Securing Windows Named Pipes: Defending Interprocess Communication from Local Privilege Escalation
Interprocess communication (IPC) on Microsoft Windows relies heavily on named pipes for exchanging structured data between local services, administrative tools, and user-space applications. Because named pipes function across session boundaries and provide network accessibility via SMB, they represent a persistent target for adversaries seeking local privilege escalation (LPE), lateral movement, and defense evasion. New defensive […]
Grok AI Exfiltrates Private User Data When Attackers Encrypt Malicious Instructions
Security researchers have demonstrated a significant vulnerability in xAI’s Grok chatbot that allows external attackers to exfiltrate private conversation history. The attack relies on an indirect prompt injection technique that encrypts malicious instructions on a webpage, evading automated guardrail scanners until Grok itself decrypts and executes the payload during normal browsing and summarization tasks. How […]
SynkLoader Malware Uses Microsoft Teams Phishing and Fake Lock Screens to Infiltrate Corporate Networks
A previously undocumented malware family named SynkLoader has surfaced in targeted social engineering campaigns across corporate Microsoft Teams environments. Discovered by security researchers at Expel, the attack chain begins with direct messages from external Microsoft 365 tenants impersonating internal IT helpdesk staff and culminates in a fake Windows lock screen designed to capture domain passwords. […]
CISA Warns of In-the-Wild Exploits Targeting Critical MLflow SSRF Vulnerability
The Cybersecurity and Infrastructure Security Agency added a critical vulnerability in the open-source machine learning platform MLflow to its Known Exploited Vulnerabilities catalog after telemetry confirmed attackers are actively scanning and compromising exposed instances. The flaw, tracked as CVE-2026-64849, allows unauthenticated remote attackers to trigger server-side request forgery requests from vulnerable MLflow servers to internal […]
SafePal Data Breach Exposed Customer Records, But Not the Keys That Matter
SafePal, the cryptocurrency hardware wallet provider, confirmed a data breach that exposed personally identifiable information for roughly 39,798 customers. The good news, and it is genuinely reassuring: wallet seed phrases, private keys, passwords, and financial account data were not part of what leaked. The company states no evidence exists that the incident compromised access to […]
SAP Commerce Cloud CVE-2026-58231: a 10.0 RCE already under attack
SAP’s max-severity Commerce Cloud RCE, CVE-2026-58231, is being exploited within days of the patch. What it is and what to do now.
Critical VMware vCenter RCE exploited via reverse SSH
A critical remote code execution vulnerability in VMware vCenter’s Syslog Server is under active exploitation right now. Tracked as CVE-2026-59310, the flaw carries a CVSS 3.1 score of 9.8 and is being used in a live campaign that drops an open source reverse SSH tool onto compromised hosts for persistence and remote access. If you […]
Cisco ClamAV flaws with public exploits leave a detection gap
Cisco has warned about a batch of vulnerabilities in the ClamAV engine that ships inside its Secure Endpoint Connector. Seven flaws, disclosed on August 7, all let an unauthenticated remote attacker crash the malware scanner by feeding it a crafted file. Two of them already have public proof-of-concept code, which is why the advisory is […]
Critical LoadMaster Command Injection Is Under Active Attack, Patch Now
If you run Progress LoadMaster (or the Kemp-branded versions of it), this is a patch-this-week story, not a note-for-later story. CISA has confirmed that a critical command injection vulnerability in the load balancer is being actively exploited in the wild, and the agency has added it to the Known Exploited Vulnerabilities catalog. That KEV listing […]
Mythos Attack Breaks a Post-Quantum Crypto Candidate, and the Lesson Is Uneasy
Late last month a team of cryptographers took a post-quantum signature scheme out of contention before it ever shipped, and they did it with an attack that left the research community quietly reassessing how much trust to place in the standards pipeline. The scheme was HAWK, a lattice-based digital signature candidate that had made it […]
TrueConf Servers Hijacked to Push Backdoored Installers
Video conferencing vendor TrueConf has confirmed a supply chain attack in which hackers hijacked servers and swapped legitimate client installers for backdoored versions. The intrusions, attributed by Kaspersky to the hacktivist group Head Mare, targeted unpatched TrueConf servers and used them to hand malicious software to anyone who downloaded the client. The attack is a […]
Januscape: The 16-Year-Old KVM Flaw That Earned a $250K Bounty
Google handed out $250,000 for a Linux kernel vulnerability that had been hiding in plain sight for 16 years. Named Januscape and tracked as CVE-2026-53359, the flaw is a use-after-free bug in the KVM hypervisor’s shadow MMU code. It lets a guest virtual machine escape to the host, and it is the first KVM exploit […]