Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

Cyber Kendra
cyberkendra.com > 2026 > 08 > microsofts-sccm-hotfix-fixes-only-one.html

Microsoft's SCCM Hotfix Fixes Only One of Four RCE Bugs

12+ hour, 28+ min ago   (359+ words) Security researcher Omri Baso has disclosed a remote code execution chain in Microsoft Configuration Manager (SCCM/ConfigMgr) that lets an ordinary Active Directory user seize SYSTEM control of a Primary Site Server — and every client it manages. Microsoft has patched…...

Cyber Kendra
cyberkendra.com > 2026 > 08 > apple-threat-notification-mercenary-spyware.html

Apple Warns iPhone Users of Mercenary Spyware Attacks

3+ day, 54+ min ago   (927+ words) Apple sent a fresh round of mercenary spyware threat notifications to users in 110 countries on Thursday, and for the first time, the warning lands as a push alert on the iPhone Lock Screen instead of an email that can sit…...

Cyber Kendra
cyberkendra.com > 2026 > 08 > namecheap-outage-hits-hosting-dns-and.html

Namecheap Outage Hits Hosting, DNS and Private Email

3+ day, 9+ hour ago   (908+ words) The blast radius is wider than that of most outages at a hosting provider because Namecheap's authoritative DNS servers sit within the same failure domain. That means sites hosted elsewhere broke too, as long as their nameservers pointed to Namecheap....

Cyber Kendra
cyberkendra.com > 2026 > 08 > trezor-says-shipmonk-breach-exposed.html

Trezor Says ShipMonk Breach Exposed 13,689 Customers

3+ day, 13+ hour ago   (286+ words) Trezor disclosed on August 13 that ShipMonk, the third-party fulfilment provider that warehouses and ships its products, reported unauthorised access to systems holding customer order data on Monday, August 10. The investigation is ongoing. 11,742 customers had full records exposed: full name, email…...

Cyber Kendra
cyberkendra.com > 2026 > 08 > cve-2026-63520-sharepoint-rce-patched.html

CVE-2026-63520: SharePoint RCE Patched by Microsoft

4+ day, 2+ hour ago   (195+ words) Rapid7 and Microsoft have disclosed CVE-2026-63520, a remote code execution flaw in Microsoft SharePoint that completes an unauthenticated exploit chain Rapid7 Labs built for Pwn2Own Berlin. Senior Principal Security Researcher Stephen Fewer found it using an AI agent workflow, and Microsoft shipped the…...

Cyber Kendra
cyberkendra.com > 2026 > 08 > litellm-breach-434000-cicd-pipelines-exposed.html

LiteLLM Breach Exposed 434,000 CI/CD Pipelines, 2,500 Firms

4+ day, 3+ hour ago   (728+ words) There is no CVE for this incident because nothing in LiteLLM itself was vulnerable. Attackers linked to the threat group TeamPCP published backdoored LiteLLM 1.82.7 and 1.82.8 to PyPI, where CloudSEK says the packages stayed live for roughly 40 minutes. Version 1.82.8 shipped a…...

Cyber Kendra
cyberkendra.com > 2026 > 08 > shieldbreak-poc-bypasses-microsofts.html

ShieldBreak PoC Bypasses Microsoft's RoguePlanet Defender Fix

5+ day, 2+ hour ago   (294+ words) Security researcher Nightmare Eclipse has released ShieldBreak, a proof-of-concept exploit that defeats the patch Microsoft shipped five weeks ago for a Windows Defender privilege escalation flaw. The researcher dropped the PoC code on GitHub and wrote that Microsoft has failed…...

Cyber Kendra
cyberkendra.com > 2026 > 08 > microsoft-leaves-windows-passkey-prompt.html

Microsoft Leaves Windows Passkey Prompt Spoofing Unfixed

6+ day, 10+ hour ago   (675+ words) Three weeks before Microsoft makes passkeys the default sign-in method for Entra ID, new research shows that the Windows dialog protecting them can be faked well enough to fool the people who build security products for a living — and that…...

Cyber Kendra
cyberkendra.com > 2026 > 08 > deadlock-ransomware-puts-its.html

DeadLock Ransomware Puts Its Negotiation Portal On-Chain

6+ day, 11+ hour ago   (261+ words) Every ransomware crew eventually loses its website. DeadLock's operators appear to have decided not to have one. Instead of a hardcoded onion address, the page fires read-only eth_call requests at six public Polygon RPC endpoints to reach two smart contracts. One…...

Cyber Kendra
cyberkendra.com > 2026 > 08 > researchers-buy-no-reply-domains-and.html

Researchers Buy 'No Reply' Domains and Get Company Data

1+ week, 1+ day ago   (221+ words) Cory Solovewicz, a security researcher and consultant, laid out the problem at the Defcon security conference this week. He registered noreply.us in 2020, intending to use it as a personal catch-all (an inbox that accepts mail sent to any address…...