Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday

15/07/2026 0 Comments 0 tags

Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive. It has been described as a Windows User Profile Service arbitrary hive load elevation of

New Webinar: Closing the Approval Gap in AI-Era Ad Tech

15/07/2026 0 Comments 0 tags

A single approved marketing tag can quietly load fourth-party code your security team has never seen, granting full access to your forms, customer data, and checkout pages. This on-demand webinar

SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough.

15/07/2026 0 Comments 0 tags

For years, routing traffic through cloud proxies was good enough. Then work moved to the browser, AI entered the workflow, and the inspection model stopped keeping up. Enterprise workflows now

Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution

15/07/2026 0 Comments 0 tags

Open a repository in Cursor on Windows and, if a file named git.exe is sitting in the project root, Cursor runs it. No click, no approval dialog, no warning that anything in the

Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware

15/07/2026 0 Comments 0 tags

Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security, SafeDep, Socket, and StepSecurity. The affected packages are

Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands

15/07/2026 0 Comments 0 tags

SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution. The

Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack

14/07/2026 0 Comments 0 tags

Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release covers 622 of Microsoft’s own CVEs by

SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data

14/07/2026 0 Comments 0 tags

SAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver Application Server ABAP. The vulnerability in

Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads

14/07/2026 0 Comments 0 tags

Any other browser extension that can run a script on claude.ai can still trigger Claude for Chrome tasks aimed at your Gmail, your latest Google Doc and its comments, and

LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts

14/07/2026 0 Comments 0 tags

Cybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that masquerades as NVIDIA software to blend into target environments. “LabubaRAT creates a reusable foothold for