-
A newly disclosed flaw in the Linux kernel’s traffic-control subsystem, now assigned CVE-2026-46331 and referred to as “Pedit COW,” has been found to grant any unprivileged local user full root access on vulnerable systems. Within jus…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical cloud storage attack technique that exploits a fundamental architectural vulnerability shared across all major cloud service providers. The technique, dubbed cloud bucket hijacking, allows attackers to silently redirect active data streams, …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical Local Privilege Escalation flaw has been uncovered within the Linux kernel, allowing unprivileged local users to seamlessly gain root access by manipulating the system’s page cache. This vulnerability, designated as CVE-2026-43503, rep…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical security flaw discovered in the Amazon Q Developer Extension for Visual Studio Code (VS Code) left developers vulnerable to arbitrary code execution and cloud credential theft. Tracked as CVE-2026-12957 and CVE-2026-12958, these high-severit…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Water and wastewater systems have become strategic gray‑zone targets for Russia, China, and Iran, driven by chronic underinvestment and weak operational‑technology (OT) defenses that make these utilities easy to probe and exploit. Internet‑facing human…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
China-Linked Malware Found in Counterfeit USB Drives Used on Japan Defense Force Classified Networks

Japan’s defense infrastructure has faced scrutiny following an investigation that revealed members of the Japan Self-Defense Forces (JSDF) used counterfeit USB drives embedded with malware linked to China on systems handling classified informatio…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical server-side template injection (SSTI) vulnerability in FOSSBilling, tracked as CVE-2026-28496, is exposing instances to potential full database compromise and remote code execution (RCE), with early signs of active exploitation appearing sho…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Hackers have weaponized a WinRAR path-traversal flaw tracked as CVE-2025-8088 to silently plant a Startup shortcut and run a multi-stage PowerShell loader that maps a headerless, reflectively loaded PE in memory. The campaign reuses the Ukrainian recon…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Scammers are increasingly exploiting Shopify’s ecosystem and its Shop order-tracking app to deliver fraudulent invoices directly into users’ purchase histories, marking a shift from traditional email-based phishing to in-app social engineering attacks….
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Russian authorities leveraged Cellebrite’s Universal Forensic Extraction Device (UFED) to gain access to a detained human rights activist’s iPhone, according to a detailed forensic investigation that raises fresh concerns over the use of commercial dig…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶

