F-Droid 2.0 Modernizes Android App Discovery but Leaves Some Privacy Tools Behind
F-Droid 2.0 brings the open-source Android repository its largest client redesign in a decade, with improved search, automatic updates and a modernized codebase. Privacy-conscious users should note that...
Uncensored Local AI Reworks Credential Dumper to Evade Two EDR Platforms
A controlled experiment showed a locally hosted, guardrail-free AI model modifying an LSASS credential dumper until it escaped detection by two unnamed EDR products. The limited test does...
Two Reported NetScaler Zero-Days Put Internet-Facing Gateways on Emergency Watch
Researchers say two undisclosed Citrix NetScaler remote-code-execution flaws are already being used in attacks, although vendor confirmation and technical indicators remain pending. Defenders should inventory exposed appliances, preserve...
Console Pipe Injection Shows Why EDR Cannot Rely on Classic Memory-Write Signals
A newly disclosed Windows injection method delivers payload bytes through a child console process’s redirected input, avoiding two APIs commonly associated with remote code injection. The technique still...
Wireshark Update Fixes 19 Flaws That Turn Untrusted Captures Into Workstation Risk
Wireshark 4.6.9 and 4.4.19 address 19 documented vulnerabilities, including a configuration-profile flaw that may permit code execution. Security teams should update analyst workstations and treat captures, profiles and...
CARBONATO Botnet Embeds an AI Agent in Compromised Docker Hosts
The CARBONATO botnet abuses unauthenticated Docker services, escapes privileged containers and installs an AI agent controlled through Telegram. Separate automated scripts spread across nearby networks while the agent...
Samsung MagicINFO Exploit Leads to Persistent Access and On-Host Cryptominer Build
Attackers exploited a known Samsung MagicINFO file-write flaw, installed AnyDesk, created an administrator account and disabled Microsoft Defender before building a Monero miner on the victim. The case...
Actively Exploited Linux Kernel Race Condition Enables Root and Container Escape
A race condition in Linux’s AF_ALG cryptographic interface can give an unprivileged local attacker root access and may support Docker container escape. CISA lists CVE-2025-39964 as exploited in...