RoguePlanet CVE-2026-50656: Microsoft Defender SYSTEM Privilege Escalation Patched
July 10, 2026 Microsoft has finally released a security update for the RoguePlanet CVE-2026-50656 vulnerability. This flaw allowed local attackers to escalate privileges to SYSTEM level through a race condition in the Microsoft Malware Protection Engine.…
Injective SDK npm Supply Chain Attack: Crypto Wallet Keys Stolen via Compromised Package
July 9, 2026 Threat actors compromised a legitimate GitHub contributor account for the Injective Labs SDK project and published a malicious npm package that steals cryptocurrency wallet private keys and mnemonic seed phrases. The attack affected version…
TrojPix Attack Exfiltrates Data From Air-Gapped Systems via Video Cables
July 6, 2026 Researchers at Shandong University have unveiled TrojPix, a novel attack that leaks data from air-gapped systems by modulating video cable electromagnetic emissions. The technique achieves a peak throughput of 8.1 Mbps and reaches distances…
Seven FatFs Vulnerabilities Expose Millions of Embedded Devices to Memory Corruption and Code Execution
July 4, 2026 Security researchers at runZero have disclosed seven vulnerabilities in FatFs, a small filesystem library used by millions of embedded devices worldwide. Consequently, any device that reads FAT or exFAT storage — including security cameras,…
Bad Epoll CVE-2026-46242: Linux Kernel Privilege Escalation Hits Android
July 3, 2026 A newly disclosed Linux kernel vulnerability dubbed “Bad Epoll” (CVE-2026-46242) allows an unprivileged user to escalate to root on Linux desktops, servers, and Android devices. The flaw is a use-after-free in the kernel’s…
Adobe ColdFusion Critical Patch: 6 CVSS 10.0 RCE Flaws Disclosed
July 2, 2026 Adobe has released urgent security patches for ColdFusion, resolving multiple critical vulnerabilities including six rated at the maximum CVSS score of 10.0. These flaws enable unauthenticated remote code execution on widely deployed…
SharePoint RCE CVE-2026-45659: CISA KEV Alert After Active Exploitation
July 2, 2026 CISA has confirmed active exploitation of a high-severity Microsoft SharePoint remote code execution vulnerability tracked as CVE-2026-45659 (CVSS: 8.8). Organizations running supported SharePoint Server versions should patch immediately to…
RustDuck Botnet Rebuilds Core in Rust for DDoS Attacks on Routers and Servers
June 30, 2026 A new two-stage malware family called RustDuck is hijacking home routers, IP cameras, Android boxes, and poorly secured servers to build a distributed denial-of-service (DDoS) botnet. Researchers at QiAnXin’s XLab have tracked it…
BlueHammer CVE: Ransomware Gangs Actively Exploit Microsoft Defender Privilege Escalation Flaw
June 30, 2026 CISA confirmed on Monday that ransomware gangs are now actively exploiting a high-severity Microsoft Defender privilege escalation vulnerability known as BlueHammer. The flaw, tracked as CVE-2026-33825, was originally leaked as a zero-day…
macOS ClickFix Attack Silently Deploys AMOS Infostealer via Fake CAPTCHA Terminal Commands
June 28, 2026 Security researchers at Palo Alto Networks Unit 42 have uncovered a new macOS ClickFix campaign that uses Terminal commands to silently download, mount, and execute infostealing malware. The campaign targets Mac users with fake CAPTCHA…