-
A ClickFix prompt can end in a remote-access foothold. CNCMachineRMS, an undocumented x64 RAT deployed at the end of a BabaDeda loader chain that turns a user-driven execution event into persistent hands-on-keyboard access. Rather than behaving like a …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical vulnerability in Docker, tracked as CVE-2026-17106 and referred to as “CopyEscape,” allows malicious containers to overwrite files on the host system using the widely utilized `docker cp` command. This flaw can lead to code execution as the …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The March 2026 compromise of LiteLLM was more than a short-lived malicious PyPI upload. It demonstrated how an upstream breach in developer tooling can turn AI infrastructure into a high-value conduit for credential theft, cloud intrusion, and downstre…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researchers Alejandro Hernando, also known as 0xedh, and Borja Martínez have unveiled a research project titled “Plug & Pwn.” This project demonstrates how the Windows Plug and Play (PnP) driver installation workflows can be ex…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researchers have discovered 23 vulnerabilities in Copeland’s XWEB Pro commercial refrigeration controllers, with 21 rated as high severity. These vulnerabilities could allow unauthenticated attackers to gain root-level remote code execution an…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Mozilla has rotated a GPG signing subkey used to authenticate release artifacts for Firefox and Thunderbird after an unencrypted copy of the previous subkey was unintentionally committed to a private GitHub repository. The affected signing infrastructu…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical privilege-escalation vulnerability in SUSE Rancher could allow a low-privilege, authenticated user to gain administrative control of the Rancher management plane and every downstream Kubernetes cluster it manages. This issue is tracked as CV…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An active ErrTraffic malware-as-a-service campaign that combines compromised WordPress sites, ClickFix lures, Polygon blockchain smart contracts and rapidly rotating payload domains to distribute a broad set of Windows malware. ErrTraffic is marketed a…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researchers have disclosed “GhostJacking,” a new class of attacks that exploits trusted observability and security platforms to manipulate AI agents into making unauthorized infrastructure changes, executing attacker-controlled commands, and e…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in SonicWall SMA1000 to its Known Exploited Vulnerabilities catalog, noting that the flaw has been used in ransomware campaigns. This vulnerability, tra…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


