top of page
ALL POSTS
Chrome V8 Zero-Day CVE-2026-11645 Being Exploited in the Wild - Apply Patch Immediately
Key Findings Google released security updates addressing 74 vulnerabilities, including CVE-2026-11645, a high-severity zero-day actively exploited in the wild CVE-2026-11645 is an out-of-bounds memory access flaw in V8 with a CVSS score of 8.8 that allows remote code execution via crafted HTML pages This is the fifth actively exploited Chrome zero-day in 2026, following CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, and CVE-2026-5281 CISA added CVE-2026-42271, a command injecti
Jun 93 min read
Critical One-Character Linux Kernel Vulnerability Enables Local Root Access with Public Exploits Available
Key Findings A single inverted character in Linux kernel nf_tables code allows unprivileged local users to escalate to root via use-after-free vulnerability CVE-2026-23111 Upstream patch released February 5, 2026; working exploits published April 16 and June 8, 2026 Requires existing local foothold plus nf_tables and unprivileged user namespaces, both enabled by default on most systems CVSS rating 7.8 (high); no remote vector or known active exploitation Demonstrated on Debia
Jun 93 min read
Deep Integration: Apple Intelligence Anchors the iOS 27 and macOS 27 Default Application Suites
Key Findings Apple integrated Google's Gemini models directly into Siri's core framework, marking a significant shift in the company's AI strategy Apple Intelligence is now embedded across all native applications in iOS 27 and macOS 27, functioning as system-level infrastructure rather than isolated features Safari gained autonomous web monitoring, intelligent tab organization, and AI-assisted custom extension creation Shortcuts and Home applications now support natural langu
Jun 93 min read
Meta Files Contempt of Court Complaint Against NSO Group for Defying Spyware Injunction
Key Findings Meta detected NSO Group conducting spear phishing campaigns targeting WhatsApp users despite a permanent court injunction issued last year The company filed a federal contempt-of-court complaint, alleging NSO violated the injunction by creating test accounts and luring users to malicious external websites Three malicious domains have been identified: ikhwancast.com, ghazacast.com, and fr24cast.com NSO Group remains on the U.S. Commerce Department's Entity List an
Jun 82 min read
Operation FlutterBridge: macOS Backdoor Campaign Leverages Fake Google Ads and Targeted Distribution
Key Findings Operation FlutterBridge is a sophisticated malvertising campaign targeting macOS users since late 2025, evolving from basic adware into a dangerous backdoor called FlutterShell Threat actors use fake shell companies to purchase verified Google and YouTube ads, bypassing security filters through artificial aging and legitimate developer credentials The malware masquerades as productivity tools including Podcasts Lounge, PDF-Brain, and PDF-Ninja, with three distinc
Jun 83 min read
Meta's Account Recovery Tool Vulnerability Exposes 20,000+ Instagram Users to Unauthorized Password Resets
Key Findings Meta's AI-powered Instagram account recovery tool, known as High Touch Support (HTS), contained a critical flaw that exposed over 20,000 accounts to unauthorized password resets The vulnerability existed for approximately seven weeks, from April 17 to early June 2026, before Meta discovered it on May 31 The flaw allowed attackers to request password reset links for any Instagram account and have them sent to email addresses they controlled, bypassing identity ver
Jun 84 min read
UNC3753 Escalates Campaign Against US Legal Firms: Vishing, Remote Access Tools, and Physical Intrusions
Key Findings UNC3753 (Luna Moth, Chatty Spider, Silent Ransom Group) conducted extortion campaign targeting US legal, financial, and professional services firms from January to May 2026 Attack chain relies entirely on social engineering and voice phishing with no malware or ransomware involved Threat actors escalated tactics to include physical office intrusions where operatives pose as IT technicians and insert USB drives to steal data Stolen data typically includes tax reco
Jun 83 min read
Multiple Critical Vulnerabilities Discovered: VoLTE Flaw and iOS App Security Breach
Key Findings Critical VoLTE flaw in Verizon's core voice network exposes all cellular traffic without encryption SIP signaling between devices and network completely lacks required IPsec ESP protection per 3GPP standards On-path attackers can manipulate voice calls, spoof numbers, hijack calls, and misroute emergency services Verizon has ceased coordinated vulnerability disclosure efforts and provided no evidence of active mitigation Apache Cordova InAppBrowser plugin vulnera
Jun 82 min read
PyPI Supply Chain Attack Exploits Malware Startup Hooks at Scale
Key Findings Coordinated PyPI supply chain attack compromised multiple popular open-source packages through maintainer account takeover Malware uses Python startup hooks (.pth files) to execute automatically during installation without requiring explicit package imports 448 affected artifacts identified spanning both npm and PyPI registries Threat actors dubbed the Hades cluster, part of broader Shai-Hulud and Miasma malware lineage Socket malware detection systems identified
Jun 73 min read
Critical Miasma Worm Campaign Targets Microsoft and Red Hat in Expanding Supply Chain Attack Wave
Key Findings Miasma worm infected 73 Microsoft GitHub repositories across Azure, Azure-Samples, Microsoft, and MicrosoftDocs organizations, forcing GitHub to disable access Attack represents re-compromise of previously infected "durabletask" PyPI package, suggesting threat actors maintained persistent access for over a month Miasma operates as self-replicating malware variant of Mini Shai-Hulud worm, exploiting the trust model of package registries rather than technical vulne
