CISA added CVE-2026-48939 and CVE-2026-56291 to its Known Exploited Vulnerabilities catalog after automated attackers ...
ESET found 11 Microsoft-signed UEFI shims, some over a decade old, that let attackers bypass Secure Boot without a single new ...
GodDamn ransomware's PoisonX driver is a textbook EDR bypass driver: a Microsoft-signed kernel driver that kills security ...
A technical walkthrough of the kerberoasting attack: the Kerberos quirk it abuses, RC4 vs AES, and how to detect and fix it ...
Adobe wants you to believe the story behind this week’s Adobe ColdFusion vulnerabilities is speed: attackers moving from disclosure to exploitation in hours instead of days, an arms race the defenders ...
A Gitea Docker vulnerability disclosed last month is now drawing real attacker interest, and it is easy to see why. CVE-2026-20896, rated 9.8 out of 10 on the CVSS scale, let anyone who could reach a ...
Google has rewritten the default rate-limiting schedule behind Android’s lockscreen. Its mechanics are worth understanding if you test, forensically image, or manage fleets of Android devices. The new ...
Most software composition analysis tools read what developers declare. Insignary Clarity’s patented binary-first platform analyzes what is actually built, shipped, and deployed — including the ...
A CSRF attack forces a victim’s browser to fire off a request it never meant to send. It rides on the session cookie already stored for the target site. No password gets stolen and no code runs in the ...
Credential stuffing is the automated testing of stolen username and password pairs against a login endpoint, at scale, until a valid match turns up. For defenders, it is less a single attack to block.
A brute force attack is when software automatically tries password after password, username after username, or key after key. It keeps guessing against a login or an encrypted file until one ...
A new Linux kernel bug lets an ordinary, unprivileged user become root. It now hits Android too. Researchers have named it Bad Epoll. The Bad Epoll vulnerability carries the identifier CVE-2026-46242.