Two Windows Zero-Days Give Local Attackers SYSTEM Privileges
The flaws require a local foothold, affect different Windows release families, and leave defenders with fixed-build checks but no CVE-specific compromise indicators.
Read article →Reader view
Choose the default article length.
Threat actors, malware campaigns, phishing, exploitation, and incident activity.
The flaws require a local foothold, affect different Windows release families, and leave defenders with fixed-build checks but no CVE-specific compromise indicators.
Read article →Attackers made Coder's trusted registry serve malicious Terraform modules. Operators have a 14-hour exposure window, concrete indicators, and urgent credential work.
Read article →Google observed attackers move from cloud compromise to agent-enabled mass credential harvesting in under six hours, shrinking the time defenders have to respond.
Read article →Recovered JSCeal code replays stolen cookies and passwords through a headless browser to obtain fresh Google OAuth tokens and exposes concrete Windows hunt artifacts.
Read article →A public Telerik UI exploit chains two cryptographic oracles to unsafe type loading. Upgrade ASP.NET AJAX to 2026.2.708 and check IIS for post-exploit activity.
Read article →Every on-premises build before 2026.3.1.14 needs Hotfix 4. N-able's records conflict on exploitation, so MSPs should patch and review RMM activity.
Read article →Ten malicious OpenAPI React Query Codegen releases ran on install and carried credential-stealing code with valid provenance. Teams must scope lockfiles, rebuild hosts and rotate credentials.
Read article →Forescout ported a pre-auth PLC exploit with Claude, then bricked the device during an implant attempt. Restrict FTP and monitor crashes and outbound traffic.
Read article →Two factory firmware implants expose white-label ZBT routers through an open WAN service and an unauthenticated phone-home channel.
Read article →StyleSmuggler turns poisoned Magento logs into server-side code execution, then hides a persistent implant outside the shop's webroot. Adobe has not issued a fix.
Read article →Unit 42 traced an AI-assisted ransom intrusion across web, repository, secrets, CI/CD and cloud systems in less than 10 hours. These behaviors can reveal the loop.
Read article →Recovered tooling shows how forged WebDAV requests exposed nuclear records and credentials, with specific version, request-pattern, and signing-key checks for defenders.
Read article →Five exposed SecFlow workspaces linked Claude, Qwen and DeepSeek to Asian government and education intrusions involving credential theft, webshells, and implants.
Read article →