oss-security·2h ago[NotCVE-2026-0015] Input Leap through 3.0.3 input-leapd Unauthenticated IPC Command Execution Allows Local Privilege Escalation to SYSTEM#input-leap#privilege-escalation#ipcVulnerability 4 sources
Infosecurity Magazine·19h ago highWindows Botnet x47.c Offers AI API Draining, 18 Attack Methods#ai-abuse#botnet#credential-theft 2 sources 2 min
Help Net Security·1d agoFake payroll desktop apps hand attackers a route to company paychecks#screenconnect#payroll-fraud#social-engineering 2 sources in the wild 4 min
CSO Online·1d agoDocumentation placeholder domain used in ClickFix attacks#clickfix#social-engineering#powershell 4 sources in the wild
Malwarebytes Labs·1d agoKothamine malware uses Tailscale’s tailcat to evade network detection#kothamine#rat#npm in the wild 11 min1
Cyber Security News·1d agoHackers Used a Samsung Flaw to Build a Cryptominer Inside Victim Systems#samsung#magicinfo#cryptominer 2 sources in the wild 5 min
The Register · Security·1d agoDecades-old file security flaws found in Android, Linux, macOS, and Windows#linux#windows#macos 3 sources 4 min
GBHackers·2d agoNew Windows Malware Built to Survive Takedowns With a Hidden P2P Command Network#avisloader#loader#tox 5 min
BleepingComputer·2d agoMicrosoft: September Windows updates break Always On VPN connections#always-on-vpn#ikev2#microsoft 4 sources 2 min1
The Hacker News·3d agoThis Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move#closedquorum#windows#infostealer 13 sources 5 min
oss-security·3d ago[kubernetes] CVE-2026-76654: Subpath symlinking on Windows nodes permits NTLM coercion#kubernetes#cve-2026-76654#ntlmCVE-2026-76654 2 sources
Dark Reading·3d agoEDR Evasion Stack Helps Process Injection Slip Past Defenses#edr#process-injection#evasion
Hacker News · security·3d agoShow HN: I built a post-mortem debugger for native Windows x64/x86 crashes#windows#debugger#crash-dump
GBHackers·3d ago criticalManageEngine RCE Flaw Enables SYSTEM Code Execution From Windows Login Screen#adselfservice-plus#manageengine#physical-access 2 sources 3 min
The Hacker News·3d ago criticalChinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware#uta0565#chrome#windows 4 sources in the wild 2 min
The Hacker News·3d ago highFake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR#lastpass#infostealer#byovd 5 sources in the wild 5 min
The Hacker News·4d ago highResearcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates#microsoft-defender#bigdiskbuster#zero-day 7 sources 3 min
Cyber Security News·4d agoNew TASK#STOMP Backdoor Uses PowerShell to Steal Documents and Wi-Fi Passwords#taskstomp#powershell#backdoor 4 sources in the wild 6 min
Cyber Security News·4d ago highVeeam Agent Flaw Actively Exploited to Gain SYSTEM Privileges on Windows#veeam#cve-2026-32996#privilege-escalation 4 sources 3 min
Google Project Zero·4d ago highWindows Exploitation Techniques: Dangling COM Object Registrations#windows#privilege-escalation#comCVE-2026-50343 2 sources 8 min1
Cyber Security News·4d agoVidar Malware Rewrites Its Obfuscation With Every Build to Make Detection Harder#vidar#infostealer#obfuscation 3 sources in the wild 4 min1
Cyber Security News·4d agoHackers Steal NTDS.dit to Dump Active Directory Password Hashes and Forge Golden Tickets#ntds-dit#active-directory#golden-ticket 2 sources 5 min
arXiv cs.CR·5d agoEvaluating Coding Agents on Kernel Exploit Generation#kex-bench#coding-agents#kernel-exploitAI safety & security1