Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)

03/06/2026 0 Comments 0 tags

Redis has patched a use-after-free in its blocking-client code that lets an authenticated user run arbitrary OS commands on the machine hosting the database. The flaw was found by an

Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag

03/06/2026 0 Comments 0 tags

A development flag left switched on in production builds of several Microsoft 365 Android apps disabled the check that limits account-token sharing to trusted Microsoft apps. Any other app on

Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT

03/06/2026 0 Comments 0 tags

Cybersecurity researchers have flagged a new malspam campaign that makes use of Google’s DoubleClick domain as a way to evade detection and ultimately deliver a remote access trojan (RAT) named

WhatsApp, Slack Notifications Could Hijack Google Gemini on Android

03/06/2026 0 Comments 0 tags

A single poisoned notification from WhatsApp, Slack, SMS, Signal, Instagram, or Messenger could have hijacked Google Gemini’s voice assistant on Android and made it open a victim’s connected windows, fake

One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens

03/06/2026 0 Comments 0 tags

Cybersecurity researchers have disclosed a one-click attack via Microsoft Visual Studio Code (VS Code) that makes it possible to steal a user’s GitHub token. “Just by clicking a link, it’s

Beyond the Zero-Day: See Your Network Like an Attacker | Webinar with HD Moore

03/06/2026 0 Comments 0 tags

Assume the breach. Zero-days keep shipping, AI is writing exploits faster than anyone patches, and “patch everything in time” stopped working years ago. Stop betting the org on winning that

Shrinking the IAM Attack Surface through Identity Visibility and Intelligence Platforms (IVIP)

03/06/2026 0 Comments 0 tags

The Fragmented State of Modern Enterprise Identity Enterprise IAM is approaching a breaking point. As organizations scale, identity becomes increasingly fragmented across thousands of applications, decentralized teams, machine identities, and

New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare

03/06/2026 0 Comments 0 tags

Cybersecurity researchers have discovered a remote denial-of-service exploit that affects major web servers, including NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora. The vulnerability has been codenamed HTTP/2 Bomb

Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes

03/06/2026 0 Comments 0 tags

Cybersecurity researchers have disclosed details of an unpatched issue that could be exploited to disclose a user’s NTLMv2 hash to the attacker. Like in the case of CVE-2026-33829, which impacted

Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content

03/06/2026 0 Comments 0 tags

Cybersecurity researchers have flagged a new campaign targeting Minecraft players via YouTube to spread malware capable of gaining control of victims’ systems. The Minecraft-focused malware-as-a-service (MaaS) campaign has been codenamed