Zapscape Flaw Lets a Rogue Cloud Virtual Machine Seize Root on Its Host Server
A Linux kernel vulnerability nicknamed Zapscape and tracked as CVE-2026-64561 allows a malicious KVM guest running nested virtualization to escape its virtual machine entirely and take root control...
Researchers Show How Malware Can Hijack Windows Hello Keys to Slip Into Microsoft Entra ID
New research demonstrates that malware running inside an active, unlocked Windows session can abuse Windows Hello for Business cryptographic keys to authenticate to Microsoft Entra ID, without ever...
New WordPress Flaw Turns a Failed Login Attempt Into Full Server Takeover
A newly disclosed WordPress vulnerability, dubbed XSS2Shell and tracked as CVE-2026-64638, chains a decade-old parsing quirk in the login page into full remote code execution, putting an estimated...
Levi Strauss Confirms Data Breach After Employees Fall for Social Engineering Scam
Levi Strauss & Co. has disclosed that attackers tricked three employees into handing over access to company-issued computers, letting intruders reach and exfiltrate internal files. The denim maker...
18-Year-Old Linux Kernel Bug Lets Attackers Seize Full Root and Break Out of Containers
A newly disclosed use-after-free vulnerability nicknamed SCTPhantom, tracked as CVE-2026-64564, traces back to Linux kernel code written in 2007 and lets a local attacker escalate to full root...
ChainDrop Worm Spreads Through 400+ npm Packages, Raiding Developer and Cloud Credentials
A self-propagating worm dubbed ChainDrop has infected more than 400 npm packages by hijacking trusted publishing accounts, quietly harvesting npm, GitHub, cloud, and SSH credentials from developer machines...
Patchwork Espionage Group Uses Fake PDFs and Romance-Themed Chat Apps to Spy on PCs and Phones
The long-running Patchwork espionage group, also tracked as Dropping Elephant, is running parallel campaigns against Windows machines and Android phones — one built around a PDF-disguised shortcut file,...
Swiss Government IT Agency Confirms SharePoint Breach, About 200 Accounts Compromised
Switzerland's Federal Office for Information Technology and Telecommunication says attackers likely exploited recently disclosed Microsoft SharePoint flaws to steal credentials for roughly 200 user and technical accounts. No...