execution, tampering with the global administrator’s passphrase, and DoS. Patches were also rolled out for 11 medium-severity vulnerabilities, including one in Fireware OS’s iked process and 10 in Dimension. WatchGuard says it is not aware of any of these security defects being exploited in the wild. Additional information can be found on the company’s security advisories page. Related: PaperCut Exploitation Escalates to Active Intrusions Related: Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit Related: ServiceNow Patches 3 Critical Code Injection Vulnerabilities Related: Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs
securityweek.comSep 1, 2026extracted
PaperCut Exploitation Escalates to Active Intrusions
Attacks exploiting two recently discovered PaperCut NG/MF vulnerabilities have escalated, with threat actors shifting from reconnaissance to hands-on-keyboard activity. PaperCut first warned users of its NG and MF print management solutions about an actively exploited zero-day vulnerability on August 27. It later emerged that threat actors have been chaining two flaws in their attacks. The vulnerabilities are tracked as CVE-2026-82078 and CVE-2026-81578, and they can be exploited by unauthenticated attackers to bypass authentication and achieve remote code execution on affected PaperCut NG/MF instances. The vendor quickly rolled out two emergency patches — one after the first was bypassed — and is working on an official release that addresses both vulnerabilities. In the meantime, attacks are escalating, according to exposure management firm WatchTowr, whose researchers have been monitoring the situation. “Activity has significantly evolved, and it did so quickly — we are no longer seeing purely exploratory probes to identify vulnerable systems, but real-world exploitation accompanied with hands-on-keyboard interaction from human attackers exploring systems they’ve compromised,” Jake Knott, head of threat intelligence at WatchTowr, said via email. “As part of this activity, it’s noteworthy that this appears to be ‘above average’ (the bar still being very low) in terms of sophistication — some designed purely to facilitate external to internal network pivoting and continue attacks,” Knott added. “Attackers are, as always, being selfish — keying access to their deployed in-memory payloads to ensure that only they are able to access compromised hosts and continue further. This behavior is reflective of initial access brokers, and other more aggressive-outcome type operators.” PaperCut’s updated indicators of compromise (IoCs) also indicate attack escalation, specifically the deployment of remote access tools on targeted systems. Technical details on CVE-2026-82078 and CVE-2026-81578 are also available from security firms Huntress and Rapid7. The cybersecurity agency CISA added CVE-2026-82078 and CVE-2026-81578 to its Known Exploited Vulnerabilities (KEV) catalog on Monday. Federal agencies have been instructed to address the flaws by September 14. More than 1,000 PaperCut NG/MF instances are exposed to the internet, according to data from ShadowServer. “If exposed to the Internet and unpatched at any stage in the last few days, systems should be assumed compromised by an active attacker who is combing through vulnerable hosts looking for interesting or valuable targets,” WatchTowr’s Knott warned. “And if you haven’t already, now is the time to trigger incident response processes. Patching alone will lock out new attackers while allowing existing attackers to maintain access and go further.” Related: Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit Related: ServiceNow Patches 3 Critical Code Injection Vulnerabilities Related: Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs
securityweek.comSep 1, 2026extracted
Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit
The researcher known as Nightmare Eclipse has dropped another zero-day — this time a privilege escalation exploit targeting a Kaspersky endpoint security product. Nightmare Eclipse, also known as Chaotic Eclipse, has released PoC exploits for many vulnerabilities in recent months, mainly Windows and Microsoft Defender flaws. The researcher started dropping zero-days after growing frustrated with Microsoft’s handling of vulnerability reports. While many of the exploits remained at the PoC stage, a few ended up being exploited in the wild by malicious actors. Over the weekend, Nightmare Eclipse released an exploit targeting a privilege escalation vulnerability in Kaspersky Endpoint Security. The exploit has been dubbed HardBreacher. “The PoC is not in the best shape at all, it is basically duct tapped, I just managed to make it work and that’s all,” the researcher noted. “The interesting part about this is the Kaspersky completely loses it when you take control over the UI process, you can cause it to stop functioning, grant/block access to files its not supposed to, if the PoC succeeds, the entire operating system becomes a hot mess,” the researcher added. Contacted by SecurityWeek, Kaspersky said the underlying issue has been resolved. “The corresponding fix is delivered via an automatic update, or users can trigger a database update manually,” Kaspersky stated. Other exploits made public recently by Nightmare Eclipse include ShieldBreak, which allows an attacker to spawn a shell with System privileges, and LegacyHive, which enables privilege escalation. Related: Log4j Remote Code Execution Scare Related: Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs Related: More Details Emerge on Exploited PaperCut Vulnerabilities
securityweek.comAug 31, 2026extracted
Nightmare Eclipse passa a Kaspersky. Su GitHub pubblica uno 0day in Kaspersky Endpoint Security
Un prodotto di protezione può trasformarsi esso stesso in un punto di ingresso per un attacco. L’esperto conosciuto con lo pseudonimo Nightmare Eclipse ha pubblicato un exploit sperimentale chiamato HardBreacher per Kaspersky Endpoint Security , che permette a un utente standard di violare i confini delle autorizzazioni di Windows. L’exploit pubblicato su GitHub, è stato testato su una Windows 11 25H2 completamente aggiornato con Kaspersky Endpoint Security 14.0.0.504. In caso di successo, HardBreacher crea un file MY_SNAKE_IS_SOLID.dll nella directory C:\Windows\System32 e concede all’utente corrente l’accesso completo all’oggetto creato. Un account utente standard non dovrebbe poter scrivere liberamente file in System32, quindi un risultato del genere indica una violazione del meccanismo di separazione delle autorizzazioni. Nightmare Eclipse non nasconde che la versione attuale di HardBreacher funzioni in modo instabile. L’exploit spesso termina con un errore, quindi l’esperto ha dovuto lanciarlo più volte. L’autore ritiene che il meccanismo trovato possa essere trasformato in un exploit stabile e nascosto che funziona al primo tentativo, ma una versione pronta di tale livello non è ancora disponibile. Secondo la descrizione dell’esperto, il problema è legato all’interazione di Kaspersky Endpoint Security con il proprio processo di interfaccia. Dopo aver ottenuto il controllo sul processo di interfaccia, il software di protezione inizia a comportarsi in modo non corretto. Nightmare Eclipse afferma di essere riuscito a compromettere il funzionamento del prodotto e a influenzare le operazioni di accesso ai file. I dettagli tecnici del meccanismo sono stati rivelati solo parzialmente, quindi è difficile valutare indipendentemente l’intero possibile spettro delle conseguenze. Chiamare HardBreacher un metodo pronto per ottenere immediatamente il controllo completo su Windows è ancora prematuro. La dimostrazione pubblica PoC mostra la scrittura di un oggetto in una directory sistemica protetta, ma l’autore non ha mostrato una catena stabile che porta ogni volta all’esecuzione di codice arbitrario con i privilegi SYSTEM . La riproduzione indipendente di HardBreacher da parte di altri esperti non è ancora avvenuta. Al 31 agosto, la vulnerabilità non ha ricevuto un CVE e Kaspersky non ha confermato pubblicamente il problema segnalato né ha indicato l’elenco delle versioni interessate. Un’altra questione riguarda l’entità della potenziale vulnerabilità. Nightmare Eclipse ha testato solo Kaspersky Endpoint Security 14.0.0.504, quindi non è possibile estendere le conclusioni ad altre build del prodotto. Non è noto se per l’attacco sia necessaria una configurazione specifica del software di protezione o se HardBreacher possa funzionare con le impostazioni predefinite. Nightmare Eclipse ha già attirato l’attenzione con la pubblicazione di vulnerabilità nei mezzi di protezione di Windows. In primavera, l’esperto ha rilasciato diversi PoC relativi a Microsoft Defender, tra cui BlueHammer, RedSun e UnDefend . In seguito, gli specialisti di Huntress hanno registrato l’uso delle creazioni di Nightmare Eclipse . In quell’incidente, i malintenzionati hanno tentato di utilizzare gli strumenti pubblicati dopo essere penetrati in una rete aziendale, anche se la maggior parte dei tentativi di sfruttamento è fallita. La storia di HardBreacher mostra una caratteristica sgradevole della protezione endpoint. Gli antivirus e gli EDR operano con privilegi elevati, intercettano le operazioni sui file e si integrano profondamente con Windows. Un errore all’interno di un tale prodotto offre potenzialmente all’attaccante molte più possibilità rispetto a una vulnerabilità di un’applicazione utente standard. Finora HardBreacher rimane un PoC di ricerca non confermato e instabile, ma la pubblicazione del codice funzionante aumenta notevolmente l’interesse per la verifica del problema segnalato. L'articolo Nightmare Eclipse passa a Kaspersky. Su GitHub pubblica uno 0day in Kaspersky Endpoint Security proviene da Red Hot Cyber .
redhotcyber.comAug 31, 2026extracted
Exploits and vulnerabilities in Q2 2026
The vulnerability landscape shifted significantly in Q2 2026. First, the number of registered CVEs reached an unprecedented level. This is driven primarily by the widespread adoption of AI, both for application development and search for security flaws. This resulted in entire new classes of vulnerabilities emerging, particularly in the Linux networking subsystem. Second, security researchers have been publishing exploits for unpatched vulnerabilities more frequently. Publications like these can generate significant fallout, since they potentially open the door for attackers to target unprotected systems. Statistics on registered vulnerabilities This section provides statistical data on registered vulnerabilities. The data comes from Kaspersky’s vulnerability knowledge base, which draws on the CVE database as well as the Russian BDU database and GitHub Advisory (GHSA). As a result, the figures for previous reporting periods may differ from those published in earlier reports. We examine the number of registered vulnerabilities for each month over the last five years. As the chart below shows, this number continues to surge, a trend reflected across all the databases we track. It’s driven primarily by the widespread adoption of AI tools: as we predicted in our previous report , these tools have played a major role in the discovery of vulnerabilities in third-party software. Meanwhile, these tools often contain security issues of their own. For example, OpenClaw, a popular AI project, ranked 12th among those with the highest number of vulnerabilities discovered and published in Q2, with over 200 CVEs registered during the reporting period. Finally, AI development tools are also contributing to the vulnerability landscape, since the quality of the code they produce can vary widely. Therefore, the rate at which new vulnerabilities are discovered will inevitably keep growing. Total published vulnerabilities per month from 2022 through 2026 ( download ) Next, we analyze the number of new critical vulnerabilities (CVSS > 9.0) over the same period. Total critical vulnerabilities published per month from 2022 through 2026 ( download ) As the chart shows, the number of published critical vulnerabilities jumped sharply in Q2. This is because using AI for vulnerability research makes it possible to analyze massive amounts of previously unexamined code, uncover new attack surfaces, and identify entire classes of vulnerabilities that have gone unnoticed for decades. In particular, AI was used to find a series of Dirty Frag vulnerabilities in the Linux kernel. Exploitation statistics This section presents statistics on vulnerability exploitation for Q2 2026. The data draws on open sources and our telemetry. Windows and Linux vulnerability exploitation Q2 2026 saw a new precedent in the publication of vulnerabilities in Windows components and exploits for these: researchers no longer waiting for CVE registration, let alone patches. A case in point: a researcher who goes by Nightmare Eclipse (also known as Chaotic Eclipse) published a list of new “named” vulnerabilities across various Windows subsystems. At the time the technical details were published, none of the vulnerabilities had been assigned a CVE identifier: BlueHammer : a local privilege escalation vulnerability in Windows Defender. During signature database updates, a time-of-check to time-of-use (TOCTOU) race condition occurs, allowing an attacker to substitute the directory where temporary update files are written. The researcher published a fully functional exploit for the vulnerability. RedSun : another logical vulnerability in Windows Defender with a working exploit. Suspicious and malicious files marked as “cloud” can be overwritten or restored to their original directory with elevated privileges. The exploit incorporates fragments of algorithms that make it possible to leverage various logical vulnerabilities in Windows, effectively combining a large number of popular exploitation techniques. YellowKey : a vulnerability that lets the user bypass BitLocker full-disk encryption and access system data through the Windows Recovery Environment (WinRE). A fully functional exploit was also published. GreenPlasma : a vulnerability that enables system object injection via the CTF loader for the Collaborative Translation Framework (CTFMON) service in Windows. The original publication included an exploit with limited functionality. RougePlanet : yet another Windows Defender vulnerability that, like BlueHammer, stems from a TOCTOU issue, this time in the engine responsible for real-time system scanning. The published exploit uses the vulnerability to overwrite the system file wermgr.exe with a malicious one. UnDefend : another vulnerability in the Windows Defender service. This time, the exploit causes a denial of service and blocks updates. Even though such cases remain isolated for now, we believe they’ll grow into a full-fledged trend. Early publication of exploits gives attackers an advantage over software developers, who are left with no time to fix the issues. Veteran vulnerabilities in Windows software also remain relevant. These are the ones our solutions most frequently detect exploits for: CVE-2018-0802: a remote code execution (RCE) vulnerability in the Equation Editor component CVE-2017-11882: another RCE vulnerability also affecting Equation Editor CVE-2017-0199: a vulnerability in Microsoft Office and WordPad that allows an attacker to gain control over the system CVE-2023-38831: a vulnerability in WinRAR that involves improper handling of objects within an archive CVE-2025-6218 (formerly ZDI-CAN-27198): another WinRAR vulnerability allowing the specification of relative paths to extract files into arbitrary directories, potentially leading to malicious command execution CVE-2025-8088: a vulnerability similar in exploitation method to CVE-2025-6218. The attackers used NTFS Streams to circumvent controls on the directory into which files are being unpacked The vulnerabilities listed here can be leveraged to gain initial access to a vulnerable system and for privilege escalation. This