Fired IT Admin Gets 32 Months for Bitcoin Extortion Plot That Nearly Crippled a New Jersey Company’s Network
Daniel Rhyne, a former core infrastructure engineer, has been sentenced to 32 months in federal prison for planting a hidden virtual machine, deleting domain administrator accounts, and demanding...
Console Pipe Injection Shows Why EDR Cannot Rely on Classic Memory-Write Signals
A newly disclosed Windows injection method delivers payload bytes through a child console process’s redirected input, avoiding two APIs commonly associated with remote code injection. The technique still...
Steam Windows Zero-Day Turns Local Access Into Full SYSTEM Control
A newly disclosed weakness in the Steam Client Service reportedly lets a standard Windows user execute code with SYSTEM privileges. With no confirmed vendor fix at publication time,...
Microsoft’s September Patch Wave Fixes 973 Flaws and Two Exploited Zero-Days
Microsoft’s September 2026 security release addresses 973 vulnerabilities across Windows, Office, SQL Server and other enterprise products. Two privilege-escalation zero-days are already being exploited, making rapid testing and...
WatchGuard Agent Vulnerabilities Allow Attackers to Escalate to Full SYSTEM Privileges on Windows
WatchGuard has released urgent security updates patching four high-severity vulnerabilities in the WatchGuard Agent for Windows, including chained CVE-2026-6787 and CVE-2026-6788 flaws (CVSS 8.5) that grant NT AUTHORITY\SYSTEM...