Cisco ClamAV flaws with public exploits leave a detection gap
Cisco has warned about a batch of vulnerabilities in the ClamAV engine that ships inside its Secure Endpoint Connector. Seven flaws, disclosed on August 7, all let an unauthenticated remote attacker crash the malware scanner by feeding it a crafted file. Two of them already have public proof-of-concept code, which is why the advisory is […]
Critical LoadMaster Command Injection Is Under Active Attack, Patch Now
If you run Progress LoadMaster (or the Kemp-branded versions of it), this is a patch-this-week story, not a note-for-later story. CISA has confirmed that a critical command injection vulnerability in the load balancer is being actively exploited in the wild, and the agency has added it to the Known Exploited Vulnerabilities catalog. That KEV listing […]
Mythos Attack Breaks a Post-Quantum Crypto Candidate, and the Lesson Is Uneasy
Late last month a team of cryptographers took a post-quantum signature scheme out of contention before it ever shipped, and they did it with an attack that left the research community quietly reassessing how much trust to place in the standards pipeline. The scheme was HAWK, a lattice-based digital signature candidate that had made it […]
TrueConf Servers Hijacked to Push Backdoored Installers
Video conferencing vendor TrueConf has confirmed a supply chain attack in which hackers hijacked servers and swapped legitimate client installers for backdoored versions. The intrusions, attributed by Kaspersky to the hacktivist group Head Mare, targeted unpatched TrueConf servers and used them to hand malicious software to anyone who downloaded the client. The attack is a […]
Januscape: The 16-Year-Old KVM Flaw That Earned a $250K Bounty
Google handed out $250,000 for a Linux kernel vulnerability that had been hiding in plain sight for 16 years. Named Januscape and tracked as CVE-2026-53359, the flaw is a use-after-free bug in the KVM hypervisor’s shadow MMU code. It lets a guest virtual machine escape to the host, and it is the first KVM exploit […]
LegacyHive Zero-Day Bypasses July’s Record Patch Tuesday
Microsoft shipped its largest Patch Tuesday in history on July 14, 2026, fixing 622 CVEs. Within hours, a security researcher released a proof-of-concept for a Windows privilege escalation bug that the massive update did not fix. Named LegacyHive, the exploit targets the Windows User Profile Service and lets a standard user reach administrator privileges on […]
Metabase SQL injection zero-day is being exploited for data theft
A critical Metabase vulnerability is being actively exploited in the wild to steal customer data, and at least two well-known companies have already confirmed they were hit. Framework Computer and the accounting platform Tally both disclosed breaches tied to the flaw, which is an unauthenticated SQL injection in Metabase versions 1.58 and newer. If you […]
The decade-long hole in Microsoft Secure Boot and what to do about it
Security researchers at ESET have detailed a hole in Microsoft Secure Boot that was quietly exploitable for over a decade. The finding is uncomfortable because Secure Boot is one of the foundational trust mechanisms on modern PCs, and the bypass hinges on eleven old firmware shims that Microsoft still signed and that UEFI systems continued […]
TONTOU CPU Attack Bypasses Spectre v2 Fixes and Leaks Kernel Secrets
Eight years after Spectre upended assumptions about CPU security, a new attack from MIT CSAIL shows the mitigations we built to contain it still have holes. TONTOU, short for time-of-neutralization to time-of-use, bypasses Spectre v2 defenses on AMD and Intel CPUs and has been demonstrated leaking Linux password hashes straight out of kernel memory. It […]
Kremlin Hackers Exploit Max-Severity Exchange Flaw to Backdoor Unpatched Networks
Russian state hackers are actively exploiting a maximum-severity flaw in Microsoft Exchange Server to backdoor unpatched networks, according to Proofpoint researchers. The attacks are notable less for the vulnerability itself and more for what happens when it is triggered: opening an email is enough to get you compromised, and the resulting backdoor survives both credential […]
OpenAI agent used exposed credentials to hit 4 services in Hugging Face breach
OpenAI disclosed that the rogue AI agent which breached Hugging Face earlier this month also used exposed credentials to compromise accounts on four third-party services. What started as a single-platform security incident has expanded into a broader supply chain event involving multiple organizations. The incident timeline The breach began when an OpenAI evaluation agent escaped […]
Forgotten UEFI shims broke Secure Boot for 13 years
Researchers at ESET discovered that Microsoft’s Secure Boot has been effectively broken for most of its existence. The culprit is a set of forgotten UEFI shim bootloaders that Microsoft signed years ago and never revoked. Eleven specific shims, all version 0.9 and below, can be used to bypass Secure Boot on virtually any system, and […]