underscores the critical importance of timely software updates. That said, the number of Windows users who encountered exploits declined slightly in Q2, hitting an 18-month low. Dynamics of the number of Windows users encountering exploits, Q1 2025 – Q2 2026. The number of users who encountered exploits in Q1 2025 is taken as 100% ( download ) Linux also hit a rough patch in Q2 2026. Specifically, the period saw the disclosure of the Dirty Frag family of vulnerabilities, which lets an attacker reliably escalate privileges within the operating system. All the vulnerabilities published in Q2 2026 were, in one way or another, related to the Linux caching subsystem. Here are the ones being most actively exploited: CVE-2026-31431 (Copy Fail) : a local privilege escalation vulnerability in the Linux kernel that lets an unprivileged user modify the page cache and gain root privileges. Especially dangerous for cloud and containerized environments CVE-2026-43284, CVE-2026-43500 (Dirty Frag) : a family of vulnerabilities in the Linux networking subsystem (IPsec ESP and RxRPC) that lets a local user overwrite the page cache and escalate privileges to root CVE-2026-46300 (Fragnesia) : a local privilege escalation vulnerability in the Linux kernel related to packet fragment handling and the page cache mechanism. It lets an unprivileged user gain root privileges and is also classified as part of the Dirty Frag family CVE-2026-31635 (DirtyDecrypt) : a Linux kernel vulnerability that lets a local attacker escalate privileges due to improper handling of decryption operations and page cache data modification CVE-2026-43494 (PinTheft) : a Linux kernel vulnerability that lets a local user gain elevated privileges due to errors in the memory page pinning mechanism CVE-2026-46331 (pedit COW) : a vulnerability in the Linux kernel’s traffic control subsystem (tc-pedit) that exploits a flaw in copy-on-write to modify the page cache and subsequently escalate privileges to root The vulnerabilities described above were quickly embraced by attackers. At the same time, our solutions continue to detect exploitation attempts targeting older vulnerabilities as well: CVE-2022-0847: a vulnerability known as Dirty Pipe, which enables privilege escalation and the hijacking of running applications CVE-2019-13272: a vulnerability caused by improper handling of privilege inheritance, which can be exploited to achieve privilege escalation CVE-2021-22555: a heap out-of-bounds write vulnerability in the Netfilter kernel subsystem CVE-2023-32233: another Netfilter subsystem vulnerability that allows for Use-After-Free conditions and privilege escalation through improper processing of network requests Dynamics of the number of Linux users encountering exploits, Q1 2025 – Q2 2026. The number of users who encountered exploits in Q1 2025 is taken as 100% ( download ) In Q2 2026, the number of Linux users who encountered exploits declined slightly compared to Q1. Given that a significant share of new vulnerabilities are tied to the operating system’s caching subsystem, we recommend installing patches as quickly as possible, or disabling vulnerable kernel modules if patching isn’t an option. Most common published exploits The distribution of published exploits by software type in Q2 2026 includes categories that haven’t appeared in the sample for a long time. For instance, we’re once again seeing exploits targeting SharePoint. It’s worth noting that while several vulnerability write-ups for Exchange and SharePoint were published during the quarter, most turned out to be fake, AI-generated research. While the articles and exploit source code themselves look fairly polished, they describe nonexistent problems in the software or its components — often close to genuinely vulnerable mechanisms — in order to mislead researchers. This type of attack is aimed at increasing the time it takes to detect real vulnerabilities. In some cases, the description of a nonexistent vulnerability came bundled with completely unrelated malware. Distribution of published exploits by platform, Q1 2026 ( download ) Distribution of published exploits by platform, Q2 2026 ( download ) Vulnerability exploitation in APT attacks We analyzed which vulnerabilities were exploited in APT attacks during Q2 2026. The rankings provided below include data based on our telemetry, research, and open sources. TOP 10 vulnerabilities exploited in APT attacks, Q2 2026 ( download ) In Q2 2026, a trend emerged in APT attacks toward exploiting new vulnerabilities right from the moment they’re published. As before, we’re also seeing a large number of zero-day vulnerabilities. The Langflow vulnerability deserves particular attention: it’s one of the first cases of an APT group exploiting AI technology, which many organizations are only just beginning to integrate. Because most of this tech is proprietary, it has a considerable number of security blind spots. Therefore, given the growing number of AI-based automation tools, we strongly recommend going beyond the usual patching and developing secure procedures for credential use and sensitive data handling in systems that rely on agents and LLMs. C2 frameworks In this section, we examine the most popular C2 frameworks used by APT groups and analyze the vulnerabilities targeted by the exploits that interacted with C2 agents in APT attacks. The chart below shows the frequency of known C2 framework usage in attacks during Q2 2026, according to open sources. TOP 10 C2 frameworks used by APTs to compromise user systems, Q2 2026 ( download ) Sliver, Havoc, AdaptixC2, and Metasploit remain the most widely used C2 frameworks. After studying open sources and analyzing samples of malicious C2 agents that contained exploits, we determined that the following vulnerabilities were utilized in APT attacks involving the C2 frameworks mentioned above: CVE-2026-35273: a vulnerability in Oracle PeopleSoft PeopleTools that security vendors classify as server-side request forgery (SSRF). The details of the vulnerability have never been disclosed, although some research covers the post-exploitation steps CVE-2023-46604: an insecure deserialization vulnerability in Apache ActiveMQ that allows arbitrary code execution in the context of the service process CVE-2024-12356 and CVE-2026-1731: command injection vulnerabilities in BeyondTrust software that allow an attacker to send malicious commands even without system authentication CVE-2023-36884: a vulnerability in the Windows Search component that allows commands to be run on the system, bypassing the mark-of-the-web (MoTW) mechanism CVE-2025-53770: an insecure deserialization vulnerability in Microsoft SharePoint that allows for unauthenticated command execution on the server CVE-2025-8088 and CVE-2025-6218: similar directory traversal vulnerabilities in WinRAR that allow files to be extracted from an archive to a predetermined path, potentially without the archiving utility displaying any alerts to the user These vulnerabilities show that attackers used them for initial access and privilege escalation on vulnerable systems, setting the stage for launching a C2 agent. They include both zero-day vulnerabilities and fairly well-known security issues. LLM/AI tool vulnerabilities This section analyzes data published in Kaspersky’s vulnerability knowledge base. We reviewed the Q2 2026 version of the knowledge base. As mentioned above, AI tools, plugins, and technologies have proven fairly effective at automating the search for problematic code and anomalous behavior. The high speed at which new vulnerabilities are being discovered has naturally created a need to fix them just as quickly. AI is often used for this too, which increases the volume of code being generated. However, neither code written without human involvement nor AI-generated advice is always correct. The chart below covers registered vulnerabilities in AI tools for 2025–2026. Number of published vulnerabilities in LLMs, AI tools, and plugins with similar functionality, 2025–2026 ( download ) As the charts show, AI tools are racking up a substantial number of registered vulnerabilities, and that number keeps growing quarter over quarter. It’s also worth looking at how AI tool vulnerabilities break down by type, according to the CWE system: TOP 6 vulnerability types in products that implement or use AI/LLM logic, 2025–2026 Interestingly, vulnerabilities of an undetermined type have ranked first in every quarter since the start of 2025. Traditionally-made software has the same issue, and it doesn’t look like the growing number of AI tools will fix it. It’s also notable that the list includes classes CWE developers themselves don’t recommend using for vulnerability classification , since they lump together a whole range of more specific types. CWE-284 is an example of this. Looking at the most common classes, the key issues found in AI-related software can be summed up as follows: Inadequate access control over critical system objects Improper implementation of authentication and authorization mechanisms Injections It’s worth noting that injection-related vulnerabilities were relatively rare before AI agents took off (previously, they mostly affected web apps). Recently, though, these security issues have become relevant again. Looking back at a year and a half of the AI boom, one conclusion stands out regarding registered vulnerabilities: AI tool developers are more focused on expanding functionality than on security. This is worth keeping in mind when using these tools. Let’s look at the projects and applications that either integrated AI tools or offered them as the core product. Below is a list of the those with the highest number of registered vulnerabilities for 2025–2026. TOP AI/LLM-related projects by number of published vulnerabilities, 2025–2026 ( download ) Notable vulnerabilities This section highlights the most significant vulnerabilities published in Q2 2026 that have publicly available descriptions. Since the above already covers several significant vulnerabilities published during the reporting period, this section consists mainly of LLM/AI tool vulnerabilities. CVE-2026-25253: a gatewayUrl vulnerability in OpenClaw The issue stems from the fact that the OpenClaw user interface trusts the value of the gatewayUrl parameter passed in the URL and automatically establishes a WebSocket connection to the specified address. During this connection process, it sends an authentication token without any additional user confirmation. The attack algorithm exploiting this vulnerability works as follows: The application obtains a critical connection address from an external source (the gatewayUrl URL parameter), which is controlled by the attacker. There is no validation before use. The client automatically initiates a connection to the address specified in the parameter, which belongs to the attacker. While connected, the application sends credentials (an access token) to the specified address. If the attacker obtains a valid token, the consequences depend on that token’s level of access within the system. In general, this could lead to: User session compromise Execution of operations on the user’s behalf Modification of the AI agent configuration Unauthorized access to tools and resources connected to the agent Under certain OpenClaw configurations, further compromise of the host running the agent It’s worth noting that the risk of exploitation arises from a combination of several factors: the automatic connection and token transmission, the lack of address trust verification, and the high privileges granted to the local AI agent. CVE-2026-41948: a path traversal vulnerability in the Dify AI platform The vulnerability lets an authenticated user craft a request that enables the application to escape its permitted tenant and gain access to internal REST APIs that weren’t meant for that user. The root cause is insufficient normalization and validation of the URL path before it’s passed to the internal service. Depending on the Dify configuration, the consequences can include: Unauthorized access to internal service interfaces Breach of isolation between workspaces Exposure of internal service information Conditions favorable to further attacks when combined with other vulnerabilities The use of Dify in enterprise AI platforms is particularly risky, since internal services there tend to hold elevated privileges. CVE-2026-45386: an improper access control vulnerability in Open WebUI In Open WebUI, pin/unpin operations on messages are write operations, since they modify that message’s metadata (is_pinned, pinned_by, pinned_at). In vulnerable versions, however, before performing these actions, the API only checked for read access to the channel (a chat between a user or group and the AI) containing the message, not permission to modify its content. As a result, a user with a role limited to viewing messages could still change a message’s pinned status. The vulnerability’s mechanism works as follows: The user initiates an action that changes the state of an object. The application treats this action as a regular read request. Only channel view permission is checked. The application performs a write without verifying the required user authorization. This violates one of the fundamental principles of access control models — namely, that any operation that changes the state of data must be checked for the appropriate write or moderation permissions, regardless of whether the object itself is readable. Although the vulnerability doesn’t lead to arbitrary code execution or compromise of sensitive data, it can affect data integrity and collaborative workflows. Potential consequences of exploitation include unauthorized pinning or unpinning of messages, disruption of channel moderators’ and administrators’ activities, changes to the display order of important information, and even the potential spread of false or misleading information by altering the channel containing a pinned message. Open WebUI is widely used as an interface for interacting with local and enterprise LLMs. In these systems, pinned messages often contain important instructions, announcements, or tips for users. The ability to modify them with minimal privileges can disrupt collaborative workflows, cause confusion, and undermine trust in information published by administrators and moderators. CVE-2026-45501: a vulnerability in Microsoft Exchange The vulnerability stems from improper neutralization of user input when generating Exchange web pages. As a result, the browser may interpret specially crafted data as active content instead of plain text. Although Microsoft categorizes the potential impact of exploiting this vulnerability as spoofing, flaws like this can lead to alteration of displayed content, imitation of trusted interfaces, actions on behalf of the user within an active session, and abuse of user trust. It’s worth noting that issues like this are still relevant in modern software, given that mechanisms like Content Security Policy and various parsers were specifically created to help developers neutralize dangerous parts of user page content. Conclusion and advice Q2 brought the first significant results of AI automation adoption in software development and vulnerability hunting tools. This research shows that beyond traditional patch management, organizations now need real-time monitoring of systems and access controls, since infrastructure and everyday applications now contain far more AI functionality that could lead to compromise. Accordingly, besides quickly detecting infrastructure vulnerabilities and managing security patches, modern enterprise-grade security solutions need to provide a broad range of preventive measures for tracking the overall health of systems and workstations. Kaspersky Next meets these requirements by combining proactive mechanisms with the ability to respond promptly to emerging threats.
