top of page

ALL POSTS

Chrome V8 Zero-Day CVE-2026-11645 Being Exploited in the Wild - Apply Patch Immediately

Key Findings Google released security updates addressing 74 vulnerabilities, including CVE-2026-11645, a high-severity zero-day actively exploited in the wild CVE-2026-11645 is an out-of-bounds memory access flaw in V8 with a CVSS score of 8.8 that allows remote code execution via crafted HTML pages This is the fifth actively exploited Chrome zero-day in 2026, following CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, and CVE-2026-5281 CISA added CVE-2026-42271, a command injecti

Critical One-Character Linux Kernel Vulnerability Enables Local Root Access with Public Exploits Available

Key Findings A single inverted character in Linux kernel nf_tables code allows unprivileged local users to escalate to root via use-after-free vulnerability CVE-2026-23111 Upstream patch released February 5, 2026; working exploits published April 16 and June 8, 2026 Requires existing local foothold plus nf_tables and unprivileged user namespaces, both enabled by default on most systems CVSS rating 7.8 (high); no remote vector or known active exploitation Demonstrated on Debia

Deep Integration: Apple Intelligence Anchors the iOS 27 and macOS 27 Default Application Suites

Key Findings Apple integrated Google's Gemini models directly into Siri's core framework, marking a significant shift in the company's AI strategy Apple Intelligence is now embedded across all native applications in iOS 27 and macOS 27, functioning as system-level infrastructure rather than isolated features Safari gained autonomous web monitoring, intelligent tab organization, and AI-assisted custom extension creation Shortcuts and Home applications now support natural langu

Meta Files Contempt of Court Complaint Against NSO Group for Defying Spyware Injunction

Key Findings Meta detected NSO Group conducting spear phishing campaigns targeting WhatsApp users despite a permanent court injunction issued last year The company filed a federal contempt-of-court complaint, alleging NSO violated the injunction by creating test accounts and luring users to malicious external websites Three malicious domains have been identified: ikhwancast.com, ghazacast.com, and fr24cast.com NSO Group remains on the U.S. Commerce Department's Entity List an

Operation FlutterBridge: macOS Backdoor Campaign Leverages Fake Google Ads and Targeted Distribution

Key Findings Operation FlutterBridge is a sophisticated malvertising campaign targeting macOS users since late 2025, evolving from basic adware into a dangerous backdoor called FlutterShell Threat actors use fake shell companies to purchase verified Google and YouTube ads, bypassing security filters through artificial aging and legitimate developer credentials The malware masquerades as productivity tools including Podcasts Lounge, PDF-Brain, and PDF-Ninja, with three distinc

Meta's Account Recovery Tool Vulnerability Exposes 20,000+ Instagram Users to Unauthorized Password Resets

Key Findings Meta's AI-powered Instagram account recovery tool, known as High Touch Support (HTS), contained a critical flaw that exposed over 20,000 accounts to unauthorized password resets The vulnerability existed for approximately seven weeks, from April 17 to early June 2026, before Meta discovered it on May 31 The flaw allowed attackers to request password reset links for any Instagram account and have them sent to email addresses they controlled, bypassing identity ver

UNC3753 Escalates Campaign Against US Legal Firms: Vishing, Remote Access Tools, and Physical Intrusions

Key Findings UNC3753 (Luna Moth, Chatty Spider, Silent Ransom Group) conducted extortion campaign targeting US legal, financial, and professional services firms from January to May 2026 Attack chain relies entirely on social engineering and voice phishing with no malware or ransomware involved Threat actors escalated tactics to include physical office intrusions where operatives pose as IT technicians and insert USB drives to steal data Stolen data typically includes tax reco

Multiple Critical Vulnerabilities Discovered: VoLTE Flaw and iOS App Security Breach

Key Findings Critical VoLTE flaw in Verizon's core voice network exposes all cellular traffic without encryption SIP signaling between devices and network completely lacks required IPsec ESP protection per 3GPP standards On-path attackers can manipulate voice calls, spoof numbers, hijack calls, and misroute emergency services Verizon has ceased coordinated vulnerability disclosure efforts and provided no evidence of active mitigation Apache Cordova InAppBrowser plugin vulnera

PyPI Supply Chain Attack Exploits Malware Startup Hooks at Scale

Key Findings Coordinated PyPI supply chain attack compromised multiple popular open-source packages through maintainer account takeover Malware uses Python startup hooks (.pth files) to execute automatically during installation without requiring explicit package imports 448 affected artifacts identified spanning both npm and PyPI registries Threat actors dubbed the Hades cluster, part of broader Shai-Hulud and Miasma malware lineage Socket malware detection systems identified

Critical Miasma Worm Campaign Targets Microsoft and Red Hat in Expanding Supply Chain Attack Wave

Key Findings Miasma worm infected 73 Microsoft GitHub repositories across Azure, Azure-Samples, Microsoft, and MicrosoftDocs organizations, forcing GitHub to disable access Attack represents re-compromise of previously infected "durabletask" PyPI package, suggesting threat actors maintained persistent access for over a month Miasma operates as self-replicating malware variant of Mini Shai-Hulud worm, exploiting the trust model of package registries rather than technical vulne

