Microsoft Confirms Entra ID Zero-Day Was Exploited Before the Fix Went Live
Microsoft has disclosed CVE-2026-69836, a maximum-severity deserialization flaw in Entra ID that attackers exploited in the wild before the company silently patched it server-side. There is no customer...
Researchers Show How a Signed Windows Defender Driver Could Be Turned Against Security Tools
Check Point researchers reverse-engineered Microsoft Defender's BTR.sys driver and found that its undocumented transaction protocol could be reproduced to disable antivirus and EDR products from the Windows kernel...
Feds Sound Alarm on Active Hacking Campaign Targeting Siemens S7 PLCs Nationwide
NSA, CISA, the FBI, DOE and EPA have jointly warned that hackers are actively scanning for and probing Siemens S7-series PLCs across U.S. critical infrastructure. The campaign favors...
CISA Gives Agencies Until August 21 to Patch Actively Exploited Windows VPN Flaw
CISA has added a double-free memory corruption bug in Microsoft's Internet Key Exchange service extensions to its Known Exploited Vulnerabilities catalog after confirming active attacks, giving federal agencies...
Citrix Patches Critical NetScaler Flaw That Lets Attackers Skip the Login Screen Entirely
Citrix has patched two new NetScaler ADC and Gateway vulnerabilities, including a 9.3-severity authentication bypass that can let remote attackers slip past login controls on SSL VPN, ICA...
Critical MLflow Flaw Lets Attackers Steal Cloud Credentials via Webhook Redirects
A critical server-side request forgery flaw in MLflow, tracked as CVE-2026-64849 with a 9.3 CVSS score, lets unauthenticated attackers abuse the platform's webhook-testing endpoint to reach cloud metadata...
Four Chained Flaws in Microsoft SCCM Let Any Domain User Seize Full Server Control
A newly disclosed exploit chain in Microsoft System Center Configuration Manager, tracked as CVE-2026-47301, lets a standard Active Directory user achieve remote code execution as SYSTEM on the...
Roundcube Patches Eleven Flaws, Including Remote Code Execution Reachable Through Spam-Learning Plugin
Roundcube 1.6.18 and 1.7.3 close eleven vulnerabilities, headlined by a remote code execution bug in the markasjunk plugin and two SSRF filter bypasses. No in-the-wild exploitation has been...