-
A new shellcode loader, dubbed “TriBack Loader,” to a China-nexus intrusion cluster tracked as JadeProx, with the malware explicitly engineered to evade modern EDR by abusing signed binaries and uncommon Win32 callback APIs. Across at least four observ…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Critical security vulnerabilities in FreePBX have been disclosed, exposing organizations to risks of unauthenticated remote code execution and the takeover of administrator accounts. These flaws, tracked under GitHub advisories GHSA-37j8-fhxx-9vhp and …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical heap buffer overflow vulnerability in FreeRDP’s Windows client could allow a malicious Remote Desktop Protocol (RDP) server to corrupt memory and potentially execute arbitrary code on a connecting client. This flaw specifically affects the C…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Hackers are abusing compromised GitHub repositories and GitHub Actions workflows to build a de facto global botnet that scans and exploits web hosting servers, with a primary focus on cPanel and WHM deployments. The campaign first surfaced when malicio…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A high-severity directory traversal vulnerability has been discovered in the Exim mail transfer agent. This flaw allows local attackers to access files outside the intended mail spool directory and potentially escalate their privileges. It is tracked a…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A new Windows-focused infostealer and remote access trojan (RAT) dubbed Dolphin X is being advertised on cybercrime forums with a clear pitch: automate the theft and triage of high-value corporate targets. Unlike commodity stealers that focus mainly on…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical authentication bypass vulnerability affecting Check Point SmartConsole has been actively exploited in the wild, allowing attackers to gain unauthorized access to security management systems under specific configurations. The flaw, tracked as…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A recently disclosed vulnerability in Ubuntu’s snap ecosystem, identified as CVE-2026-8933, presents a critical local privilege escalation flaw. This vulnerability allows unprivileged users to execute arbitrary code with root privileges. Qualys d…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Microsoft has introduced prompt injection protection in Defender for Office 365, representing a significant advancement in securing enterprise email environments against emerging AI-targeted threats. As organizations increasingly adopt AI assistants li…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical Bluetooth vulnerability in dealer-installed KARR Security Systems is putting over 2 million vehicles at risk of unauthorized access and immobilization. This situation has prompted urgent calls for drivers to update affected devices. Research…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


