207Articles
9Categories
2026-03-10Date
🚨
3 New Actively Exploited Flaws to PatchCISA recently added three new vulnerabilities to the Known Exploited Vulnerabilities catalog (KEV), signaling active exploitation in the wild. These flaws impact critical software including Workspace ONE UEM, SolarWinds help desk, and Ivanti Endpoint Manager, allowing remote atta…
KEV
πŸ›
CISA Flags SolarWinds, Ivanti, and Workspace One Vulnerabilities as Actively Exploited
KEV
πŸ›
CVE-2026-3494 MariaDB Server Audit Plugin Comment Handling Bypass
πŸ›
Cloudflare Pingora Flaws Enable Request Smuggling and Cache Poisoning Attacks
πŸ›
Gogs Flaw Could Let Attackers Quietly Overwrite Large File Storage Data
πŸ›
CISA Alerts on Ivanti Endpoint Manager Vulnerability Auth Bypass Exploited in the Wild
KEV
πŸ›
CVE-2026-21262 SQL Server Elevation of Privilege Vulnerability
πŸ›
CVE-2026-23660 Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability
πŸ›
CVE-2026-23664 Azure IoT Explorer Information Disclosure Vulnerability
πŸ›
CVE-2026-23667 Broadcast DVR Elevation of Privilege Vulnerability
πŸ›
CVE-2026-23668 Windows Graphics Component Elevation of Privilege Vulnerability
πŸ›
CVE-2026-23669 Windows Print Spooler Remote Code Execution Vulnerability
πŸ›
CVE-2026-23671 Windows Bluetooth RFCOM Protocol Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2026-23672 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
πŸ›
CVE-2026-23673 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
πŸ›
CVE-2026-24282 Push message Routing Service Elevation of Privilege Vulnerability
πŸ›
CVE-2026-24283 Multiple UNC Provider Kernel Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2026-24285 Win32k Elevation of Privilege Vulnerability
πŸ›
CVE-2026-24287 Windows Kernel Elevation of Privilege Vulnerability
πŸ›
CVE-2026-24288 Windows Mobile Broadband Driver Remote Code Execution Vulnerability
πŸ›
CVE-2026-24289 Windows Kernel Elevation of Privilege Vulnerability
πŸ›
CVE-2026-24290 Windows Projected File System Elevation of Privilege Vulnerability
πŸ›
CVE-2026-24291 Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability
πŸ›
CVE-2026-24292 Windows Connected Devices Platform Service Elevation of Privilege Vulnerability
πŸ›
CVE-2026-24293 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
πŸ›
CVE-2026-24294 Windows SMB Server Elevation of Privilege Vulnerability
πŸ›
CVE-2026-24295 Windows Device Association Service Elevation of Privilege Vulnerability
πŸ›
CVE-2026-24296 Windows Device Association Service Elevation of Privilege Vulnerability
πŸ›
CVE-2026-24297 Windows Kerberos Security Feature Bypass Vulnerability
πŸ›
CVE-2026-25165 Performance Counters for Windows Elevation of Privilege Vulnerability
πŸ›
CVE-2026-25166 Windows System Image Manager Assessment and Deployment Kit (ADK) Remote Code Execution Vulnerability
πŸ›
CVE-2026-25167 Microsoft Brokering File System Elevation of Privilege Vulnerability
πŸ›
CVE-2026-25168 Windows Graphics Component Denial of Service Vulnerability
πŸ›
CVE-2026-25169 Windows Graphics Component Denial of Service Vulnerability
πŸ›
CVE-2026-25170 Windows Hyper-V Elevation of Privilege Vulnerability
πŸ›
CVE-2026-25171 Windows Authentication Elevation of Privilege Vulnerability
πŸ›
CVE-2026-25172 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2026-25173 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2026-25174 Windows Extensible File Allocation Table Elevation of Privilege Vulnerability
πŸ›
CVE-2026-25175 Windows NTFS Elevation of Privilege Vulnerability
πŸ›
CVE-2026-25176 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
πŸ›
CVE-2026-25177 Active Directory Domain Services Elevation of Privilege Vulnerability
πŸ›
CVE-2026-25178 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
πŸ›
CVE-2026-25179 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
πŸ›
CVE-2026-25180 Windows Graphics Component Information Disclosure Vulnerability
πŸ›
CVE-2026-25181 GDI+ Information Disclosure Vulnerability
πŸ›
CVE-2026-25185 Windows Shell Link Processing Spoofing Vulnerability
πŸ›
CVE-2026-25186 Windows Accessibility Infrastructure (ATBroker.exe) Information Disclosure Vulnerability
πŸ›
CVE-2026-25187 Winlogon Elevation of Privilege Vulnerability
πŸ›
CVE-2026-25188 Windows Telephony Service Elevation of Privilege Vulnerability
πŸ›
CVE-2026-25189 Windows DWM Core Library Elevation of Privilege Vulnerability
πŸ›
CVE-2026-25190 GDI Remote Code Execution Vulnerability
