exploit

Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)

Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894) 2026-09-16 at 15:36 By Zeljka Zorz A newly disclosed vulnerability in Parallels Desktop, tracked as CVE-2026-90894 and dubbed “ParaShells,” can allow any local user on a Mac to gain root privileges on the host system. ParaShells PoC in action (Source: JFrog) The danger […]

Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894) Read More »

Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution 2026-09-14 at 14:51 By Ionut Arghire The Chinese-language input method editor for Windows can allow attackers to execute arbitrary code remotely. The post Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution appeared first on SecurityWeek. This article is an excerpt from […]

Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution Read More »

New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender

New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender 2026-09-10 at 10:09 By Ionut Arghire The exploit provides full System privileges on Windows machines running the September 2026 patches. The post New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender Read More »

Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491)

Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491) 2026-09-09 at 10:53 By Sinisa Markovic Google has fixed 230 vulnerabilities in Chrome, including a zero-day flaw, CVE-2026-87491, with an in-the-wild exploit. “Google is aware that an exploit for CVE-2026-87491 exists in the wild,” the company said in a Tuesday security advisory. The fix has been […]

Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491) Read More »

Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits

Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits 2026-09-07 at 15:15 By Ionut Arghire The proof-of-concept (PoC) exploits lead to privilege escalation, spawning a shell with System privileges. The post Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits Read More »

N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)

N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218) 2026-09-07 at 14:55 By Sinisa Markovic N-able released an emergency hotfix for CVE-2026-86218, a remote code execution (RCE) flaw affecting N-central, its remote monitoring and management (RMM) solution popular with managed service providers (MSPs). In its release notes, N-able described CVE-2026-86218 as a “critical-CVSS-rated vulnerability […]

N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218) Read More »

Google patches actively exploited Chrome zero-day (CVE-2026-85046)

Google patches actively exploited Chrome zero-day (CVE-2026-85046) 2026-09-04 at 15:09 By Sinisa Markovic Google has patched 12 vulnerabilities affecting its popular Chrome browser, among them CVE-2026-85046, which has been exploited in the wild. “Google is aware that an exploit for CVE-2026-85046 exists in the wild,” the company said in a Thursday security advisory. The fix […]

Google patches actively exploited Chrome zero-day (CVE-2026-85046) Read More »

Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)

Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911) 2026-09-02 at 16:24 By Sinisa Markovic Nearly 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability, according to daily scans from the Shadowserver Foundation. The United States and Germany top the list with 6,200 and 5,100 unpatched servers. CVE-2026-62911 […]

Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911) Read More »

Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)

Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586) 2026-09-02 at 15:42 By Zeljka Zorz A threat actor is actively targeting internet-exposed Sangoma Switchvox instance through a recently patched SQL injection flaw (CVE-2026-9586), and organizations running them should check for signs of compromise immediately. How CVE-2026-9586 works Switchvox is a VoIP-based unified communications platform built on […]

Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586) Read More »

SonicWall SMA 1000 appliances under attack via zero-day flaws

SonicWall SMA 1000 appliances under attack via zero-day flaws 2026-09-02 at 13:13 By Zeljka Zorz Attackers are exploiting two previously undisclosed vulnerabilities (CVE-2026-83548, CVE-2026-83549) in SonicWall SMA 1000 appliances, the vendor confirmed on Tuesday. The vulnerabilities (CVE-2026-83548, CVE-2026-83549) The SonicWall SMA 1000 series is a line of secure remote access appliances (SSL VPN gateways) built […]

SonicWall SMA 1000 appliances under attack via zero-day flaws Read More »

Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars

Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars 2026-09-01 at 15:37 By Eduard Kovacs Forescout researchers used Claude AI to port a remote code execution exploit between WAGO PLC models. The post Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars appeared first on SecurityWeek. This […]

Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars Read More »

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) 2026-08-26 at 13:59 By Zeljka Zorz Attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform, CISA confirmed on Tuesday by adding the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. The KEV entry does not contain or point to details […]

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) Read More »

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks 2026-08-25 at 13:03 By Zeljka Zorz At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday. About CVE-2026-73570 Zimbra Collaboration Suite (ZCS) is a communication and collaboration platform popular with organizations that need to have control over […]

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks Read More »

PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)

PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121) 2026-07-27 at 15:04 By Zeljka Zorz Security researchers who discovered and reported CVE-2026-54121 (aka “Certighost”), a critical privilege elevation vulnerability in Active Directory Certificate Services (AD CS), have released a proof-of-concept (PoC) exploit for and technical details related to the flaw. The vulnerability AD CS […]

PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121) Read More »

Microsoft releases fix for RoguePlanet Defender flaw (CVE-2026-50656)

Microsoft releases fix for RoguePlanet Defender flaw (CVE-2026-50656) 2026-07-09 at 15:14 By Zeljka Zorz Microsoft has finally released a security update for its Microsoft Malware Protection Engine, which fixes CVE-2026-50656, the Windows Defender local privilege escalation vulnerability triggered by the RoguePlanet exploit. The vulnerability and the fix CVE-2026-50656 is due to improper link resolution before […]

Microsoft releases fix for RoguePlanet Defender flaw (CVE-2026-50656) Read More »

Attackers using Langflow flaw for credential harvesting (CVE-2026-55255)

Attackers using Langflow flaw for credential harvesting (CVE-2026-55255) 2026-07-08 at 17:03 By Zeljka Zorz The US Cybersecurity and Infrastructure Security Agency (CISA) is warning about yet another Langflow vulnerability (CVE-2026-55255) leveraged by attackers in the wild. The flaw was added to the agency’s Known Exploited Vulnerabilities catalog on Tuesday, July 7, nearly two weeks after […]

Attackers using Langflow flaw for credential harvesting (CVE-2026-55255) Read More »

Attackers exploit critical Adobe ColdFusion vulnerability (CVE-2026-48282)

Attackers exploit critical Adobe ColdFusion vulnerability (CVE-2026-48282) 2026-07-07 at 15:03 By Zeljka Zorz CVE-2026-48282, one of the maximum severity vulnerabilities patched in Adobe ColdFusion on June 30, 2026, has been targeted by attackers in the wild. Exploitation attempts were detected on July 2, through the honeypot sensors of cybersecurity threat-intelligence service KEVIntel, mere minutes after […]

Attackers exploit critical Adobe ColdFusion vulnerability (CVE-2026-48282) Read More »

New Exploit Bypasses Apple’s Boot Defenses, Affects Millions of iPhones

New Exploit Bypasses Apple’s Boot Defenses, Affects Millions of iPhones 2026-06-22 at 13:03 By Eduard Kovacs The vulnerability exploited by the Usbliter8 exploit cannot be patched and a PoC exploit has been released by researchers. The post New Exploit Bypasses Apple’s Boot Defenses, Affects Millions of iPhones appeared first on SecurityWeek. This article is an […]

New Exploit Bypasses Apple’s Boot Defenses, Affects Millions of iPhones Read More »

Scroll to Top