securelist.comAug 26, 2026extracted
Microsoft Patches Exploited Entra ID Vulnerability
Microsoft on Thursday announced the rollout of 22 new security updates that resolve severe vulnerabilities across multiple products, including a critical Entra ID zero-day exploited in attacks. The exploited Entra ID flaw is tracked as CVE-2026-69836, and it could have been exploited for remote code execution (RCE). Microsoft discovered the issue internally and patched it on the server side, with no action required from customers. The tech giant has not shared any information about the attacks involving exploitation of CVE-2026-69836. Most of the other patches address critical and high-severity flaws in Microsoft Azure, Entra ID, Exchange, Fabric, and Partner Center products. The most severe of these include elevation-of-privilege (EoP) bugs in Azure SQL Database (CVE-2026-69502), Azure Arc (CVE-2026-69555 and CVE-2026-65816), and Exchange Online (CVE-2026-65801), as well as an RCE flaw in Azure Managed Instance for Apache Cassandra (CVE-2026-65770), all with a CVSS score of 10/10. Seven other critical EoP issues were resolved: CVE-2026-68782 (Azure SQL Database), CVE-2026-63509 (Microsoft Fabric), CVE-2026-69851 (Entra ID), CVE-2026-68789 (Azure SQL Database), CVE-2026-69400 (Azure Logic Apps), CVE-2026-62834 (Azure Data Factor), and CVE-2026-66309 (Azure SQL Database). Additionally, Microsoft patched high-severity vulnerabilities in Azure Virtual Machines, Microsoft Partner Center, Azure Data Factory, Azure Stack HCI, Azure Data Manager for Energy, Copilot in Azure, and Windows Remote Help Defense. No customer action is required for the majority of these security defects, as Microsoft has deployed the mitigations on the server side. Earlier this week, Microsoft fixed a high-severity command injection bug in Copilot that could be exploited remotely for information disclosure (CVE-2026-24301). Last week, the company announced that it was working on patches for ShieldBreak, a zero-day Defender exploit dropped on August 2026 Patch Tuesday by security researcher Nightmare Eclipse (also known as Chaotic Eclipse). The company assesses that the vulnerability ShieldBreak targets is a high-severity bug, now tracked as CVE-2026-69414 (CVSS score of 7.8). “Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as ‘ShieldBreak’. We are working to provide a high-quality security update that addresses this vulnerability,” the company said. Headline and body of the article have been updated to show that the Entra ID vulnerability has been exploited Related: CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities Related: Critical GitLab Flaw Exploited Shortly After Disclosure
securityweek.comAug 21, 2026extracted
CVE-2026-12957 and CVE-2026-12958 - Issues in Language Servers for AWS and Amazon Q Developer Plugins
CVE-2026-12957 and CVE-2026-12958 - Issues in Language Servers for AWS and Amazon Q Developer Plugins Bulletin ID: 2026-047-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/23/2026 09:00 AM PDT Description: Language Servers for AWS provide the underlying language-server runtime that powers Amazon Q Developer's AI coding assistance across its IDE plugins (Visual Studio Code, JetBrains, Eclipse, and Visual Studio). We identified CVE-2026-12957, an improper trust boundary enforcement issue in Language Servers for AWS before version 1.65.0. If a local user opens a maliciously crafted workspace, any commands within the project configuration files may be automatically executed. This issue requires the user to trust the workspace when prompted. We identified CVE-2026-12958, a missing symlink-validation issue in Language Servers for AWS before version 1.69.0. This may occur when a local user opens a workspace with a maliciously crafted symlink that resolves to a file path outside the workspace trust boundary. These issues affect the Amazon Q Developer IDE plugins, which bundle Language Servers for AWS. Both issues are remediated in Language Servers for AWS version 1.69.0. Affected products & versions: Language Servers for AWS: < 1.69.0 Amazon Q Developer for Visual Studio Code: < 2.20 Amazon Q Developer for JetBains: < 4.3 Amazon Q Developer for Eclipse: < 2.7.4 AWS Toolkit with Amazon Q for Visual Studio: < 1.94.0.0 Resolution: These issues have been addressed in Language Servers for AWS version 1.69.0 and the corresponding Amazon Q Developer plugin releases that bundle it. We recommend upgrading to the latest version of your Amazon Q Developer IDE plugin, and ensuring any forked or derivative code is patched to incorporate the new fixes. Amazon Q Developer for VS Code Amazon Q Developer for JetBrains Amazon Q Developer for Eclipse Amazon Q Developer for Visual Studio Workarounds: No workarounds are available. References: Acknowledgement: We would like to thank Wiz for collaborating on this issue through the coordinated vulnerability disclosure process. Please email [email protected] with any security questions or concerns.
aws.amazon.comAug 20, 2026extracted
Microsoft working on Defender patch for ShieldBreak zero-day
On Friday, Microsoft confirmed it has begun working on a security patch for a Defender zero-day vulnerability named "ShieldBreak." A security researcher who uses the "Nightmare Eclipse" handle disclosed this privilege escalation vulnerability after Microsoft released the August 2026 Patch Tuesday security updates. "Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims," a Microsoft spokesperson told BleepingComputer when asked for a statement regarding the new ShieldBreak zero-day. "Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible." Nightmare Eclipse described ShieldBreak as a bypass for RoguePlanet, another Defender privilege escalation flaw disclosed in June, and shared a ShieldBreak proof-of-concept (PoC) exploit that local attackers with limited permissions can use to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems. "Microsoft has failed to properly patch the RoguePlanet vulnerability CVE-2026-50656, this PoC demonstrates a full patch bypass," Nightmare Eclipse said. "The PoC was tested in the latest version of windows 11 25h2 (+Canary channel) and windows server 2025, the PoC also have a 100% success rate. Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to ShieldBreak as well." Vulnerability analyst Will Dormann confirmed last week that the ShieldBreak exploit works but added that Microsoft Defender must also be enabled for attackers to escalate privileges. Tracked as CVE-2026-69414 and waiting for a patch On Friday, three days after ShieldBreak was disclosed, Microsoft said it's now tracking the flaw as CVE-2026-69414and confirmed it's working on a patch, but has yet to acknowledge that Nightmare Eclipse found it. "Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as 'ShieldBreak,'" the company said. "We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available." Nightmare Eclipse publicly disclosed ShieldBreak without notice to Microsoft as part of an ongoing dispute with the company over its vulnerability disclosure and bug bounty practices. Days after the researcher published PoC exploits without prior notice, Microsoft responded with warnings of legal action against people engaging in "malicious activity causing real harm" to its customers, prompting many to believe that the company was directly threatening the security researcher. Since April, Nightmare Eclipse has disclosed multiple zero-day exploits targeting Microsoft Defender, BitLocker, and various other Windows components, now known as LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend. While the company fixed the YellowKey, GreenPlasma, and MiniPlasma flaws as part of the June 2026 Patch Tuesday and RoguePlanet in July, the other security flaws disclosed by Nightmare Eclipse remain zero-days and are still awaiting an official patch. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 17, 2026extracted
Windows nel mirino: l’exploit ShieldBreak mette in crisi Microsoft Defender dopo il Patch Tuesday
Betti RHC, la prima graphic novel al mondo dedicata alla cybersecurity awareness, ha finalmente il suo sito ufficiale. Uno spazio tutto suo dove scoprire il progetto, sfogliare le copertine degli episodi e immergersi nel mondo di Betti: la giovane laureanda in informatica che, dopo la morte misteriosa del padre, si trasforma nell'hacker più potente del mondo. Una storia avvincente che, episodio dopo episodio, affronta una minaccia digitale diversa — dal phishing al ransomware, fino al cyberbullismo — e insegna a riconoscerla e a difendersi, senza che sembri mai una lezione. Sul sito trovate tutto ciò che rende Betti un progetto diverso dal solito: la sua filosofia, le anteprime delle tavole e il racconto di come nasce ogni volume. Perché dietro Betti RHC c'è solo lavoro umano: ogni tavola è disegnata interamente a mano dagli artisti del Gruppo Arte di Red Hot Cyber, senza alcun uso di intelligenza artificiale. E a garantire che ogni storia sia realistica e tecnicamente corretta c'è la supervisione degli hacker etici del gruppo HackerHood, che mantengono il racconto fedele al mondo reale della sicurezza informatica. C'è spazio anche per le aziende, che possono usare Betti come strumento di awareness diverso dai soliti corsi: acquistare i volumi, personalizzarli con il proprio brand o sponsorizzare nuovi episodi. E come primo regalo, l'episodio "Byte the Silence", dedicato al cyberbullismo, è scaricabile gratuitamente per uso personale. Perché la miglior difesa, in fondo, è una bella storia. 👉 Scopri tutto su https://betti.redhotcyber.com/
redhotcyber.comAug 16, 2026extracted
Microsoft patches LegacyHive Windows zero-day vulnerability
Microsoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday. The security flaw was disclosed by a security researcher who uses the "Nightmare Eclipse" handle in protest of Microsoft's bug bounty and vulnerability disclosure practices. Nightmare Eclipse published a LegacyHive proof-of-concept (PoC) exploit hours after the July 2026 Patch Tuesday security updates were released, claiming it exploits a security vulnerability in the Windows User Profile Service. However, unlike previous exploits they released, the LegacyHive PoC requires additional credentials, making it harder for threat actors to weaponize the vulnerability. "Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims," a Microsoft spokesperson told BleepingComputer when asked for a statement regarding LegacyHive. Vulnerability analyst Will Dormann explained that non-admin users can use Nightmare Eclipse's exploit to modify the classes registry hive and gain automatic code execution when the admin account logs in to a compromised system. One day after the PoC was released, cybersecurity expert Kevin Beaumont also published LegacyHive exploitation detection queries for Microsoft Defender for Endpoint (MDE) and confirmed that the exploit worked. Official LegacyHive patches available Microsoft has now patched the vulnerability this week as part of its August Patch Tuesday updates and now tracks it as CVE-2026-62832. However, it has yet to acknowledge that Nightmare Eclipse discovered the flaw, instead tagging it as reported by an anonymous researcher. The company says that LegacyHive stems from improper link resolution before file access ('link following') in the Windows User Profile Service, and successful exploitation allows local attackers to gain administrator privileges. "An authenticated attacker who has credentials for another local account could run a specially crafted application to load another user's registry hive," Microsoft says. "Successful exploitation could allow the attacker to access or modify another user's data and gain administrator privileges. User interaction is not required." ACROS Security, the company behind the 0Patch cybersecurity platform, also released free unofficial LegacyHive patches on July 20 for systems running Windows 10 2004 or later and Windows Server 2022 or later. Nightmare Eclipse has disclosed multiple zero-day flaws since April 2026, including ShieldBreak, LegacyHive, RoguePlanet, YellowKey, BlueHammer, RedSun, GreenPlasma, MiniPlasma, and UnDefend in Microsoft Defender, BitLocker, and other Windows components. Microsoft patched the YellowKey, GreenPlasma, and MiniPlasma flaws as part of the June 2026 Patch Tuesday, and the RoguePlanet vulnerability in July, but the other zero-days are still awaiting an official patch. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 13, 2026extracted
Adobe Commerce Bug Targeted Immediately After Disclosure
Hackers started targeting a fresh critical-severity Adobe Commerce vulnerability immediately after public disclosure, webstore security firm Sansec reports. Tracked as CVE-2026-71362 (CVSS score of 9.1), the security defect is described as an incorrect authorization issue that allows unauthenticated attackers to elevate their privileges. Adobe resolved the flaw on August 2026 Patch Tuesday, saying it had no evidence of in-the-wild exploitation, but warning that threat actors have targeted Commerce before. Shortly after Adobe’s advisory was published, Sansec warned that it blocked the first exploitation attempts targeting the CVE. According to Sansec, the flaw can be exploited by remote, unauthenticated attackers to take over other customer accounts. “Sansec reviewed the patch and confirmed that the vulnerability lets attackers switch a customer session to another customer account. This gives them access to the victim’s account and private customer data,” the cybersecurity firm notes. Adobe resolved the underlying issue by modifying how Commerce and Magento handle customer identity in account sessions, Sansec says. The vulnerability impacts all Commerce, Commerce B2B, and Magento Open Source versions up to and including those running the July 2026 patches. On Tuesday, Adobe rolled out an isolated patch to fix the critical flaw and six other security defects in all three products, and published installation instructions. “Please apply the latest security updates as soon as possible. Successful exploitation of these vulnerabilities could lead to arbitrary code execution, security feature bypass, and privilege escalation,” the company notes. “[The isolated patch] allows merchants to apply the fix in isolation with fewer risks of delay due to potential integration issues,” Adobe says. Related: WordPress 7.0.4 Patches Remote Code Execution Vulnerability Related: Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’ Related: Zoom Patches Zero-Click Code Execution Vulnerability Related: SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform
securityweek.comAug 13, 2026extracted
Fortinet Patches Authentication Flaws in FortiWeb and FortiManager
Fortinet on Wednesday announced patches for eight vulnerabilities across its products, including high-severity authentication bugs in FortiWeb and FortiManager. In FortiWeb, the company resolved an improper authentication issue impacting deployments configured with specific, non-default settings. A remote, unauthenticated attacker could exploit the flaw, tracked as CVE-2026-26035, “to log in to the FortiWeb GUI/CLI with a random username and password,” Fortinet explains. The weakness is associated with the wildcard setting for administrator accounts, which is disabled by default. When it is enabled, the system will match any username on a remote server with the Remote User account. “When wildcard is enabled, and if you have defined a group name in the Admin User Group (User > User Group > Admin Group), then the system will match the users on the remote server whose group name value is the same as you defined,” Fortinet explains. CVE-2026-26035 was patched in FortiWeb versions 8.0.3, 7.6.7, 7.4.12, and 7.2.13. As a workaround, the company recommends disabling the wildcard setting. The FortiManager vulnerability, tracked as CVE-2026-70468, is an authentication bypass issue that allows remote attackers to impersonate any FortiGate device managed by FortiManager. It requires a specific CLI option to be set and for the attacker to have a valid certificate. Fortinet also patched a high-severity buffer overflow bug (CVE-2026-70465) in FortiClient for Windows that could allow unauthenticated attackers who can modify or craft DNS responses to execute arbitrary code. On Wednesday, the company also resolved medium- and low-severity security defects in FortiWeb WAF, FortiOS, and FortiSIEM, and published an advisory detailing the impact of CVE-2026-49975, the HTTP/2 Bomb attack affecting Apache HTTP Server. Fortinet makes no mention of any of these vulnerabilities being exploited in the wild. Additional information can be found on the company’s PSIRT advisories page. Related: Critical VMware vCenter Vulnerability in Attackers’ Crosshairs Related: Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’ Related: SharePoint Vulnerability Exploited Shortly After PoC Release Related: Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws
