Chinese APT Group Deploys Signed Kernel Rootkit to Hide ‘CoolClient’ Backdoor on Government Networks
Researchers have exposed a HoneyMyte campaign that pairs the PlugX loader with a new backdoor called CoolClient, concealed by a digitally signed kernel rootkit driver. The malware has...
Roundcube Patches Eleven Flaws, Including Remote Code Execution Reachable Through Spam-Learning Plugin
Roundcube 1.6.18 and 1.7.3 close eleven vulnerabilities, headlined by a remote code execution bug in the markasjunk plugin and two SSRF filter bypasses. No in-the-wild exploitation has been...
Four Chained Flaws in Microsoft SCCM Let Any Domain User Seize Full Server Control
A newly disclosed exploit chain in Microsoft System Center Configuration Manager, tracked as CVE-2026-47301, lets a standard Active Directory user achieve remote code execution as SYSTEM on the...
Threema Beats Back Multi-Day DDoS Siege, Rolls Out New Upstream Filtering
Privacy-focused messenger Threema spent nearly a day fighting off a shifting distributed denial-of-service campaign that hit both its own infrastructure and its colocation partner. No group has claimed...
Shell Launches Investigation After Cl0p Extortion Group Claims Theft of Nearly 90GB of Internal Data
Energy giant Shell has activated its incident response process after the Cl0p extortion syndicate listed the company on its dark-web leak site, claiming to have stolen roughly 89GB...
Attackers Race to Weaponize Maximum-Severity SAP Commerce Cloud Flaw Within Days of Patch
A maximum-severity remote code execution flaw in SAP Commerce Cloud is already being probed by attackers just days after a fix shipped, with honeypot sensors picking up automated...
Security Leaders Warn the ‘Agentic Attacker’ Has Arrived After AI Models Reportedly Breached Hugging Face on Their Own
An incident in which autonomous OpenAI models allegedly broke out of a sandboxed test environment and gained remote code execution on Hugging Face's infrastructure — carrying out more...
Microsoft Sets Hard Deadline to Kill SMS and Voice Login Codes in Entra ID, Pushes Passkeys Instead
Microsoft is moving to make passkeys the default sign-in method across Entra ID while permanently retiring native SMS and voice-based multi-factor authentication by February 2027. The company says...