FreeRADIUS and Chrome Security Updates Address Critical Buffer Overflow and Multiple Vulnerabilities

Key Findings FreeRADIUS released emergency patches to fix critical unauthenticated buffer overflow vulnerabilities affecting multiple authentication protocols Malicious actors can crash vulnerable servers without any authentication by sending specially crafted UDP packets Chrome 149 stable release addresses 429 security vulnerabilities including critical memory corruption bugs in graphics and GPU handling Developers are intentionally limiting technical disclosure details to p

PCPJack: How Attackers Hijacked 230 Cloud Servers for Covert Email Relay

Key Findings Threat actor PCPJack compromised 230 cloud servers across AWS, Google Cloud, and Microsoft Azure and converted them into covert SMTP relay proxies Complete toolkit, source code, and live command-and-control configuration were accidentally exposed in an unauthenticated directory on a C2 server The operation used Sliver C2 framework combined with Chisel tunneling to create a self-healing, monitored email relay network that synced verified proxies every five minutes

International Law Enforcement Smashes Major Cybercrime Operations

Key Findings French-led international operation dismantled a major counterfeit document production facility in Alicante, Spain Police seized approximately 800 forged European documents, professional production equipment, and a transport vehicle The facility supplied fake credentials to migrant smuggling networks across Europe, enabling border evasion and illegal residence claims Coordinated enforcement action disrupted critical infrastructure used by organized crime groups Eu

The Renaissance of Native Architecture: Microsoft's WinUI Rebrand and Context Menu Refinement to Salvage Windows 11 Performance

Key Findings Microsoft rebranded WinUI 3 to WinUI at Build 2026, signaling a strategic shift away from resource-heavy web frameworks like Electron and WebView2 The company is actively removing version numbers to emphasize long-term stability and reduce developer anxiety over breaking changes Windows 11's bloated hybrid applications are being replaced with native architecture across core system components including the Start Menu Microsoft announced plans to streamline the con

Cisco Unified CM Critical Vulnerability: Public Exploit Code Now Available

Key Findings CVE-2026-20230 affects Cisco Unified CM with a CVSS score of 8.6, elevated to Critical severity by vendor Unauthenticated remote attackers can exploit an SSRF flaw to write unauthorized files and potentially gain root access Public proof-of-concept exploit code is already available Vulnerability requires WebDialer service to be enabled, which is disabled by default Fixed releases available: version 14SU6 for Release 14 and 15SU5 for Release 15 No complete workaro

Chinese APT Group's Cloud Storage Exploitation: Inside Operation Dragon Weave's Financial Sector Espionage

Key Findings Two major cyber espionage campaigns have targeted high-profile victims using cloud infrastructure and legitimate services to avoid detection Operation Dragon Weave uses multi-stage infection tactics with dual execution pathways to deploy AZUREVEIL, an advanced remote access agent A separate campaign compromised a stock exchange executive's Outlook account for 150 days, stealing complete mailbox contents through incremental exfiltration Both operations weaponize l

Critical WordPress Vulnerabilities: Valve Platform and Forms Plugin Exploited for Web Shell Distribution

Key Findings Gaming platform profiles weaponized to distribute WordPress web shells via invisible Unicode steganography Nearly 2,000 websites compromised through Steam profile command injection technique Critical Everest Forms Pro vulnerability (CVE-2026-3300, CVSS 9.8) actively exploited to create rogue admin accounts Attackers using cookie-authenticated backdoors to maintain persistent access and rewrite code remotely Over 17,900 exploit attempts blocked in single day as at

China-Linked TA4922 Hackers Deploy SilentRunLoader Malware Against UK and European Targets

Key Findings TA4922, a suspected China-aligned cybercrime group, has expanded operations from East Asia to target organisations in the UK, Germany, Italy, and South Africa The group uses locally-tailored phishing emails impersonating tax authorities, benefits services, and government agencies to increase open rates SilentRunLoader, a new Python-based malware likely developed with LLM assistance, steals Chrome credentials, cookies, and browsing data TA4922 employs a diverse to

Google's June 2026 Android Security Update Fixes 124 Vulnerabilities Including One Active Zero-Day Exploit

Key Findings Google released patches for 124 Android security vulnerabilities in June 2026, including one actively exploited flaw CVE-2025-48595 (CVSS 8.4) is a privilege escalation vulnerability in the Android Framework currently under limited, targeted exploitation The flaw affects Android 14, 15, 16, and 16 QPR2, requires no user interaction, and allows code execution through integer overflow CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on Ju

CISA Adds Actively Exploited Vulnerabilities to KEV Catalog

Key Findings CISA added two actively exploited vulnerabilities to the Known Exploited Vulnerabilities catalog requiring immediate remediation CVE-2022-0492 affects Linux Kernel with CVSS 7.8, enabling privilege escalation and container escape attacks CVE-2025-48595 targets Android 14 and later with CVSS 8.4, allowing arbitrary code execution with elevated privileges Federal agencies must patch both vulnerabilities by June 5, 2026 under Binding Operational Directive 22-01 Both

  • Youtube

© 2025 by Explain IT Again. Powered and secured by Wix

bottom of page