securityweek.comAug 13, 2026extracted
Critical VMware vCenter Vulnerability in Attackers’ Crosshairs
Threat actors have started exploiting a recently patched critical-severity vulnerability in VMware vCenter, rapid incident response company Quirso reports. The bug was disclosed on July 29, when Broadcom patched it alongside four other security defects in multiple VMware products. Tracked as CVE-2026-59310 (CVSS score of 9.8), the flaw is described as a directory traversal issue in the Syslog server that leads to remote code execution. “A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code,” Broadcom’s advisory reads. According to Quirso, an advanced persistent threat (APT) actor has been exploiting web-accessible VMware vCenter servers vulnerable to CVE-2026-59310, using a reverse shell for persistent access. The cybersecurity company identified over 360 victim IP addresses across 47 countries, half of which are distributed across only five countries: Germany, the US, Turkey, Iran, and France. “The exact number of victim organizations cannot be inferred from these IP addresses, as an IP address does not necessarily correspond to a unique company or physical system. Some addresses belong to hosting providers, cloud networks, or shared infrastructure,” Quirso says. According to the company, the exploitation started on August 3, with over 340 victim IP addresses seen connecting to the attackers’ infrastructure by August 5. “While the attacker might have had prior knowledge of the vulnerability, the strong correlation between the time of disclosure and exploitation suggests the disclosure as the initial starting point for the campaign,” Quirso notes. Following initial compromise, the attackers dropped the open source SSH reverse shell framework reverse_ssh to maintain an outbound control connection from the compromised systems, bypassing security controls that typically block inbound connections. Quirso released a generic YARA rule for identifying reverse_ssh builds. As the tool can also be used for legitimate penetration testing, organizations with publicly accessible vCenter systems are advised to validate any detections by also looking for unauthorized installations and unexpected outbound connections and execution. Related: Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’ Related: Fresh Windows Zero-Day Exploited in North Korean Cyberattacks Related: ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact Related: SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform
securityweek.comAug 13, 2026extracted
Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’
Security researcher Nightmare Eclipse has dropped a fresh zero-day exploit leading to privilege escalation on Windows. Also known as Chaotic Eclipse, the disgruntled researcher released multiple zero-day exploits targeting Microsoft products over the past several months, usually right after the Patch Tuesday security updates. Right on cue, the new proof-of-concept (PoC) exploit, dubbed ShieldBreak, was published on August 2026 Patch Tuesday. It targets a vulnerability in Microsoft Defender, allowing any user to gain System privileges. According to Nightmare Eclipse, the exploit is a RoguePlanet patch bypass, works on the latest Windows 11 versions and on Windows Server 2025, and likely impacts Windows 10 machines as well. Tracked as CVE-2026-50656, RoguePlanet is a race condition flaw in Defender that Nightmare Eclipse dropped as a zero-day on June 9. Microsoft acknowledged the exploit on June 16 and released fixes for it on July 9. Per the analysis of Tharros Labs’s Will Dormann, ShieldBreak involves setting up a temporary directory registered as a Cloud Sync provider, planting an EICAR file, controlling Defender’s scan path to System32, using Windows’ CLFS to swap the identity file and hydration data to a ‘phoneinfo.dll’ file in System32, then running the QueueReporting scheduled task. “In the wer.dll code, there is explicit code to load phoneinfo.dll [which does not exist by default in Windows]. Because at this point, phoneinfo.dll exists and is our own code, this runs, spawning conhost.exe with SYSTEM privileges,” Dormann says. Both Dormann and cybersecurity expert Kevin Beaumont, who published detection queries for the fresh PoC, disagree with Nightmare Eclipse’s assertion that ShieldBreak is a RoguePlanet bypass, as they work differently. “RoguePlanet was a filesystem race condition vuln that uses virtual disks and NT native file manipulation to trick the quarantine process into overwriting system files. ShieldBreak user-mode callback hook to change file contents during a Defender cloud-hydration scan via cfapi (Cloud Filter API),” Beaumont said. Dormann also points out that “ShieldBreak seems to require Defender to be active to work,” while RoguePlanet did not. Responding to a SecurityWeek inquiry, a Microsoft spokesperson provided the following statement: “Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims. Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible. Importantly, we support coordinated vulnerability disclosure, an industry standard that protects customers and supports the research community by ensuring their findings are thoroughly investigated and addressed before being made public. *Updated with statement from Microsoft. Related: SharePoint Vulnerability Exploited Shortly After PoC Release Related: Chipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities Combined Related: Fresh Windows Zero-Day Exploited in North Korean Cyberattacks Related: Ivanti EPM Update Patches Remotely Exploitable Flaws
securityweek.comAug 13, 2026extracted
Microsoft’s massive Patch Tuesday releases continue as AI reshapes bug discovery
Microsoft’s massive Patch Tuesday releases continue as AI reshapes bug discovery Microsoft on Tuesday released fixes for 419 security vulnerabilities, one of the largest monthly counts on record and the latest sign that artificial intelligence is dramatically increasing the number of software flaws security teams must contend with. In May, when Microsoft shipped patches for 137 vulnerabilities, the company stated the industry had reached a moment “where AI-powered vulnerability discovery stops being speculative and starts being an engineering problem.” Since then, successive record-breaking releases — 206 in June, followed by 622 in July — have seen the company explode past its annual record for vulnerabilities, of around 1,250. According to the company’s August release notes, the latest update addresses 62 critical and 357 important-rated issues. As with last month, Microsoft no longer lists the individual CVEs and has replaced the previously itemized batch with a summary table showing a count of bugs by product family, alongside a “Notable CVEs” section. This month’s update features about five times the volume of patches Microsoft was shipping in a typical month before AI-assisted vulnerability discovery took hold. On the eve of that surge, Britain’s National Cyber Security Centre warned that organizations needed to prepare for a new tempo in mitigating vulnerabilities. Three of this month’s flaws are zero-days. Two were publicly disclosed before the patches dropped, while one of which — CVE-2026-68820, affecting the Windows component that handles network connections — has been seen exploited in the wild. The company tied the attacks to a campaign by Lazarus Group, which has been been targeting applicants for “attractive job opportunities at well-known companies in the defense, aerospace, and aviation industries” in a complicated attack that sees them combine PDFs with a trojanised reader allowing the hackers to secretly take control of the applicants’ machines. One of the publicly-known flaws, CVE-2026-62832, was attributed by Microsoft to an anonymous researcher. The details of the vulnerability appear to match a proof-of-concept called LegacyHive published by the pseudonymous researcher Nightmare Eclipse hours after last month’s Patch Tuesday — the latest instalment in a months-long standoff over the company’s disclosure and bounty practices. Widespread exploitation of the surge in vulnerabilities has not yet been observed. But the Five Eyes intelligence alliance warned in June that frontier AI models would soon be “fundamentally transforming both offensive and defensive cyber capabilities,” adding “the timeline is not years, it is months.” The release date marks the start of a regular cycle for cybersecurity defenders. Once a patch is out, attackers pick it apart in an attempt to reverse-engineer the holes it plugs and then race to break into machines that have not yet been updated — a phenomenon often described as “Exploit Wednesday.” Although the volume of bugs likely makes it more difficult for Microsoft to provide a detailed advisory, the new clustered format of the Security Updates page risks making triage more complex. Defenders and third-party trackers must now piece together the full picture from underlying advisory feeds themselves and figure out what needs to be patched first. Alexander Martin is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79
therecord.mediaAug 12, 2026extracted
New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges
A security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldBreak" after Microsoft released the August 2026 Patch Tuesday security updates. The new vulnerability is described as a bypass for RoguePlanet, another Defender privilege escalation flaw disclosed in June and patched by Microsoft one month later. However, cybersecurity expert Kevin Beaumont, who also published ShieldBreak exploitation detection queries for Microsoft Defender for Endpoint, said that the two exploits work very differently. "RoguePlanet was a filesystem race condition vuln that uses virtual disks and NT native file manipulation to trick quarantine process into overwriting system files," Beaumont noted. "ShieldBreak user-mode callback hook to change file contents during a Defender cloud-hydration scan via cfapi (Cloud Filter API)." According to Nightmare Eclipse, ShieldBreak can be used to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems. "Microsoft has failed to properly patch the RoguePlanet vulnerability CVE-2026-50656, this PoC demonstrates a full patch bypass," they said. "The PoC was tested in the latest version of windows 11 25h2 (+Canary channel) and windows server 2025, the PoC also have a 100% success rate. Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to ShieldBreak as well." Will Dormann, principal vulnerability analyst at Tharros, , saying that Microsoft Defender needs to be enabled for the ShieldBreak exploit to escalate attackers' privileges. The ShieldBreak exploit is part of an ongoing and heated dispute between Microsoft and Nightmare Eclipse over the company's vulnerability disclosure and bug bounty practices. Microsoft responded to Nightmare Eclipse's disclosures with warnings of legal action against people engaging in "malicious activity causing real harm" to its customers, which prompted cybersecurity experts to believe the company was directly threatening the security researcher. Since April 2026, the researcher has disclosed LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend zero-day exploits targeting Microsoft Defender, BitLocker, and various other Windows components While Microsoft fixed the RoguePlanet vulnerability in July and the YellowKey, GreenPlasma, and MiniPlasma flaws as part of the June 2026 Patch Tuesday, the other vulnerabilities disclosed by Nightmare Eclipse are still waiting for an official patch. "Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims. Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible," a Microsoft spokesperson told BleepingComputer when asked for a statement regarding the new ShieldBreak zero-day exploit. "Importantly, we support coordinated vulnerability disclosure, an industry standard that protects customers and supports the research community by ensuring their findings are thoroughly investigated and addressed before being made public." Update August 13, 07:53 EDT: Added Microsoft statement. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 12, 2026extracted
Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)
Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820) Microsoft’s August 2026 Patch Tuesday delivered security fixes for 400+ vulnerabilities, including one that has been exploited in zero-day attacks (CVE-2026-68820) and three that were publicly disclosed prior to the release of the patches. Vulnerabilities of note CVE-2026-68820 is a use-after-free flaw that affects the Windows Ancillary Function Driver for WinSock (AFD.sys) and allows a low-privileged local attacker to elevate privileges to SYSTEM. “A locally authenticated attacker could run a specially crafted application on an affected system to trigger a race condition,” Microsoft explained. “User interaction is not required.” Check Point researchers reported that the vulnerability has been exploited by North Korean attackers to deploy a kernel-mode rootkit in a new wave of the Operation Dream Job campaign. The three publicly disclosed vulnerabilities are: CVE-2026-62832, a vulnerability in the Windows User Profile Service that may allow an authenticated attacker to achieve Admin privileges by running a specially crafted application. “This is the flaw behind ‘LegacyHive,’ the unpatched proof-of-concept released by researcher Nightmare-Eclipse just hours after July’s Patch Tuesday,” commented Chris Goettl, VP of Product Management for security products at Ivanti. “This vulnerability lets a standard user coerce the User Profile Service into loading another user’s registry hive – including an administrator’s – to gain unauthorized access to that user’s Classes registry data.” CVE-2026-72971 affects the Windows Container Isolation FS Filter Driver (unionfs.sys), which may allow authenticated attackers to tamper with a vulnerable system. (This one only affectes Windows 11 versions for ARM64-based Systems.) Crowdstrike flagged a third vulnerability that was publicly disclosed before the patch was made available: CVE-2026-62737, a elevation of privilege vulnerability affecting the Windows kernel “While not officially recognized by Microsoft as publicly disclosed, a Chinese-language blog was published on August 9, 2026, describing a proof-of-concept exploit that can cause a system crash,” the company noted. Other vulnerabilities of note fixed this month include: CVE-2026-62815, a critical Microsoft QUIC vulnerability that can be exploited by unauthenticated attackers by sending a specially crafted packet to an affected service over the network. “Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required,” Microsoft says. CVE-2026-62878, a stack-based buffer overflow vulnerability in Windows DNS that can lead to remote code execution. This one can also be easily, reliably and remotely exploited by unauthenticated attackers. CVE-2026-63520, in Microsoft Sharepoint, discovered by Rapid7 researchers. It can be used in conjunction with CVE-2026-55040, a previously patched Sharepoint flaw, to achieve unauthenticated remote code execution against a vulnerable server. A Microsoft