-
Security researcher Nightmare-Eclipse, also known as Chaotic Eclipse, has released a new Windows privilege escalation exploit named ShieldBreak. This exploit claims to bypass Microsoft’s July 2026 fix for the RoguePlanet Windows Defender vulnerability,…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat researchers have identified an active campaign exploiting the critical VMware vCenter vulnerability CVE-2026-59310, with 361 victim IP addresses observed across 47 countries. This campaign reportedly began within days of the public disclosure an…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified a critical SQL injection vulnerability in Metabase, adding it to its Known Exploited Vulnerabilities (KEV) Catalog. This flaw allows unauthenticated remote attackers to gai…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A Chrome Web Store operation that turns “free VPN” extensions into browser-wide traffic relays controlled by a single proxy provider. The campaign comprises 737 extensions published by at least 40 developer accounts, with 274 masquerading as 66 recogni…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Google Chrome has implemented enhanced defenses aimed at disrupting abusive web push notifications that are often used to distribute malware, phishing attempts, fraudulent payment requests, and scam content. This initiative combines browser-based permi…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Corporate network access is becoming both cheaper to obtain at scale and vastly more valuable at the top end of the criminal market. That contradiction defines the identity threat economy entering 2026: billions of stolen credentials have made basic lo…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Google has released Chrome version 151.0.7922.137/138 for Windows and macOS, and version 151.0.7922.137 for Linux. This update addresses five high-severity security vulnerabilities, all use-after-free (UAF), that affect various Chrome components, inclu…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly disclosed vulnerability in Microsoft SharePoint Server, tracked as CVE-2026-63520, could allow attackers to execute arbitrary code remotely on affected systems. This flaw has a severity rating of 8.1 out of 10 according to CVSS v3.1. It affects…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A counterfeit installer for the widely used PC-cleaning utility CCleaner is being used to compromise Windows systems and deploy a malicious Chrome extension dubbed GhostDesk. CCleaner’s global popularity, with more than two billion downloads, gives att…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly identified Android malware family, tracked as WindRelay, is being used alongside the SpyNote remote-access trojan to convert victims’ phones into rogue contactless-card readers and enable real-time, card-present fraud. Group-IB’s investigation …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


