CISA added CVE-2026-48939 and CVE-2026-56291 to its Known Exploited Vulnerabilities catalog after automated attackers ...
ESET found 11 Microsoft-signed UEFI shims, some over a decade old, that let attackers bypass Secure Boot without a single new ...
Most EDR bypass driver incidents rely on a driver the attacker never had to hide, because it already has a real, valid signature. That is exactly what happened with GodDamn, a ransomware family that ...
A technical walkthrough of the kerberoasting attack: the Kerberos quirk it abuses, RC4 vs AES, and how to detect and fix it ...
Adobe wants you to believe the story behind this week’s Adobe ColdFusion vulnerabilities is speed: attackers moving from disclosure to exploitation in hours instead of days, an arms race the defenders ...
Google has rewritten the default rate-limiting schedule behind Android’s lockscreen. Its mechanics are worth understanding if you test, forensically image, or manage fleets of Android devices. The new ...
Most software composition analysis tools read what developers declare. Insignary Clarity’s patented binary-first platform analyzes what is actually built, shipped, and deployed — including the ...
A CSRF attack forces a victim’s browser to fire off a request it never meant to send. It rides on the session cookie already stored for the target site. No password gets stolen and no code runs in the ...
Credential stuffing is the automated testing of stolen username and password pairs against a login endpoint, at scale, until a valid match turns up. For defenders, it is less a single attack to block.
A new Linux kernel bug lets an ordinary, unprivileged user become root. It now hits Android too. Researchers have named it Bad Epoll. The Bad Epoll vulnerability carries the identifier CVE-2026-46242.
Two new Cursor IDE vulnerabilities let an attacker break out of the editor’s command sandbox. All it takes is text the AI agent reads on your behalf. Cato AI Labs disclosed the pair, tracked as ...
The Amazon Q developer vulnerability disclosed last week (CVE-2026-12957, CVSS 8.5) is getting coverage as a patched VS Code extension flaw. It deserves a wider reading. The bug was fixed in May. But ...