Defender zero-day exploit In related news, the security researcher who goes by “Nightmare Eclipse” released a proof-of-concept (PoC) exploit that ostensibly bypasses the patch for CVE-2026-50656, the “RoguePlanet” Microsoft Defender vulnerability the company pushed out in July 2026. Dubbed “ShieldBreak” by the researcher, the vulnerability professedly affects Windows 11, 10 and Windows Server 2025. Vulnerability analyst Will Dormann confirmed that the PoC exploit works if Defender is enabled. Security researcher and former Microsoft employee Kevin Beaumont noted that the ShieldBreak exploit (aka RoguePlanet 2) “operates very differently” that the initial RoguePlanet exploit. “RoguePlanet was a filesystem race condition vuln that uses virtual disks and NT native file manipulation to trick quarantine process into overwriting system files. ShieldBreak user-mode callback hook to change file contents during a Defender cloud-hydration scan via cfapi (Cloud Filter API),” he explained, and released detections and hunting queries for the latter. He confirmed that ShieldBreak works on the latest Windows 11 version. Vulnerability analyst Will Dormann confirmed that the PoC exploit works if Defender is enabled and he also thinks ShieldBreak doesn’t seem to be a RoguePlanet bypass. Don’t rush and test patches “This volume of updates indeed seems to be the new normal – at least for now. What is interesting is that, while there is an explosion of bugs being reported (and fixed), there has been no equivalent increase in the number of bugs being actively exploited, at least as 0-days,” says Dustin Childs, head of threat awareness at TrendAI’s Zero Day Initiative. He also pointed out that Microsoft listing actively exploited bugs as “Unproven” or downplaying working Pwn2Own exploits may force security teams to perform independent risk triage. Ivanti’s Goettl says that the patches need to be triaged to identify CVEs that require immediate attention and that organizations need to remember that CVEs with high CVSS scores but which are not exploited or are not in internet-facing systems can be handled in a second round of patching. Tyler Reguly, Associate Director, Security R&D at Fortra, says that despite the latest mega-updates, IT admins and security teams should keep calm and not rush updates: “You need to make sure that you are rolling out safe updates that will not negatively impact your systems.” His advice for CISOs is to talk to their teams about how they are shifting or modifying their workflows to better accommodate this patching shift, and support them by enabling the changes they want to see made. UPDATE (August 13, 2026, 04:10 a.m. ET): The section about the ShieldBreak exploit has been rewritten to reflect new insight from security researchers who tested it. Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
helpnetsecurity.comAug 12, 2026extracted
ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access
The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldBreak. The vulnerability, rooted in Microsoft Defender for Windows, demonstrates a patch bypass for CVE-2026-50656 (CVSS score: 7.8), otherwise known as RoguePlanet. RoguePlanet has been described as a race condition that, if successfully exploited, could grant an attacker the ability to spawn a shell with SYSTEM-level privileges, enabling them to run arbitrary code or perform unauthorized actions. Although it was first disclosed by the researcher in June 2026, a patch for the vulnerability was not released by Microsoft until almost a month later. The tech giant described it as a privilege escalation issue in the Microsoft Malware Protection Engine ("mpengine.dll"). Soon after, Chaotic Eclipse said the "defense-in-depth updates" introduced by Microsoft to address CVE-2026-50656 can cause Defender to leak 8 bytes of data when attempting to open a file in certain scenarios on Windows 11 25H2 and Windows Server 2025. Microsoft told The Hacker News at the time that it's aware of the report and is investigating. ShieldBreak, on the other hand, is assessed to be a full patch bypass for CVE-2026-50656, with the researcher claiming that "Microsoft has failed to properly patch the RoguePlanet vulnerability." "The PoC was tested in the latest version of Windows 11 25h2 (+Canary channel) and Windows Server 2025, the PoC also have a 100% success rate," the researcher added. "Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to ShieldBreak as well." When contacted for comment, a Microsoft spokesperson shared the following statement with The Hacker News - Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims. Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible. Importantly, we support coordinated vulnerability disclosure, an industry standard that protects customers and supports the research community by ensuring their findings are thoroughly investigated and addressed before being made public. Security researcher Kevin Beaumont, in a post on Mastodon, confirmed the exploit works on Windows 11, adding that the two exploits work differently. "RoguePlanet was a filesystem race condition vuln that uses virtual disks and NT native file manipulation to trick quarantine process into overwriting system files," Beaumont noted. "ShieldBreak user-mode callback hook to change file contents during a Defender cloud-hydration scan via cfapi (Cloud Filter API)." Will Dormann, principal vulnerability analyst at Tharros, also validated ShieldBreak, stating Defender needs to be enabled for the exploit to work and that "my naive eyeballs fail to see the similarity" with RoguePlanet. Dormann explained the sequence of actions as follows - Plant an EICAR file Use Object Manager symlinks to control Defender's scan path to system32. During the scan, leverage CLFS to swap the identity file and hydration data to C:\Windows\system32\phoneinfo.dll (which doesn't exist by default in Windows) Run the QueueReporting scheduled task, which runs wermgr.exe -upload as Run with highest privileges "In the wer.dll code, there is explicit code to load phoneinfo.dll," the researcher said. "Because at this point, phoneinfo.dll exists and is our own code, this runs, spawning conhost.exe with SYSTEM privileges. I don't recall RoguePlanet doing anything with cloud providers, CLFS, hydration anything, phoneinfo.dll, and unlike RoguePlanet, ShieldBreak seems to require Defender to be active to work." The development comes as the Windows maker shipped patches for 421 security flaws, including 236 flaws in Windows. One of the patches involves CVE-2026-62832 (CVSS score: 7.8), a Windows User Profile Service privilege escalation vulnerability that was disclosed by Chaotic Eclipse last month under the name LegacyHive. "Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally," Microsoft said. "An authenticated attacker who has credentials for another local account could run a specially crafted application to load another user's registry hive. Successful exploitation could allow the attacker to access or modify another user's data and gain administrator privileges. User interaction is not required." Also remediated by Microsoft is an actively exploited zero-day in the Windows Ancillary Function Driver for WinSock (CVE-2026-68820, CVSS score: 7.0) that grants SYSTEM privileges and a publicly disclosed Windows Container Isolation FS Filter Driver (unionfs.sys) tampering vulnerability (CVE-2026-72971, CVSS score: 5.5). The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has since added CVE-2026-68820 to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply the fixes by August 25, 2026. Update Microsoft has assigned the CVE identifier CVE-2026-69414 (CVSS score: 7.8) for ShieldBreak, tagging it with an exploitability assessment of "Exploitation More Likely." It described the issue as a privilege escalation flaw impacting Microsoft Defender. "Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as 'ShieldBreak,'" the company said, without acknowledging Chaotic Eclipse for discovering the flaw. "We are working to provide a high quality security update that addresses this vulnerability." (The story was updated after publication on August 13, 2026, to include a response from Microsoft and additional insights related to the flaw.)
thehackernews.comAug 12, 2026extracted
Microsoft Plugs Nearly 400 Security Holes
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today. August’s overstuffed bundle of patch joy from Microsoft did not eclipse its recording breaking release of more than 570 security updates last month, but it is double June’s then-record batch of nearly 200 fixes. Microsoft has attributed the recent patch deluge to vulnerability discoveries aided by artificial intelligence, and experts roundly agree that Windows users should get used to the idea of Patch Tuesdays (the second Tuesday of each month) covering hundreds of newly discovered security flaws. Fully 42 of the 398 flaws that Microsoft patched today earned Redmond’s most-dire “critical” rating, meaning they are severe enough that malware or malcontents could exploit them to gain remote control over a Windows computer with little to no help from the user. The sole known “zero day” bug fixed by Microsoft this month is CVE-2026-68820, a privilege escalation weakness in a core Windows component called afd.sys, which the security firm Automox describes as “the driver behind Windows socket connections on effectively every endpoint.” “This isn’t a front-door bug,” Automox’s Landon Miles wrote in a Patch Tuesday blog post. “It’s step two in a chain: an attacker phishes their way into a low-privilege foothold, then uses the driver flaw to take the box. The 7.0 score reflects the high attack complexity, because race conditions are fiddly. The exploit has to be thrown over and over until the timing lands. Someone is clearly landing it anyway.” CVE-2026-62832 is another privilege escalation flaw that Microsoft has labeled likely to be exploited; this flaw, in the Windows User Profile Service, may be related to the recent “LegacyHive” public disclosure from the prolific bug hunter known as Nightmare Eclipse. The other publicly disclosed flaw is CVE-2026-72971, a low-impact local tampering vulnerability that Microsoft reckons is unlikely to be exploited. Other major software makers are likewise increasing their patch volumes and cadence thanks to AI, including Adobe which last month moved to twice-monthly security bulletins published on the 2nd and 4th Tuesday of each month. Cisco, Google, Mozilla and Oracle also are shipping updates far more frequently and abundantly. By all accounts, AI is quite good at finding security holes in software. But for now at least, patching the resulting bugpocalypse remains a heavily human-centric endeavor, and the jury is still out on whether AI technologies will turn out to be as good at fixing vulnerabilities as they are at finding and exploiting them. This is an important question when one considers that these same AI technologies also are suggesting fixes for the vulnerabilities they find. Researchers at 1Password recently examined what happens when different large language models (LLMs) generate vulnerability patches for newly disclosed, complex vulnerabilities. They found the LLMs produced patches that failed to fix the flaw or added a new weakness in the process (or both) more than half the time. Ed Skoudis, president of the SANS Technology Institute, said his team has seen excellent results using AI to generate patches, provided there are humans in the loop to test the suggested fixes and push for iterative improvements. “AI is rapidly becoming astonishingly good at finding vulnerabilities, but this research shows that fixing them is a very different problem,” Skoudis wrote in a SANS newsletter today. “Don’t expect one-shot AI patching to work reliably. Instead, iterate, test, challenge, improve, and verify. AI can be an extraordinary patching partner, but today it still needs a skilled human at the keyboard.” Tyler Reguly at Fortra says while reports of Microsoft patching hundreds of vulnerabilities in one go have prompted some organizations to try to patch faster, it’s important to bear in mind that only one of the almost 400 bugs addressed today is known to be actively exploited. Reguly suggested security leaders check in with their teams to see how they’re handling the increasing workloads, which often involve testing fixes before deploying them in production environments. “If you’re a chief security officer talk to your teams about how they are shifting or modifying their workflows to better accommodate the patching shift that we’re seeing and support them across various organizational units by enabling the changes they want to see made,” Reguly said. “There’s no need to rush these updates, no matter what various vendors and organizations try to tell you. You need to make sure that you are rolling out safe updates that will not negatively impact your systems.” Speaking of the humans behind the keyboards, don’t neglect to backup your system and/or data before applying this month’s monster patch load. The day after each month’s Patch Tuesday is sometimes derisively referred to as Reboot Wednesday, but it generally doesn’t hurt to wait a few days to apply these huge update bundles because it sometimes takes a couple of days for the occasional misbehaving patch to get ironed out properly by Microsoft. For a clickable, per-patch breakdown by severity and urgency, check out this roundup from the SANS Internet Storm Center.
krebsonsecurity.comAug 11, 2026extracted
CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July. Tracked as CVE-2026-45659, this security flaw stems from a deserialization of untrusted data weakness and allows attackers with low privileges to execute arbitrary code on unpatched SharePoint servers. It can also be exploited in low-complexity attacks because (as Microsoft explained in May when it released security updates for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition) "an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component." The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities Catalog (KEV) on July 1, ordering Federal Civilian Executive Branch (FCEB) agencies to secure their servers within three days. "This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise," the U.S. cybersecurity agency warned at the time. In a subsequent advisory, the cybersecurity agency also urged security teams to monitor affected servers for signs of exploitation, apply Microsoft's latest patches, verify successful installation, and shorten patching cycles. It also recommended enabling Windows Antimalware Scan Interface (AMSI integration for SharePoint web applications and using Microsoft Defender Antivirus (MDAV) detections to detect and remediate compromise. Internet security watchdog group Shadowserver currently tracks over 8,500 Microsoft SharePoint servers exposed online, with over 200 of them unpatched against the CVE-2026-45659 vulnerability. While Microsoft has yet to update the CVE-2026-45659 advisory to tag it as exploited, CISA has now also flagged it as abused by ransomware gangs in a Tuesday update to the KEV Catalog. Since November 2021, the cybersecurity agency has flagged 14 actively exploited Microsoft SharePoint vulnerabilities, with eight of them also exploited in ransomware attacks. In June, CISA also confirmed that ransomware gangs now exploit a high-severity Microsoft Defender privilege escalation vulnerability (dubbed BlueHammer), which was also targeted as a zero-day to access the Security Account Manager (SAM) database, which contains password hashes for local accounts. The security flaw (tracked CVE-2026-33825) was leaked by a security researcher known as "Nightmare Eclipse" in early April, together with proof-of-concept exploit code. However, as with CVE-2026-45659, Microsoft has yet to confirm that the CVE-2026-33825 security flaw is being exploited in the wild. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 11, 2026extracted
August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse?
