A COM class that points at a DLL that does not exist is not harmless. Project Zero shows how a dangling registration in a writable path becomes SYSTEM, and how to audit your estate for the same pattern.
Rust maintainers are being lured onto video calls to install a fake audio codec or paste a command. The arrayref release of 20 August, downloaded 2,285 times in 86 minutes, shows why their accounts are the prize.
ChainScript turns a pasted Win+R command into a per-user MSI, a hidden Node.js agent and a C2 address stored on the Polygon blockchain. Here is the chain step by step, why the pointer survives takedown, and the controls that still work.
The same two Jade Sleet backdoors that helped take 292 million dollars from KelpDAO turned up on an Indian IT provider with no crypto ties. What the vendor established, what it did not, and what UK firms that outsource to Indian MSPs should ask this week.
TeamPCP stole more than 500,000 credentials but, by Google's estimate, made only tens of thousands of dollars. What an undercover analyst saw, what rests only on one researcher's account, and what UK engineering teams should change.
TASK#STOMP relies almost entirely on wscript, PowerShell, Task Scheduler and the .NET compiler, so it leaves no conventional executable to catch. It also leaves a script block log, a task creation event and an AMSI scan behind at every step. The report does not name a victim, sector or attacker.
Two GPOs, six settings, no Windows malware: how PAYLOAD used Group Policy for domain-wide extortion, what Kaspersky could not establish, and the Microsoft audit events that would have seen it.
The Clop defacement is confirmed at the presentation layer. The evidence does not yet establish server root, victim-data access or control of the onion identity.
A joint advisory of 18 September 2026 puts at least 30,000 exploited PCs and over 7,000 drained cryptocurrency wallets behind a fake recruitment campaign. The arithmetic says the access, not the crypto, was the product. No UK victim is named.
Fake GitHub organisations impersonating LastPass Authenticator ranked in search and delivered an infostealer behind a Microsoft signed driver that terminates 145 security products. The repositories are gone. Most of the delivery chain is not.
About 170 private CrowdSec repositories were cloned in nine minutes and four seconds on 22 May 2026, using the account of a developer who had just left. GitHub's own documentation explains why the organisation audit log was empty.
The forced theme install is real, the chain to code execution is real, and both run on an administrator's session. Here is what WordPress fixed, in which versions, and what its own release notes do not say.
Three Linux kernel CVEs entered CISA's KEV catalogue on 18 September 2026 and four others got public local root exploits the same day. No CVE appears on both lists, and the patch state differs sharply between them.
CVE-2026-58138 lets anyone who can reach an unpatched Conductor server run operating system commands on it. The open-source build has no authentication to bypass, and the orchestrator holds credentials for everything it orchestrates.
WeaselBiscuit executed on import rather than install, so the standard ignore-scripts control sat at the wrong gate. Every package is now gone from npm, median takedown under 13 hours. Here is what it could actually reach.
CVE-2026-91843 lets an unauthenticated attacker run code as root on Check Point Security Management, Multi-Domain and Log Servers. The advisory names eleven affected version bands and offers four packages. No exploitation is reported and one indicator is published.
CISA retires its weekly Vulnerability Bulletin on 28 September. We parsed 70 issues: it was a CVSS-sorted copy of CVE records, with no exploitation signal, long gaps and a "Not Yet Assigned" table that hid CVSS 10.0 exploited flaws.
KREMLIN copies an extension into Chrome and Edge, enables developer mode and regenerates the Secure Preferences integrity MACs so the browser loads it as approved. It changes what an ExtensionSettings allowlist can and cannot promise.
The Pixel modem zero-day is real and fixed at patch level 2026-09-05. The record names no targets, no attacker and no chain, and CISA's CVSS score moved from 8.0 to 8.8 within a day with nothing new from Google.
An unauthenticated root path into Cisco ISE and a local privilege escalation in Acronis's cPanel backup plugin entered KEV together. What each attacker needs first, what fixes it, and what the three-day clock means in the UK.