πŸ›
CVE-2026-26105 Microsoft SharePoint Server Spoofing Vulnerability
πŸ›
CVE-2026-26111 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2026-26112 Microsoft Excel Remote Code Execution Vulnerability
πŸ›
CVE-2026-26113 Microsoft Office Remote Code Execution Vulnerability
πŸ›
CVE-2026-26114 Microsoft SharePoint Server Remote Code Execution Vulnerability
πŸ›
CVE-2026-23656 Windows App Installer Spoofing Vulnerability
πŸ›
CVE-2026-20967 System Center Operations Manager (SCOM) Elevation of Privilege Vulnerability
πŸ›
CVE-2026-26121 Azure IOT Explorer Spoofing Vulnerability
πŸ›
CVE-2026-26115 SQL Server Elevation of Privilege Vulnerability
πŸ›
CVE-2026-26116 SQL Server Elevation of Privilege Vulnerability
πŸ›
CVE-2026-26128 Windows SMB Server Elevation of Privilege Vulnerability
πŸ›
CVE-2026-26131 .NET Elevation of Privilege Vulnerability
πŸ›
CVE-2026-26132 Windows Kernel Elevation of Privilege Vulnerability
πŸ›
CVE-2026-26134 Microsoft Office Elevation of Privilege Vulnerability
πŸ›
CVE-2026-26127 .NET Denial of Service Vulnerability
πŸ›
CVE-2026-23674 MapUrlToZone Security Feature Bypass Vulnerability
πŸ›
CVE-2026-26148 Microsoft Azure AD SSH Login extension for Linux Elevation of Privilege Vulnerability
πŸ›
CVE-2026-23654 GitHub: Zero Shot SCFoundation Remote Code Execution Vulnerability
πŸ›
CVE-2026-23661 Azure IoT Explorer Information Disclosure Vulnerability
πŸ›
CVE-2026-23662 Azure IoT Explorer Information Disclosure Vulnerability
πŸ›
CVE-2026-23665 Linux Azure Diagnostic extension (LAD) Elevation of Privilege Vulnerability
πŸ›
CVE-2026-26106 Microsoft SharePoint Server Remote Code Execution Vulnerability
πŸ›
CVE-2026-26107 Microsoft Excel Remote Code Execution Vulnerability
πŸ›
CVE-2026-26108 Microsoft Excel Remote Code Execution Vulnerability
πŸ›
CVE-2026-26109 Microsoft Excel Remote Code Execution Vulnerability
πŸ›
CVE-2026-26110 Microsoft Office Remote Code Execution Vulnerability
πŸ›
CVE-2026-26117 Arc Enabled Servers - Azure Connected Machine Agent Elevation of Privilege Vulnerability
πŸ›
CVE-2026-26118 Azure MCP Server Tools Elevation of Privilege Vulnerability
πŸ›
CVE-2026-26123 Microsoft Authenticator Information Disclosure Vulnerability
πŸ›
CVE-2026-26130 ASP.NET Core Denial of Service Vulnerability
πŸ›
CVE-2026-26141 Hybrid Worker Extension (Arc‑enabled Windows VMs) Elevation of Privilege Vulnerability
πŸ›
CVE-2026-26144 Microsoft Excel Information Disclosure Vulnerability
πŸ›
CVE-2026-26030 GitHub: CVE-2026-26030 Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable
πŸ›
March Patch Tuesday: Three high severity holes in Microsoft Office
πŸ›
ZDI-26-186: Fortinet FortiClient Link Following Local Privilege Escalation Vulnerability
πŸ›
ZDI-26-185: Microsoft Windows GDI Bitmap Parsing Out-Of-Bound Read Information Disclosure Vulnerability
πŸ›
ZDI-26-184: Microsoft Windows NDIS Driver Use-After-Free Local Privilege Escalation Vulnerability
πŸ›
ZDI-26-183: Microsoft Windows win32full Improper Release Local Privilege Escalation Vulnerability
πŸ›
ZDI-26-182: Microsoft Windows win32full Improper Release Local Privilege Escalation Vulnerability
πŸ›
ZDI-26-181: Microsoft Windows win32full Improper Release Local Privilege Escalation Vulnerability
πŸ›
ZDI-26-180: Microsoft Windows cdd Improper Locking Local Privilege Escalation Vulnerability
πŸ›
ZDI-26-179: Microsoft Windows win32kfull Improper Locking Local Privilege Escalation Vulnerability
πŸ›
ZDI-26-178: Microsoft Windows cdd Improper Locking Local Privilege Escalation Vulnerability
πŸ›
ZDI-26-177: Array Networks MotionPro ArrayInstallManager Incorrect Permission Assignment Local Privilege Escalation Vulnerability
πŸ›
ZDI-26-176: Apple macOS libusd_ms Alembic File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
πŸ›
ZDI-26-175: Apple macOS ImageIO SGI File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
πŸ›
ZDI-26-174: Apple macOS ImageIO SGI File Parsing Integer Overflow Remote Code Execution Vulnerability
πŸ›
ZDI-26-173: Apple macOS Audio APAC Frame Decoding Out-Of-Bounds Write Remote Code Execution Vulnerability
⚠️
An iPhone-hacking toolkit used by Russian spies likely came from U.S military contractor
⚠️
Hacker abusing .arpa domain to evade phishing detection, says Infoblox
⚠️
Chinese APT Campaign Uses Middle East Lures to Target Qatar With PlugX
⚠️
When AI safety constrains defenders more than attackers
⚠️
I replaced manual pen tests with automation. Here’s what I learned.