August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse? July 2026 Patch Tuesday was record-setting in so many ways. The sheer volume of security patches for almost every product in the Microsoft portfolio was the highest ever and, of course, well over 600 CVEs were identified in the Security Updates Guide. Interestingly, only two CVEs were reported as exploited zero-days and only one as publicly disclosed, but we’ll get back to that later in this article. There were 405 CVEs reported against Windows 11 and Server 2025, and 337 logged for Windows 10 and its associated server versions. There were record numbers of CVEs for Microsoft SharePoint and Office, and also updates for SQL Server, Exchange Server, and .NET framework as well. Did you catch the CVEs reported for Age of Empires and Minecraft Server? Many organizations are still struggling to test and deploy all these patches, and others are asking if there may be another wave coming next week. The impact of AI on vulnerability identification is forcing IT administrators and security professionals to ask questions and drive changes in the patch management industry. Microsoft is even recommending a three-day turnaround on patching, with a two-day grace period to stay ahead of the ‘AI-accelerated’ threats as they continue to grow. As you can imagine, this sparked a debate among several industry experts. They agree the threat will continue to grow but the challenge to meet a three-day requirement is that large enterprises are constrained by testing, change control, and compatibility requirements. That challenge needs to be addressed by building a process that can deploy patches in days for the vulnerabilities that matter most and stays disciplined with everything else. Only a small fraction of disclosed vulnerabilities are ever confirmed as exploited in the wild. I mentioned in my introductory paragraph only three CVEs out of 600+ from July Patch Tuesday were known exploited or publicly disclosed, so there’s no need to focus heavily on all the other patches immediately or to treat every CVE as an emergency. Focus on triaging the CVEs and patches accordingly, assessing your systems’ exposure to the highest vulnerabilities, testing as appropriate for the systems involved, and deploying in risk priority once you’ve completed your assessment. Traditional ring deployment included deployment of almost all patches starting with a small pilot group, then to less critical company systems, and finally installation organization wide. The Patch Apocalypse requires a new approach with a more specific focus on risk: Identify the known exploited or internet facing vulnerabilities as the most critical Match those patches up with the systems in your organization that are at highest risk based on network location, data processed, business criticality, etc. Develop a quick test or an acceptance scenario to ensure the patches do not disrupt those systems. Once that is complete you can deploy this set and move on to the next set of lower priority systems. This approach is key to reducing risk in the Patch Apocalypse. There were a few important items to note from this past month as we go into the August Patch Tuesday. If you are still catching up on deploying the updates from July, you should focus on getting the SharePoint patches out. The Microsoft Security Center announced that CVE-2026-50522, a remote code execution vulnerability, is now actively being exploited. Hackers can steal machine keys using this vulnerability and maintain access after the system is patched. With these keys, a remote attacker can execute code on the SharePoint system. Speaking of hackers, the researcher, Nightmare Eclipse, is in the news again with a disclosed vulnerability being called LegacyHive. Per ACROS Security, ‘The vulnerability allows a regular non-admin user to mount any other user’s registry hive in full access mode, and then either access that user’s stored secrets or modify any values in their registry to affect what gets executed the next time they log in.’ This vulnerability in the Windows User Profile Service has been acknowledged by Microsoft and they are working on a fix. There is no CVE assigned yet, but this is one to look for in the upcoming August release. And finally, if you have edge systems with outdated secure boot certificates, Microsoft has introduced some targeting improvements in the latest Windows 11 24H2 and 25H2 preview patch. This enhancement will ‘increase coverage’ of devices eligible to receive new Secure Boot certificates and should help you out next week with the cumulative updates. There are several products reaching End of Servicing per Microsoft’s Modern Policy, meaning the continuous updates will cease and there is no extended support. Windows 11 Version 24H2 reaches End of Servicing in two months on October 13th, 2026. On November 10th, Windows 11 Version 23H2 Enterprise and Education Editions, as well as Windows 11 IoT Enterprise 23H2, will reach End of Servicing. Microsoft also announced the end of ESU support for Exchange Server 2016/2019 this October. The ESU support has been extended for a six-month period, but will not be extended again so plan accordingly per the announcement’s recommendations. August 2026 Patch Tuesday forecast Microsoft has already said the large volume CVE trend will continue as AI identifies more vulnerabilities. With that already stated, we can expect another large set of updates with many new CVEs reported. I suspect Microsoft fixed a lot of the ‘low hanging fruit’ last month so maybe the number will be back to normal highs we’ve seen in the past. We may not see the entire portfolio updated but most of the products will receive updates again. Adobe had a small set of releases on July 28th for Format Plugins, Bridge, and the on-premise Campaign Classic. It’s hard to know what AI will find and Adobe will fix, but I would consider Photoshop, InCopy, InDesign, and Acrobat Reader high on the list of possibilities since they didn’t have updates in the last month. It’s unlikely Apple will release any updates next week. The last major release was on July 27th for macOS Tahoe 26.6, macOS Sequioa 15.7.8, and macOS Sonoma 14.8.9. These releases had large numbers of reported CVEs with Tahoe having 128 unique CVEs as an example. There was a minor release on August 6th with just CVE-2026-65400, a screen sharing vulnerability, addressed in each. Applying the latest patches will take care of the major release as well since they are cumulative. Google released Chrome Desktop 151.0.7922.108 for Windows on August 6th addressing 41 CVEs. They continue to release security updates weekly, but I suspect we see fewer CVEs with a minor update next week. It’s likely we’ll see Mozilla release some minor updates for Thunderbird and Firefox next week. The last major release was July 21st for Firefox and Thunderbird 153, Firefox ESR 115.38, Firefox ESR 140.13, and Thunderbird 140.13. Welcome to the patch apocalypse! Traditional patching based on vendor severity and flat CVSS values is rapidly being overcome by events. And those events are AI-driven.
helpnetsecurity.comAug 7, 2026extracted
Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers
Microsoft announced on Monday that over the past year it has paid out more than $20 million through its bug bounty programs. Between July 1, 2025, and June 30, 2026, the company received vulnerability reports through its 15 bug bounty programs from researchers across 64 countries. Microsoft said it received 2,531 eligible reports, and 562 researchers have been awarded a total of over $20 million, with the largest single payout reaching $200,000. [ Read: Will AI Kill the Bug Bounty Industry? ] The total amount includes $2.3 million given to participants at the Zero Day Quest hacking contest. In addition, $800,000 was paid out through new initiatives, such as those targeting vulnerabilities in third-party and open source code. Microsoft noted that it saw a significant increase in submission volume during the second half of the year, which it attributed to “both strong engagement from the research community and the growing use of AI to support security research”. Microsoft paid out roughly $17 million in 2024 and 2025, and approximately $13 million every year between 2020 and 2023. While the latest numbers show that Microsoft’s bug bounty programs are increasingly successful, not all researchers are happy with the company’s handling of vulnerability reports. A researcher who uses the online moniker Chaotic Eclipse and Nightmare Eclipse has released the details of several zero-days without giving Microsoft the chance to patch them. Some of the flaws ended up being exploited in the wild. Chaotic Eclipse has voiced strong dissatisfaction with Microsoft, alleging that the company mishandled vulnerability reports, ignored communications, withheld bounty payments, deleted the researcher’s reporting account, and breached a prior agreement. Related: Google Paid Out $17 Million in Bug Bounty Rewards in 2025 Related: Apple Bug Bounty Update: Top Payout $2 Million, $35 Million Paid to Date Related: Meta Paid Out $4 Million via Bug Bounty Program in 2025
securityweek.comAug 4, 2026extracted
⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended. Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear, poisoned dependencies, weak defaults, and tooling that moved from forum chatter to real targets. The full weekly recap report follows. ⚡ Threat of the Week Anthropic Disclosed its Models Targeted 3 Organizations - Anthropic revealed that three of its models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, breached three unnamed organizations during cybersecurity testing without its knowledge. The AI firm said the earliest incidents date back to April 2026, adding it made the discoveries after launching a "large-scale retrospective review" in response to the recent Hugging Face incident. "After reviewing 141,006 evaluation runs where Claude could have obtained internet access, we identified three incidents in which a model accessed the internet from within or while interacting with the evaluation environment of Irregular, one of our third-party evaluation partners, and then gained unauthorized access to the production infrastructure of three different organizations," it said. Mythos: Map Attack Paths to Collapse Lateral Breach Routes Access the Gartner® CTEM report to see how the Mythos platform continuously maps cross-domain attack paths and isolates key choke points to break active lateral movement to critical assets. Get the full report ➝ 🔔 Top News Coldcard Hardware Wallet Flaw Linked to $88.6M Bitcoin Theft - A vulnerability in Coldcard hardware wallet firmware is said to have been exploited to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seed phrases were generated using a flawed random number generator. "Coldcard firmware contains an RNG integration error that causes ngu.random to use MicroPython's deterministic Yasmarang fallback instead of the STM32 hardware RNG," Square Engineering said. "This does not mean every remote attacker can immediately recover every seed. Practical cost depends on available UID information, boot timing, prior RNG calls, and derivation cost." Russian Hackers Exploit Microsoft OWA Flaw to Maintain Mailbox Access - Russian threat actors exploited a security flaw in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors. The activity, which began on July 22, 2026, involves the weaponization of CVE-2026-42897 (CVSS score: 8.1), a cross-site scripting (XSS) vulnerability in OWA. It was flagged by Microsoft as having been exploited in attacks as far back as May 2026. The activity has been attributed to Laundry Bear. The new wave of exploitation revolving around CVE-2026-42897 culminates with the deployment of a previously unknown JavaScript browser-based implant codenamed OWAReaper that's specifically built for persistent access within Microsoft's webmail client. Critical Rails Flaw Leads to Arbitrary File Read - Ruby on Rails shipped patches for a critical Active Storage vulnerability (CVE-2026-66066, CVSS score: 9.5) that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. The flaw can be exploited to expose Rails process environment and secrets such as secret_key_base, master key, database passwords, cloud storage credentials, and API tokens, which may enable remote code execution or lateral movement into connected systems. CVE-2026-66066 is exploitable when libvips is used, enabling an attacker to upload a specially crafted image to a vulnerable application and read arbitrary files on the server. A key prerequisite for the attack is that the server must allow image uploads from untrusted users. Additional details of the flaw have been released by the Rails team, along with tools to help assess vulnerable applications. "Because this vulnerability requires no authentication and targets the default image processor in modern Rails environments, it is essential to apply vendor patches and rotate secrets immediately," Akamai said. Coordinated Attacks Target 30+ Minnesota Water Systems - A coordinated cyber attack campaign targeted over 30 water systems in Minnesota on July 26 and 27, 2026. "The nature and extent of the impact varied by system, and the investigation is still determining how many experienced operational disruptions," Minnesota IT Services (MNIT) said. The activity has not been officially attributed to any known threat actor, although Iranian threat actors have been previously implicated in similar attacks targeting water facilities in the U.S. "At this time, there are no active requests from Minnesota communities for residents to modify their drinking water use," MNIT added. The development has prompted the U.S. government to issue an advisory, urging "critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible." Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses, resulting in boil water notices and sustained manual operations. Organizations are advised to disconnect the PLC from the internet, enable password protection and change default passwords, and allowlist IPs to only allow remote access from known engineering laptops or other critical OT assets. Censys said it identified 4,148 internet-exposed hosts that respond to EtherNet/IP and self-identify as Rockwell Automation/Allen-Bradley, with more than 70% of them located in the U.S. Similarly, there are 4,117 internet-exposed hosts that fingerprint as Siemens SIMATIC S7-1200 and 2,072 internet-exposed hosts that fingerprint as Schneider Electric hardware. Over the weekend, Michigan reported cyber attacks on nine of the state's water systems but an official told Associated Press that all systems were operating "safely." The campaign underscores the escalating threat to poorly protected operational technology (OT) assets from adversaries seeking to disrupt critical infrastructure services across the U.S. and elsewhere. Hijacked Wi-Fi Networks Lead to CornFlake Malware - Storm-2945, a sub-cluster associated with Midnight Blizzard (aka APT29), has been conducting "widespread but targeted traffic manipulation attacks" involving hospitality sector networks served by captive portals across the world. The campaign, ongoing since May 2026, has been codenamed CaptiveCrunch by Microsoft. This involves manipulating DNS and HTTP traffic from networks served by captive portals to redirect user traffic through actor-controlled infrastructure. "As part of the CaptiveCrunch campaign, Storm-2945 has leveraged their AitM position to redirect users through actor-controlled phishing infrastructure and has also delivered malware purporting to be browser or operating system updates in response to automated connectivity checks issued by users' browsers," Microsoft said. This includes a fully-featured Windows remote access trojan (RAT) called CornFlake with capabilities to conduct system enumeration, collect files and keystrokes, steal credentials and session tokens, conduct audio and video surveillance, monitor for removable media, and provide the threat actor a remote shell on infected systems. Also delivered via the trojan is a PowerShell-based infostealer called ChocoShell to harvest browser session cookies, saved passwords, Microsoft 365 Single Sign-On (SSO) tokens, and Wi-Fi credentials from compromised systems. The campaign is orchestrated via a web-based C2 panel called FruitStone. The infrastructure employs a variety of ClickFix techniques to trick the victim into downloading and executing the malware. There is also evidence indicating that the attackers are using similar ClickFix landings for Android devices to download and install an APK file. As of July 16, 2026, a portion of CaptiveCrunch landing pages have been found to redirect users to device code authentication flow experiences. ️🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first - CVE-2026-48449 (Adobe Campaign Classic), CVE-2026-18556, CVE-2026-18577 (N-able N-central), CVE-2026-44827, CVE-2026-45804, CVE-2026-44513 (Hugging Face Diffusers), CVE-2026-17583 (Thermo Fisher Scientific), CVE-2026-66066 (Rails), CVE-2026-10702 (Mozilla Firefox), CVE-2026-60004, CVE-2026-58443 (Gitea), CVE-2026-63077, CVE-2026-59792, CVE-2026-59793, CVE-2026-59794, CVE-2026-59795, CVE-2026-59796 (JetBrains TeamCity), CVE-2026-61511 (vBulletin), CVE-2026-53264 (Linux Kernel), CVE-2026-53921 (OpenWrt), CVE-2026-64765, CVE-2026-64766, CVE-2026-64764, CVE-2026-64763, CVE-2026-43776, CVE-2026-43818, CVE-2026-28981 (Apple iOS and macOS), CVE-2026-66032, CVE-2026-66033, CVE-2026-66034, CVE-2026-66035 (libssh2), from CVE-2026-59686 through CVE-2026-59690 (Progress Kemp LoadMaster), from CVE-2026-66036 through CVE-2026-66041 (FFmpeg), CVE-2026-66398 (phpMyFAQ), CVE-2026-64645, CVE-2026-64649, CVE-2026-64642, CVE-2026-64641 (Next.js), CVE-2026-13385 (ASUS), from CVE-2026-16804 through CVE-2026-16807 (Google Chrome), CVE-2026-52824 (Kimai), CVE-2026-53565, CVE-2026-53566 (Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows), CVE-2026-9770, CVE-2026-13230 (TP-Link Kasa EC70 v4 and EC71 v4 smart cameras), CVE-2026-15682 (AnyDesk), CVE-2026-53481, CVE-2026-53483 (Dell PowerProtect Data Domain), CVE-2026-52886, CVE-2026-54758, CVE-2026-57233 (Notepad++), CVE-2026-57807 (miniOrange OAuth Single Sign On - SSO WordPress plugin), CVE-2026-28302, from CVE-2026-28304 through CVE-2026-28317, CVE-2026-28321 (SolarWinds Serv-U), CVE-2026-16771 (AT&T Arris BGW210-700), CVE-2026-13723 (Develar), CVE-2026-16637 (OPeNDAP Hyrax), CVE-2026-15969, CVE-2026-15971, CVE-2026-15974, CVE-2026-15976, CVE-2026-15977, CVE-2026-15978 (SGLang), CVE-2026-15657, CVE-2026-15658 (foreUP), CVE-2026-16503, CVE-2026-16504 (VPS.org), CVE-2026-48395, CVE-2026-48396 (Adobe Bridge), CVE-2026-5674 (PipeWire PulseAudio), CVE-2026-34909 (Ubiquiti UniFi OS), and CVE-2026-17059 (keycloak-services). 