Skip to content
category — security

ls ./category/security --page 3

Security

Breaches, vulnerabilities, malware and the patches that matter.

page 3 of 9 — 211 articles

A terabyte left over four days, and nothing in the chain was a vulnerability

2026-09-10

McKesson's 8-K describes roughly one terabyte exfiltrated between 21 and 25 August 2026, detected on the last day. The chain was vishing to Okta SSO to Salesforce and Snowflake — no CVE, no exploit, no patch. And the claimed 284 million records are database rows, by the attackers' own account.

974 flaws, and the two that matter are both privilege escalation

2026-09-09

Microsoft patched 974 vulnerabilities in September, a 70% jump over the previous record, with 723 of them in Windows and more than 110 rated critical. Two are being exploited. Both are CVSS 7.8 local privilege escalation, which means the attacker is already on the machine — and that is the whole triage.

The attribution came from commit emails across 84 GitHub accounts

2026-09-09

The DFIR Report traced a decade-old Bing poisoning operation — fake activation portals, tech support scams, a custom bot and a Monero miner — to two named companies in Rajasthan, using email addresses left in GitHub commit history. That is a far stronger evidentiary chain than most attribution, and it is worth saying so.

The anonymous client passes the ownership check by being nobody

2026-09-09

Two flaws in FreeIPA and 389 Directory Server are unremarkable on their own. Together they let an unauthenticated client write a token entry with blank ownership, satisfy the check for whether it owns that entry, and attach a Kerberos identity with administrative group membership. Nobody has published how to tell whether it already happened to you.

440,000 blocked attempts is a WAF metric, not a compromise count

2026-09-08

Wordfence blocked more than 250,000 attempts against Super Forms and more than 190,000 against Elementor Pro. Both flaws are unauthenticated file upload, both are patched, and the Super Forms campaign has been running since 14 July. What nobody has published is how many sites actually fell.

One researcher dropped three exploits. Only Gen Digital has shipped a fix

2026-09-08

PrettyPrague, FalconFlank and GreenSection target Avast's sandbox, CrowdStrike Falcon's macro remediation and NVIDIA's display driver. Gen Digital has patched. CrowdStrike's advice is to turn the affected protection off. NVIDIA is still investigating. And the FalconFlank claim this site called single-source last week now has independent confirmation.

Adobe has patched StyleSmuggler. The first confirmed victim was fully patched too

2026-09-08

CVE-2026-75650 is rated CVSS 10.0 and Adobe shipped the fix on 8 September, four days into active exploitation. Applying it is only half the remediation — the encryption keys have to be rotated as well. And the first confirmed victim was already running the August patches, which is why patching is not the same as being clear.

PEEP forges Chromium's own integrity values. It also needs you to be compromised first

2026-09-08

SOCRadar documented a post-exploitation toolkit that installs itself into Chrome and Edge profiles as an extension called Smart Bookmarks, forges the signatures Chromium uses to detect exactly that, and reaches the operating system through native messaging. It cannot get onto a machine by itself, which is the part the headlines drop.

The payloads sit on a blockchain testnet, which is free

2026-09-08

Netskope found over 5,400 compromised WordPress and PrestaShop sites pulling their next stage from smart contracts on the BNB Smart Chain testnet. EtherHiding is not new. Putting it on the testnet is, because the testnet costs nothing, behaves like the real chain, and has no abuse desk to write to.

The rogue ScreenConnect clients infect the hosts that connect to them

2026-09-08

Huntress found ScreenConnect clients that write a four-stage VBScript chain onto machines as they connect, profile each host, and then request a different payload depending on how much RAM it has and which EDR is installed. There is no code execution vulnerability to patch — it abuses file transfer, and ConnectWise says the fix is to turn the permission off.

The Telerik exploit chain needs the hardening step Telerik recommends

2026-09-07

TantoSec released a working exploit on 7 September for a padding-oracle chain in Telerik's RadAsyncUpload control that ends in unauthenticated code execution. Its precondition is an explicit, non-default encryption key — the setting administrators were told to configure. Roughly 127,000 requests and an hour in a lab.