Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix
JFrog disclosed CVE-2026-90894, a 7.8-rated local privilege escalation in Parallels Desktop for Mac, patched only in version 27, which Intel Macs cannot install.
JFrog researcher Yuval Moravchick disclosed CVE-2026-90894 (dubbed ParaShells, CVSS 7.8), a local privilege escalation in Parallels Desktop for Mac that lets non-admin users run code as root. The root-level prl_disp_service listens on a world-writable socket, and argument injection into a tar command via QProcess::splitCommand and the --use-compress-program option yields code execution as root, demonstrated on Parallels Desktop 26.4.0 build 57513 on Apple silicon. The fix appears in version 27.0.0, but Parallels Desktop 27 requires Apple silicon, leaving Intel Macs on the 26.x line with no build JFrog describes as fixed. No exploitation in the wild has been reported and Parallels has not published a statement.
Hackers Abuse VSSAdmin to Extract NTDS.dit and Delete Windows Recovery Copies
Huntress details intruders using PsExec and VSSAdmin on domain controllers to steal NTDS.dit credentials and delete shadow copies before ransomware.
Huntress analysts identified attackers launching SYSTEM-level command shells via PsExec on a domain controller, then running 'vssadmin create shadow' to snapshot and copy the NTDS.dit Active Directory database. Shadow copies were later deleted to destroy local recovery options ahead of a likely ransomware stage. Huntress recommends correlating VSS creation/deletion events with remote execution, DNS enumeration, and lateral movement rather than alerting on any single VSS event.
Windows BitLocker Flaw Lets Attackers Execute Code on Vulnerable Systems
Microsoft patched CVE-2026-69449, a heap-based buffer overflow in Windows BitLocker allowing privileged local attackers to execute code; no exploitation reported.
Microsoft disclosed CVE-2026-69449 on September 8, 2026, an Important-severity heap-based buffer overflow (CWE-122) in Windows BitLocker with a CVSS 3.1 base score of 6.7. The attack vector is local (AV:L) with high privileges required, so exploitation needs privileged local access rather than remote access over the internet. Microsoft, as assigned CNA, has not reported public exploitation, and administrators are urged to inventory BitLocker-enabled systems and apply updates. Interim mitigations include least-privilege access, limiting administrative rights, and monitoring for unexpected elevated process activity.
Microsoft: Windows Server 2025 changes causing app crashes
Microsoft warns Windows Server 2025 memory-management changes crash AWE apps, including SQL Server with Lock Pages in Memory; disable LPIM as workaround.
Microsoft confirmed a known issue where Windows Server 2025 memory-management changes cause access violations, memory corruption, or unexpected termination in applications using Address Windowing Extensions (AWE). SQL Server running with the Lock Pages in Memory (LPIM) policy is affected, with symptoms including 0xC0000005 access violations, DBCC CHECKDB failures, crash dumps, and services stopping or restarting unexpectedly. Microsoft's temporary workaround is to disable the LPIM policy for the SQL Server service account or disable AWE in other affected apps, with a permanent fix promised in a future Windows update.
Slovakia Warns of Cyber Risks in Road Speed Cameras
Slovakia's NBÚ warns that speed camera systems from SODASUS, Simicon and NEROline pose cyber risks including undocumented remote access.
Slovakia's National Security Authority (NBÚ) warned of a significant cyber threat tied to several road speed camera products: NERO R-ONE units sold by Cyprus-based SODASUS, and Cordon-series cameras made by Russia's Simicon and sold by Croatia's NEROline. A security analysis requested by the Interior Ministry found weak protections, mismatches between documented and actual communication settings and software versions, unclear hardware/software provenance, and pre-configured remote-access mechanisms outside operator control. NBÚ warned that compromised cameras could expose vehicle and licence-plate data, tamper with records, or serve as a foothold into public-sector networks lacking segmentation. The Interior Ministry reportedly removed the units from its pilot deployment and asked the supplier to replace them with equipment meeting Slovak and EU security requirements.
Three intrusions at UK criminal records office went undetected for two years
UK ICO reprimands ACRO criminal records office after three undetected intrusions over two years exposed thousands of records, including domestic violence victims.
The UK Information Commissioner's Office reprimanded ACRO Criminal Records Office after three intrusions between July 2021 and June 2023 exploited a Kentico customer portal unpatched since September 2019 and ignored Trend Micro antivirus alerts, including four quarantined Mimikatz detections. An attacker maintained persistent access for roughly seven months and staged data of nearly 11,000 people for exfiltration, though ACRO could not confirm exfiltration due to insufficient logging. ACRO notified more than 84,000 people on a precautionary basis; the Medusa ransomware group claimed the incident, and network segmentation kept attackers out of the Police National Computer.