🎥 Cybersecurity Webinars AI Can Build Exploits in Minutes. Can Your Security Team Keep Up? → AI is collapsing the time between vulnerability disclosure and attack. Advanced models can now uncover flaws, generate working exploits, and chain them into complete attack paths at machine speed. This webinar presents a practical framework for gaining the visibility, context, and response speed needed to investigate and stop threats before attackers pull ahead. How to Control the Open-Source Security Debt Created by AI Coding Tools → Learn how AI coding tools are expanding unvetted open-source use, accelerating vulnerability backlogs, and weakening existing governance. This webinar shows how to measure the resulting remediation debt, connect it to breach, audit, and productivity risks, and identify which governance models can contain it without slowing development. 📰 Around the Cyber World Now-Patched Gitea Flaw Detailed - NoScope shared additional technical details of a security flaw in Gitea (CVE-2026-27771, CVSS score: 8.2) that was patched back in May 2026. The vulnerability allowed unauthenticated remote attackers to pull private container images from Gitea deployments without requiring an account, password, or other credentials. "Gitea's container registry implements the OCI Distribution Specification, which authenticates clients with a bearer token issued by a dedicated token service. On affected versions, that token service issued a valid, signed JWT to requesters presenting no credentials at all," NoScope said. "The token was honest about what it represented, carrying UserID: -1 and an empty Scope, but no registry read endpoint ever consulted those fields. Catalog listing, tag enumeration, manifest retrieval and blob download all accepted it. Any unauthenticated party on the internet could enumerate every container repository on an instance, including those marked private, and pull their layers." SQLite Critical CVEs or AI Slop? - JFrog said it uncovered a set of SQLite CVEs (CVE-2026-51302, CVE-2026-51303, CVE-2026-51300, CVE-2026-51297, CVE-2026-51296, and CVE-2026-51304) that seem to be instances of AI-generated slop making their way into official vulnerability feeds and receiving critical severity scores before technical validation. The analysis found that the advisories referenced functions that didn't exist in the affected SQLite versions, cited incorrect or impossible source code locations, included PoCs that failed to reproduce any vulnerability, and, most importantly, were not listed on SQLite's official CVE page. The findings show that organizations must take steps to distinguish legitimate vulnerabilities from questionable or AI-generated vulnerability reports before initiating unnecessary remediation, patching efforts, or automated security workflows. LegacyHive Flaw Detailed - LevelBlue published a technical breakdown of LegacyHive, a PoC released by Chaotic Eclipse (aka Nightmare-Eclipse) last month coinciding with the release of Microsoft's Patch Tuesday update. The vulnerability is a Local Privilege Escalation (LPE) vulnerability affecting Windows User Profile, a component responsible for loading and unloading Windows user profiles. On exploitation, LegacyHive can allow attackers to load other users' hives and gain access to application data and Windows Explorer history, among others. "For EDR platforms with visibility into native Windows APIs, the strongest signals are user-mode invocations of NtCreateDirectoryObjectEx and NtCreateSymbolicLinkObject," LevelBlue said. "These functions are rarely used outside system components, debugging tools, or specialized research utilities. Seeing both from the same process should immediately warrant investigation. Even without NT API telemetry, LegacyHive leaves a distinctive execution chain. The attack combines offline access to ntuser.dat or UsrClass.dat, modification of registry hives through Microsoft's Offline Registry API, batch oplock requests, and CreateProcessWithLogonW using LOGON_WITH_PROFILE. Each operation is legitimate in isolation but observing them together within a short time window is highly unusual and well suited for behavioral correlation by EDR and SIEM platforms." Chinese Military Taps Into U.S. Models - According to a new report from Reuters, Chinese military researchers have distilled cutting-edge models developed by U.S. companies OpenAI and Anthropic to train domestic AI systems to advance the country's defense capabilities. The report was based on a review of more than 80 Chinese academic papers and patents. Exposed Police Dashboard Lays Bare How China Tracks Foreigners - An internet-exposed police dashboard named "Dynamic Control Platform for Overseas Personnel" has revealed how law enforcement agencies in the country track over 700 foreigners, including those in the northern Chinese city of Zhangjiakou. "In total, it had entries for nearly 12,000 people, which included fugitives, people from Hong Kong and Taiwan, as well as more than 300 foreign journalists," The New York Times reported. "Some of them had not been to Zhangjiakou." The dashboard displayed entries about people grouped by nationality, with their birth date, sex, marital status, address and occupation, and sometimes their religion. The leak was discovered by security researcher and journalist Marc Hofer. The system is believed to be developed by a Beijing company named Origin Dynamic, which filed a patent application in 2023 for a similar "information interface for non-Chinese citizens." The Problem of DangleGeddon - Cybersecurity researchers have once again warned of the risks posed by dangling DNS infrastructure across government, banking, automotive, manufacturing, and pharmaceutical sectors. A dangling DNS record is an active Domain Name System entry (DNS) that points to a resource no longer owned, used, or controlled by the original organization. This typically occurs when web applications, cloud storage, or virtual servers are deleted without first removing their corresponding CNAME or A records from the domain registrar. An attacker can leverage this behavior to claim that abandoned cloud service name or IP address, effectively hijacking a trusted subdomain. This, in turn, can permit the attacker to host malicious content and serve phishing pages or malware, inflict reputational damage by abusing the trusted brand's subdomain, steal user credentials to create convincing phishing pages that appear to be legitimate services, perform cookie theft, and bypass security controls if the legitimate brand's subdomain is allowlisted in security tools. In one case analyzed by Silent Push, an unspecified automotive company left a dangling DNS record pointing to a developmental application gateway hosted by an Azure virtual machine (VM). "This device can potentially be operationalized and passively receive stored XSS from internal scripts and API calls," it said. "Developers' credentials, like API keys and authentication headers, could be harvested for reuse to expand access into the company. In addition, the VM could serve as a platform for malware hosting with the coveted TLS lock." Microsoft Teams Vishing Leads to Chaos Ransomware - A Microsoft Teams voice phishing (vishing) campaign tracked as STAC4749 has used a "consistent set of IT-themed cloud domains and personas to gain remote access to victims' systems" between February and June 2026 in attacks targeting dozens of North American organizations. "Following initial access, STAC4749 operators deployed a modular post-exploitation toolset, including a custom loader and backdoor to maintain persistent, controlled access and support follow-on activity," Sophos said. "In several incidents, attackers later leveraged this access to deploy Chaos ransomware." IAB Uses Teams Phishing for Ransomware Attacks - A suspected initial access broker (IAB) for ransomware attacks has been observed using Teams vishing that convinces victims to launch a Quick Assist remote support session. The initial access is used to run PowerShell scripts to gather host information and deploy a Go-based backdoor dubbed GoGRPC. Four different versions of the backdoor have been spotted: Lep, Giver, Pet, and Kind. "These variants have overlapping capabilities but notable implementation differences," Zscaler said. "GoGRPC is actively evolving. Each variant modifies its payloads and capabilities, adding or removing functionality to better support the threat actor's objectives. Recent changes indicate an increased targeting of corporate environments, which may be tied to ransomware attacks." In some instances, the threat actor has also deployed a backdoor called BlindDoor, a Go-based reverse SOCKS proxy known as RevSocket, and a Python-based reverse SOCKS proxy referred to as PyGRPC. Arch Linux Disables AUR Package Adoption Amid Malware - Arch Linux has taken the step of temporarily disabling package adoption due to a surge in malicious takeovers of existing packages. "Due to the current influx of malicious package adoptions and follow-up commits made via the AUR, package adoption is currently disabled while we are handling the situation," the maintainers said. "We will send a follow-up once we're able to. In the meantime, feel free to report suspicious adoption events or commits that haven't been dealt with yet, and stay vigilant!" In June 2026, a separate campaign targeted AUR via more than 400 packages. New Dolphin X Infostealer Spotted - A new infostealer called Dolphin X uses an AI behavioral profiler to score and prioritize infected users based on their application usage, browsing activity, and installed software to identify high-value victims and maximize profits. The malware targets more than 300 applications and attempts to exfiltrate browser passwords, cryptocurrency wallets, SSH keys, and cloud tokens. Dolphin X has been advertised on the cybercrime underground by a vendor using the alias Kontraktnik since May 2026. A lifetime subscription ranges from $1,140 for basic access to $3,420 for the full-featured version. "A single archive can contain data from nine browsers, more than 100 wallet extensions, 65 desktop wallets, 10 password managers, and 30 cloud command-line tools," Varonis said. "This gives the malware potential access to everything from a victim's personal accounts to the credentials used to manage their employer's cloud environment." Attackers Turn to Microsoft's Trusted Login System for Phishing - Bad actors are increasingly abandoning fake Microsoft login pages in favor of abusing Microsoft's legitimate authentication infrastructure in phishing attacks, allowing them to bypass security controls. Check Point said it identified more than 200 phishing emails targeting users across approximately 120 organizations worldwide between June 25 and the second week of July 2026. "The messages impersonated Microsoft Teams task notifications from HR and directed recipients to a legitimate Microsoft sign-in page," it said. "Victims were then prompted to grant permissions to an attacker-controlled application, allowing the campaign to abuse Microsoft's trusted authentication flow while concealing its malicious intent." FBI Arrests Man Accused of Using Steam Games to Drain Victims' Crypto Wallets - The U.S. Federal Bureau of Investigation (FBI) arrested Zyaire Wilkins, a 21-year-old Florida resident and student, of uploading fake video games that contained malware to Steam that, when downloaded and installed by unsuspecting gamers, stole their passwords and other valuable data, and drained their cryptocurrency wallets. Per the FBI, Wilkins and his accomplices are alleged to have infected around 8,000 victims, and then hacked around 80 cryptocurrency wallets to steal at least $220,000 worth of cryptocurrency. Turning Keystroke Noise to Text - A new study from a group of academics from Tohoku University has demonstrated a new acoustic side-channel attack that can reconstruct text typed on a laptop by just analyzing the sound of keystrokes. While prior attacks relied on collecting labeled recordings from the target keyboard beforehand or required specialized hardware, the latest eavesdropping attack enables stealthy eavesdropping in two real-world scenarios, including physical spaces (public and semi-public) and online meetings. The system works by first isolating individual keystrokes from an audio recording, grouping similar sounds together, and then using a Transformer-based language model to determine the most likely sequence of characters. "Our method combines unsupervised acoustic clustering with Transformer-based language model inference and iterative self-training, enabling stable character inference under highly uncertain acoustic-to-character mappings," the researchers said. "We demonstrate that the proposed method achieves over 99% reconstruction accuracy with only 100-150 observed keystrokes under a close-proximity recording setup using a smartphone placed near the target device, significantly outperforming prior unsupervised baselines in low-data regimes." Two Open-Source Software Supply Chain Attack Campaigns - Socket has flagged a fake corepack.org site that's impersonating Corepack, a Node.js tool for managing package managers, and using it as a lure to deliver an infostealer and proxyware to developers who download it. "The site has existed in some form since early 2026 as a low-quality, apparently AI-generated imitation, but it recently started serving executable downloads," Socket said. "Corepack is not distributed as a Windows installer, and the real project has no official website at corepack.org. Any download offered there should be treated as malicious." It's assessed that the site is AI-generated. In a related development, JFrog identified a massive set of 148 npm packages that are disguised as student web proxies, but hide mutable remote code execution vectors and a high-performance Wisp-compatible WebSocket traffic generator. "They were designed to silently enlist visiting browsers into distributed denial-of-service botnets while generating aggressive popunder advertising revenue," it said. Some aspects of the campaign were highlighted by SafeDep in late May 2026. AI linked to more than half of cybercrime in Africa - A new report from INTERPOL has found that AI is enabling 55% of reported cybercrimes across Africa, making attacks faster, more scalable, and increasingly