CVE-2026-76461 lets a crafted email run root commands on Cisco Secure Email Gateway. The KEV deadline is today. The upgrade closes the hole; it does not tell you whether the gateway, and the credentials it holds, were already taken.
Read from the joint advisory in full. A unique Telegram bot per victim removes the pivot defenders rely on, and the escalation to personal devices lands outside every control on the asset register.
A careful reading of Anthropic's targeting and conventional-weapons evaluations, including the 37 km geolocation result, simulated strike rates, limitations and practical controls.
Read from Microsoft's own CVRF. Nothing is publicly disclosed, the 1,170 figure is a month's accumulation, and the field to check is Customer Action Required.
Read from Adobe's own bulletin, the NVD record and CISA's catalogue. A fully patched store was still taken, and the catalogue has not moved since Friday.
MikroTrick, the indicators of compromise, and the methodology section almost nobody quoted. The vendor's own detection marker does not prove a device is clean, and CERT Polska say so.
The most consequential sentence in the IOS XR advisory is the one about how the flaws were found, and almost every write-up removed it. What follows from it is a counting problem.
A directive reported as reducing the patching burden coincides with the most aggressive tier becoming the default on three quarters of new entries. Two opposite errors are circulating about it.
AS62390 announced a Hetzner /24 for 33 hours, diverting Softaculous update traffic. Let's Encrypt issued a valid certificate because its own domain validation was routed through the hijack.
Exploit code for an unpatched local privilege escalation in CrowdStrike Falcon Sensor appeared at 02:48 UTC. The README contains two qualifications the coverage has dropped.
Kestra, LiteLLM and Starlette joined the KEV catalogue at 16:54 UTC with no coverage at all. All three were months old, and the titles misdescribe two of them.
Check Point Research documents Gambling Goblin compromising Brazilian government web servers since mid-2025. The module reverse-proxies three hardcoded prefixes and strips their Content-Security-Policy.
Read from the KEV feed and the NVD API on 2 September 2026: three loud exploitation claims, none catalogued, and a substitution trap where searching KEV by product name clears the wrong identifier.
Thirteen trojanised theme packages were pulled after Socket published. Checked by hand today: a sibling package Socket named as a sleeper is still installable, and the malicious jQuery is still on GitHub.
Kaspersky documents a recruitment lure whose README bans AI code review, declares the trojanised file bug-free, and ships a malicious package inside the archive so no scanner ever sees it.
CVE-2026-82329 lets an unauthenticated attacker reach admin on Artifactory. JFrog fixed it the same day it was published, its advisory misstates the 7.146 fix, and the exploitation claim rests on one firm.
ESET disclosed an inert comment block designed to make AI analysis refuse. The whole primary source is three posts on X, nobody tested it, and Endor Labs documented the same trick in June.
Every stage uses documented Windows behaviour, so there is no patch, no KEV deadline and no scanner finding. The controls that reach it had to be set before the lure arrived.
Black Hat 2026 research with four identifiers, one unpatched open-source path AWS has assigned to the customer, and the reason prompt hardening measured the wrong component.
Huntress documents the first Akira use of Safe Mode boot. The full technique chain contains no exploit at all, the encryptor starved of virtual memory and failed, and the victim is still extortable.
One million implant check-ins, more than 15 government webmail tenants watering-holed by a single script tag, and a supplier relationship the coverage flattened into one team.
Pass-ta-key, Silver and Golden: account takeover with no user interaction, forged biometric verification, and every synced key exported for resale. Why two outlets reached opposite conclusions from the same paper.
Check Point attributes the August zero-day to Lazarus. The exploit is fixed, but the delivery chain, a recruiter approach and an SEO-ranked impersonation site, is untouched and still works.
Counted from Microsoft's release document: 420 CVEs, 176 elevation of privilege, 119 in Office. Why the published totals disagree, and why severity-first triage gets this month wrong.
Initial access changed. The attack path did not. Half of ransomware victims with a credential leak saw it within 95 days of the attack, a window long enough to act in, if anyone is looking.