Jun 64 min read
FreeRADIUS and Chrome Security Updates Address Critical Buffer Overflow and Multiple Vulnerabilities
Key Findings FreeRADIUS released emergency patches to fix critical unauthenticated buffer overflow vulnerabilities affecting multiple authentication protocols Malicious actors can crash vulnerable servers without any authentication by sending specially crafted UDP packets Chrome 149 stable release addresses 429 security vulnerabilities including critical memory corruption bugs in graphics and GPU handling Developers are intentionally limiting technical disclosure details to p
Jun 53 min read
PCPJack: How Attackers Hijacked 230 Cloud Servers for Covert Email Relay
Key Findings Threat actor PCPJack compromised 230 cloud servers across AWS, Google Cloud, and Microsoft Azure and converted them into covert SMTP relay proxies Complete toolkit, source code, and live command-and-control configuration were accidentally exposed in an unauthenticated directory on a C2 server The operation used Sliver C2 framework combined with Chisel tunneling to create a self-healing, monitored email relay network that synced verified proxies every five minutes
Jun 53 min read
International Law Enforcement Smashes Major Cybercrime Operations
Key Findings French-led international operation dismantled a major counterfeit document production facility in Alicante, Spain Police seized approximately 800 forged European documents, professional production equipment, and a transport vehicle The facility supplied fake credentials to migrant smuggling networks across Europe, enabling border evasion and illegal residence claims Coordinated enforcement action disrupted critical infrastructure used by organized crime groups Eu
Jun 52 min read
The Renaissance of Native Architecture: Microsoft's WinUI Rebrand and Context Menu Refinement to Salvage Windows 11 Performance
Key Findings Microsoft rebranded WinUI 3 to WinUI at Build 2026, signaling a strategic shift away from resource-heavy web frameworks like Electron and WebView2 The company is actively removing version numbers to emphasize long-term stability and reduce developer anxiety over breaking changes Windows 11's bloated hybrid applications are being replaced with native architecture across core system components including the Start Menu Microsoft announced plans to streamline the con
Jun 43 min read
Cisco Unified CM Critical Vulnerability: Public Exploit Code Now Available
Key Findings CVE-2026-20230 affects Cisco Unified CM with a CVSS score of 8.6, elevated to Critical severity by vendor Unauthenticated remote attackers can exploit an SSRF flaw to write unauthorized files and potentially gain root access Public proof-of-concept exploit code is already available Vulnerability requires WebDialer service to be enabled, which is disabled by default Fixed releases available: version 14SU6 for Release 14 and 15SU5 for Release 15 No complete workaro
Jun 42 min read
Chinese APT Group's Cloud Storage Exploitation: Inside Operation Dragon Weave's Financial Sector Espionage
Key Findings Two major cyber espionage campaigns have targeted high-profile victims using cloud infrastructure and legitimate services to avoid detection Operation Dragon Weave uses multi-stage infection tactics with dual execution pathways to deploy AZUREVEIL, an advanced remote access agent A separate campaign compromised a stock exchange executive's Outlook account for 150 days, stealing complete mailbox contents through incremental exfiltration Both operations weaponize l
Jun 44 min read
Critical WordPress Vulnerabilities: Valve Platform and Forms Plugin Exploited for Web Shell Distribution
Key Findings Gaming platform profiles weaponized to distribute WordPress web shells via invisible Unicode steganography Nearly 2,000 websites compromised through Steam profile command injection technique Critical Everest Forms Pro vulnerability (CVE-2026-3300, CVSS 9.8) actively exploited to create rogue admin accounts Attackers using cookie-authenticated backdoors to maintain persistent access and rewrite code remotely Over 17,900 exploit attempts blocked in single day as at
Jun 43 min read
China-Linked TA4922 Hackers Deploy SilentRunLoader Malware Against UK and European Targets
Key Findings TA4922, a suspected China-aligned cybercrime group, has expanded operations from East Asia to target organisations in the UK, Germany, Italy, and South Africa The group uses locally-tailored phishing emails impersonating tax authorities, benefits services, and government agencies to increase open rates SilentRunLoader, a new Python-based malware likely developed with LLM assistance, steals Chrome credentials, cookies, and browsing data TA4922 employs a diverse to
Jun 32 min read
Google's June 2026 Android Security Update Fixes 124 Vulnerabilities Including One Active Zero-Day Exploit
Key Findings Google released patches for 124 Android security vulnerabilities in June 2026, including one actively exploited flaw CVE-2025-48595 (CVSS 8.4) is a privilege escalation vulnerability in the Android Framework currently under limited, targeted exploitation The flaw affects Android 14, 15, 16, and 16 QPR2, requires no user interaction, and allows code execution through integer overflow CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on Ju
Jun 32 min read
CISA Adds Actively Exploited Vulnerabilities to KEV Catalog
Key Findings CISA added two actively exploited vulnerabilities to the Known Exploited Vulnerabilities catalog requiring immediate remediation CVE-2022-0492 affects Linux Kernel with CVSS 7.8, enabling privilege escalation and container escape attacks CVE-2025-48595 targets Android 14 and later with CVSS 8.4, allowing arbitrary code execution with elevated privileges Federal agencies must patch both vulnerabilities by June 5, 2026 under Binding Operational Directive 22-01 Both
Jun 32 min read
bottom of page