difficult for victims and platforms to detect. This encompasses digital sextortion and online harassment, as well as sophisticated business email compromise (BEC) schemes. "The absence of real-time, inter-agency data sharing between banks, telecoms and law enforcement creates a dangerous blind spot in efforts to combat financial fraud," INTERPOL said. "This vulnerability is being exploited by criminals who have moved beyond simply stealing existing credentials to creating entirely synthetic identities. Combining real personal data with fabricated elements, these AI-generated digital personas can bypass even advanced biometric verification systems and have been used to open bank accounts, secure mobile loans and register SIM cards under false names." Security Risks of Exposed MCP Servers - Google-owned Wiz has warned that enterprises are exposing Model Context Protocol (MCP) servers to the internet, with some of them returning full tool catalog to an anonymous caller, fetching real data, and revealing a sensitive backend. "These expose sensitive data like employee PII and internal business records, write and delete operations on production systems, and in some cases code execution and access to cloud credentials," Wiz said. "The protocol's first widely-used version shipped without an authentication mechanism. The spec added OAuth 2.1 in March 2025, but nearly all the servers we found still run the original version and don't use it. The pattern is the same across most of them: backend credentials baked into the deployment, a managed cloud endpoint that's internet-reachable by default, no auth layer added on top." Nuclear-Sabotage Malware Benchmark Trick Most Frontier AI Models - A multi-stage reverse-engineering benchmark developed by SentinelOne tests "whether a model can keep a malware investigation trustworthy as new evidence repeatedly invalidates its earlier conclusions," in contrast to other AI benchmarks that test bounded tasks. Developed based on its own analysis of the Fast16 malware, the study found that "OpenAI's GPT-5.6 Sol was the only publicly available model to complete the full eight-stage investigation, giving concrete shape to what 'Frontier-class' capabilities offer analysts." That said, humans remain essential to define objectives, expose blind spots, and retain final publication authority. An Open Directory Reveals NGINX Rift and Ghost CMS Exploits - An exposed directory on a Singapore-hosted VPS, 165.154.236[.]93, has been found to stage exploits for NGINX Rift (CVE-2026-42945), a long-standing heap overflow, and a blind SQL injection in the Ghost Content API (CVE-2026-26980), alongside Splunk, PaperCut, Samba, WebLogic, and D-Link NAS tooling. "The recovered shell history from the directory recorded the attacker running the exploits against live external infrastructure, using out-of-band (OOB) DNS callbacks to verify execution, and using the same server to catch reverse shells," Hunt.io said. "Alongside the web exploits were a broader RCE toolkit and pre-staged install files for AdaptixC2 and SuperShell. The target list spanned eleven countries across five continents and leaned heavily toward high-value sectors: federal and state government, universities, healthcare and financial services." The activity is believed to be the work of a Chinese-speaking threat actor. CISA Issues Guidance to Isolate Vital Systems and Manage OSS Risks - The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued guidance to help critical infrastructure operators protect essential services from growing cyber threats and ensure continuity of operations during cyber incidents or geopolitical crises by maintaining robust isolation and recovery plans. "State-sponsored cyber actors target critical infrastructure for several nefarious reasons such as espionage or service disruption, often linked to broader geopolitical conflicts," CISA said. "During crises or conflicts, operators of critical infrastructure and network defenders may isolate essential operational technology (OT) systems as an emergency measure to prevent adversaries from executing cyberattacks, to contain ongoing threats, and to facilitate the restoration of compromised systems." The agency has also outlined considerations and best practices for federal entities to securely use, evaluate, and publish open-source software. "The guidance urges agencies to obtain sufficient transparency into all relevant components, including training data, of the AI system before deeming the product as OSS for risk management purposes," it said. "Only with transparency and access can agencies understand and study the software, analyze it for vulnerabilities, and remediate any found vulnerabilities or risks." RubyGems Cryptojacking Campaign - A set of 199 malicious gems published to RubyGems has been found to embed an identical XMRig cryptojacking payload to mine Monero cryptocurrency on developer systems. "Each gem is a trojanized copy of a popular, legitimate Ruby library," Palo Alto Networks Unit 42 said. "The payload uses a 5-hour delayed Thread.new{sleep 18000; ...} trigger to evade sandbox analysis." In addition to taking steps to achieve persistence via multiple methods, the malware uses SSH for lateral movement and is capable of infecting other ecosystems, including Node.js, Python, Docker, Git, and VS Code extensions. Mend.io, which also shared details of the campaign, said the payload is hidden inside a dotfile (lib/.threadpool.rb) that standard directory scans skip by default. Email Threat Landscape in Q2 2026 - Microsoft said phishing volume linked to the Tycoon 2FA phishing platform, including QR code phishing and CAPTCHA-gated phishing, fell 92% from pre-disruption averages in the second quarter of 2026 between April and June. However, the tech giant said it "observed continued growth in Teams-based social engineering, particularly voice phishing (vishing), with weekly malicious call attempts reaching nearly ten times the mid-2025 baseline by the end of the quarter." Microsoft said it detected approximately 7.6 billion email-based phishing threats throughout the quarter, with monthly volumes declining modestly from 2.7 billion in April to 2.4 billion in June. HTML and PDF attachments remained the two most common malicious payload types across the quarter, together accounting for roughly 60-70% of all payload-based attacks each month. In early June 2026, Microsoft said it detected a large-scale BEC campaign that reached more than 67,000 users across more than 42,000 organizations in under three hours, most of them in the U.S., with an aim to redirect salary payments to attacker-controlled bank accounts. 🔧 Cybersecurity Tools EMBA → Firmware is where critical bugs hide longest because it is opaque, fragmented, and painful to inspect manually. EMBA turns that black box into an actionable security report: it extracts embedded-device firmware, runs static and emulation-based analysis, builds an SBOM, and flags outdated components, insecure binaries, vulnerable scripts, and hard-coded credentials through a command-line workflow with web-based reporting. Built for penetration testers, product-security teams, and developers, it compresses days of firmware triage into a repeatable open-source process. GrantGuard → Every "always allow" click in Claude Code can leave behind a standing permission that remains long after the task ends, with pasted API keys, credential-store access, unrestricted git push, or destructive commands buried in rarely reviewed settings. GrantGuard is an open-source, local-only tool that finds these accumulated grants, classifies them by risk, and lets users remove unsafe permissions through a browser interface or CLI, without sending settings off-device or loading third-party runtime packages. Disclaimer: This is strictly for research and learning. It hasn't been through a formal security audit, so don't just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you're doing stays on the right side of the law. Conclusion The useful question is not whether a system is exposed. It is which quiet assumption lets it reach farther than intended: a default, a trusted workflow, an abandoned endpoint, or code nobody checked. That is where the next incident is probably waiting. Not in the loudest alert, but in the handoff everyone assumes belongs to someone else. Check the boundaries. Then check what crosses them.
thehackernews.comAug 3, 2026extracted
The automotive software vulnerabilities hiding in your dashboard
The automotive software vulnerabilities hiding in your dashboard Pop the hood on a new car and you won’t find much you can fix with a wrench. What you’ll find is software, and a lot of it. The screen in the dash probably runs Android or a flavor of Linux. The system watching the road for you might run QNX or VxWorks, the same kind of code that flies aircraft and runs factory floors. Carmakers spent the last decade making this switch, and it bought them app stores, wireless updates, and quicker release cycles. It also handed them something less welcome: every old, publicly documented bug those platforms have collected over the years. Researchers at Télécom SudParis decided to count that baggage. They built a scanner called VERA, aimed it at the operating systems inside current cars, and tallied up the known flaws. The pile is big. It’s also messier than the raw numbers make it look, which turns out to be the more interesting part of the story. What’s running in your car? First, the researchers worked out who runs what, which is harder than it sounds because carmakers treat this stuff as a trade secret. A 2023 BMW dashboard runs a Qualcomm chip loaded with Automotive Grade Linux and Android. GM and Cadillac are moving to Red Hat’s in-vehicle OS for their 2026 models. Tesla has quietly run Linux for years. Line it all up and the fleet starts to look like a rolling collection of general-purpose computers, plugged into cellular, Wi-Fi, Bluetooth, and the car’s own internal wiring. Then they scanned it. The counts landed all over the map. Automotive Grade Linux topped the chart with 1,203 documented flaws in the version they tested. Android wasn’t far off. A leaner, safety-focused stack called Eclipse S-CORE came in with a grand total of eight. Part of that gap is just how much extra software each platform ships. Part of it is attention: popular open platforms get poked at by more researchers, so more of their flaws end up on the books. Getting looked at is its own kind of exposure. Certified doesn’t mean bulletproof You might expect the safety-certified systems to come out clean. They don’t. QNX Neutrino carries a respected security certification, and the tested build still logged 56 known vulnerabilities. VxWorks 7 sits at an even higher certification tier and landed in the low dozens. Certification does real work here. It shrinks the attack surface and forces discipline into how the code gets built. What it can’t do is stop the mountain of surrounding software from sprouting new bugs that somebody has to patch. A big number is a to-do list, not a verdict This is where the study gets honest with itself, and where a lot of scary headlines fall apart. A logged vulnerability is a maybe. It’s a weakness that could matter under the right conditions, if the vulnerable code is even switched on, if the attacker can reach it, if the setup happens to line up. A thousand flaws means a thousand things a defender has to keep an eye on. It doesn’t mean a thousand ways into the car. To show the difference, the team built two working attacks. One went after a bug in SQLite, a database engine buried inside all sorts of apps, running on Android Automotive. The other targeted a service discovery protocol called SOME/IP, and this one tells the whole story in miniature. They ran the same attack against three platforms. It worked on Red Hat’s AutoSD and on Tesla’s software, letting them knock a service offline. It flopped on Android Automotive, which the researchers figure was down to the platform shuffling its port numbers around. One bug, three systems, two very different afternoons. Same severity score on paper, and the outcome came down to what defenses were actually turned on. All of this ran inside Docker containers on a lab bench, picked because they’re easy to reproduce. That setup nails the filesystem, the installed packages, the config. It skips the vendor’s custom kernel, the firmware quirks, the hardware protections. The numbers describe what’s sitting in the software image. They stop short of what happens in a car parked in your driveway. The scanners have a car problem There’s a working-stiff angle here too. The everyday scanners security folks reach for assume a tidy system with a clean inventory of parts. Cars don’t play along. Trivy, one of the popular ones, coughed up more than a thousand false alarms on a single robotics image and barely anything useful on others. VERA sits on top of the existing tools and filters for the automotive reality, tossing out flaws in command-line utilities and developer tools that a locked-down car would never expose in the first place. What you get back is shorter and sharper, a list somebody can actually work through instead of drown in. So, here’s what to walk away with. The code in your car now shares a family tree, and a rap sheet, with the rest of the computing world. The length of that rap sheet tells you how much there is to watch. The real job is sorting out which of those old bugs your particular car will ever let anyone near. Download: The ultimate guide to network operations management
helpnetsecurity.comJul 24, 2026extracted
NCSC-2026-0256 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Communications
Oracle heeft kwetsbaarheden verholpen in Communications producten en onderliggende third party software. Het betreft een totaal van 213 kwetsbaarheden, waarvan 67 zich bevinden in Oracle producten en 146 in third-party producten waar eerder updates voor zijn verschenen en welke in deze Oracle updates zijn verwerkt. De ernstigste kwetsbaarheden, 12 stuks, hebben een CVSS score van 9 en hoger gekregen en zijn hieronder omschreven. 11 hiervan bevinden zich in embedded third-party producten. De overige kwetsbaarheden hebben lagere scores gekregen en het voert te ver om detailinformatie op te nemen in deze advisory. Hiervoor verwijst het NCSC naar de bijgevoegde referentie. Oracle Communications Converged Application Server versies 8.2 en 8.3 bevatten een kwetsbaarheid die onbevoegde netwerktoegang mogelijk maakt en kan leiden tot volledige overname van het systeem. Libtiff tot versie 4.7.0 bevat een write-what-where kwetsbaarheid en een stack-based buffer overflow die kunnen worden geactiveerd door speciaal vervaardigde TIFF-bestanden, wat kan leiden tot code-executie of crashes. Apache Tomcat versies 8.5.0 tot 11.0.5 bevatten kwetsbaarheden waardoor speciaal opgemaakte HTTP-verzoeken rewrite rules en security constraints kunnen omzeilen, met mogelijke data disclosure, wijziging of denial of service als gevolg. Eclipse Jetty's HTTP/1.1 parser verwerkt chunked transfer encoding extensies met onjuist gesloten aanhalingstekens verkeerd, wat request smuggling mogelijk maakt en kan leiden tot cache poisoning, access control bypass en sessie kaping. Perl versies met een verouderde vendored zlib in Compress::Raw::Zlib bevatten meerdere beveiligingsproblemen die zijn opgelost in een specifieke commit. Lodash versies tot 4.17.23 bevatten meerdere kwetsbaarheden waaronder code-injectie via onbetrouwbare keys in _.template, prototype pollution, regex denial of service en command injection. Apache HTTP Server versies 2.4.0 tot 2.4.67 bevatten diverse kwetsbaarheden in meerdere modules die kunnen leiden tot server crashes, code-executie, cross-site scripting en informatielekken. Apache Kafka versies 4.1.0 en 4.1.1 hebben een kwetsbaarheid in de JWT token validatie waardoor onbevoegde toegang mogelijk is. AIOHTTP versies voor 3.13.4 accepteren null bytes en control characters in HTTP headers, wat header injectie en response splitting mogelijk maakt. De cryptography package van versies 45.0.0 tot 46.0.7 bevat een buffer overflow bij het verwerken van niet-contigu buffers op Python 3.11+, wat kan leiden tot crashes of informatielekken. Spring Boot versies 4.0.0 tot 4.0.5 bevatten een kwetsbaarheid die het mogelijk maakt om de standaard web security te omzeilen. Apache MINA versies 2.1.X en 2.2.X bevatten meerdere deserialisatie kwetsbaarheden die code-executie mogelijk maken door bypass van classname allowlist en filters.
advisories.ncsc.nlJul 22, 2026extracted
Loading 40 more…