Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Microsoft's SCCM Hotfix Fixes Only One of Four RCE Bugs
12+ hour, 28+ min ago (359+ words) Security researcher Omri Baso has disclosed a remote code execution chain in Microsoft Configuration Manager (SCCM/ConfigMgr) that lets an ordinary Active Directory user seize SYSTEM control of a Primary Site Server — and every client it manages. Microsoft has patched…...
Apple Warns iPhone Users of Mercenary Spyware Attacks
3+ day, 54+ min ago (927+ words) Apple sent a fresh round of mercenary spyware threat notifications to users in 110 countries on Thursday, and for the first time, the warning lands as a push alert on the iPhone Lock Screen instead of an email that can sit…...
Namecheap Outage Hits Hosting, DNS and Private Email
3+ day, 9+ hour ago (908+ words) The blast radius is wider than that of most outages at a hosting provider because Namecheap's authoritative DNS servers sit within the same failure domain. That means sites hosted elsewhere broke too, as long as their nameservers pointed to Namecheap....
Trezor Says ShipMonk Breach Exposed 13,689 Customers
3+ day, 13+ hour ago (286+ words) Trezor disclosed on August 13 that ShipMonk, the third-party fulfilment provider that warehouses and ships its products, reported unauthorised access to systems holding customer order data on Monday, August 10. The investigation is ongoing. 11,742 customers had full records exposed: full name, email…...
CVE-2026-63520: SharePoint RCE Patched by Microsoft
4+ day, 2+ hour ago (195+ words) Rapid7 and Microsoft have disclosed CVE-2026-63520, a remote code execution flaw in Microsoft SharePoint that completes an unauthenticated exploit chain Rapid7 Labs built for Pwn2Own Berlin. Senior Principal Security Researcher Stephen Fewer found it using an AI agent workflow, and Microsoft shipped the…...
LiteLLM Breach Exposed 434,000 CI/CD Pipelines, 2,500 Firms
4+ day, 3+ hour ago (728+ words) There is no CVE for this incident because nothing in LiteLLM itself was vulnerable. Attackers linked to the threat group TeamPCP published backdoored LiteLLM 1.82.7 and 1.82.8 to PyPI, where CloudSEK says the packages stayed live for roughly 40 minutes. Version 1.82.8 shipped a…...
ShieldBreak PoC Bypasses Microsoft's RoguePlanet Defender Fix
5+ day, 2+ hour ago (294+ words) Security researcher Nightmare Eclipse has released ShieldBreak, a proof-of-concept exploit that defeats the patch Microsoft shipped five weeks ago for a Windows Defender privilege escalation flaw. The researcher dropped the PoC code on GitHub and wrote that Microsoft has failed…...
Microsoft Leaves Windows Passkey Prompt Spoofing Unfixed
6+ day, 10+ hour ago (675+ words) Three weeks before Microsoft makes passkeys the default sign-in method for Entra ID, new research shows that the Windows dialog protecting them can be faked well enough to fool the people who build security products for a living — and that…...
DeadLock Ransomware Puts Its Negotiation Portal On-Chain
6+ day, 11+ hour ago (261+ words) Every ransomware crew eventually loses its website. DeadLock's operators appear to have decided not to have one. Instead of a hardcoded onion address, the page fires read-only eth_call requests at six public Polygon RPC endpoints to reach two smart contracts. One…...
Researchers Buy 'No Reply' Domains and Get Company Data
1+ week, 1+ day ago (221+ words) Cory Solovewicz, a security researcher and consultant, laid out the problem at the Defcon security conference this week. He registered noreply.us in 2020, intending to use it as a personal catch-all (an inbox that accepts mail sent to any address…...