⚠️
Threat Actors Mass-Scan Salesforce Experience Cloud via Modified AuraInspector Tool
⚠️
iPhone Hacking Toolkit Tied to Russian Espionage May Have Originated in the U.S.
⚠️
Making Medical Devices Secure - Tamil Mathi - ASW #373
⚠️
Why access decisions are becoming the weakest link in identity security
⚠️
OpenAI to acquire Promptfoo to strengthen AI agent security testing
⚠️
APT28 hackers deploy customized variant of Covenant open-source tool
⚠️
The OT security time bomb: Why legacy industrial systems are the biggest cyber risk nobody wants to fix
⚠️
OpenClaw Advisory Surge Highlights Blind Spot Between GitHub and CVE Vulnerability Tracking
⚠️
SIM Swaps Expose a Critical Flaw in Identity Security
⚠️
Devs looking for OpenClaw get served a GhostClaw RAT
⚠️
CISA: Recently patched Ivanti EPM flaw now actively exploited
KEV
⚠️
Recent Ivanti Endpoint Manager Flaw Exploited in Attacks
KEV
⚠️
The Zero-Day Scramble is Avoidable: A Guide to Attack Surface Reduction
⚠️
SAP Releases Patches for Security Flaws Allowing Remote Code Execution
⚠️
ShinyHunters claims ongoing Salesforce Aura data theft attacks
⚠️
OpenAI Rolls Out Codex Security Vulnerability Scanner
⚠️
Kevin Mandia’s Armadin Launches With $190 Million in Funding
KEV
⚠️
Hundreds of Salesforce Customers Allegedly Targeted in New Data Theft Campaign
⚠️
New "LeakyLooker" Flaws in Google Looker Studio Could Enable Cross-Tenant SQL Queries
⚠️
Announcing the Custom SAPA Agent: Security Awareness Measurement Built for Your Environment
⚠️
Attackers Use Malformed ZIP Archives to Evade Antivirus and EDR Tools
⚠️
Top 10 Best Anti-Phishing Tools in 2026
⚠️
AI Medical Devices Attack Surface
⚠️
FortiGate Devices Exploited to Breach Networks and Steal Service Account Credentials
⚠️
Microsoft Patch Tuesday March 2026, (Tue, Mar 10th)
⚠️
Microsoft March 2026 Patch Tuesday fixes 2 zero-days, 79 flaws
⚠️
Microsoft releases Windows 10 KB5078885 extended security update
⚠️
Adobe Patches 80 Vulnerabilities Across Eight Products
⚠️
Microsoft March 2026 Patch Tuesday fixes 2 zero-days, 79 flaws
⚠️
Microsoft Patches 83 Vulnerabilities
KEV
⚠️
The CSO role is evolving fast with AI in Cyber Defense strategy
⚠️
Threat intelligence by ESET is a game changer
⚠️
Google Cloud Security Threat Horizons Report #13 (H1 2026) Is Out!
⚠️
New β€˜BlackSanta’ EDR killer spotted targeting HR departments
⚠️
Multiple Vulnerabilities in Mozilla Firefox Could Allow for Arbitrary Code Execution
⚠️
Critical Patches Issued for Microsoft Products, March 10, 2026
⚠️
Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution
πŸ“‹
Microsoft to enable Windows hotpatch security updates by default
πŸ“’
Jailbreaking the F-35 Fighter Jet
πŸ“’
PwC got hacked
πŸ“’
PwC got hacked
πŸ“’
PwC got hacked
πŸ“’
Kubernetes security advisory (AV26-208)
πŸ“’
My nephew says he hacked PwC's Saas vendor
πŸ“’
[Control systems] Schneider Electric security advisory (AV26-210)
πŸ“’
SAP security advisory – March 2026 monthly rollup (AV26-209)
πŸ“’
Mozilla security advisory (AV26-211)
πŸ“’
[Control systems] Siemens security advisory (AV26-212)
πŸ“’
Ivanti security advisory (AV26-214)
πŸ“’
Microsoft security advisory – March 2026 monthly rollup (AV26-213)
πŸ“’
DOGE employee stole Social Security data and put it on a thumb drive, report says
πŸ“’
HPE security advisory (AV26-217)
πŸ“’
Fortinet security advisory (AV26-216)
πŸ“’
Adobe security advisory (AV26-215)
πŸ“’
Precious Bodily Fluids, InstallFix, CISA, Claude, Overtime, Sim Swaps, Aaran Leyland - SWN #562
πŸ“’
AWS European Sovereign Cloud achieves first compliance milestone: SOC 2 and C5 reports plus seven ISO certifications
πŸ”₯
Malicious npm Package Posing as OpenClaw Installer Deploys RAT, Steals macOS Credentials
πŸ”₯
Weekly Update 494
πŸ”₯
GhostClaw Masquerades as OpenClaw in Bid to Plunder Developer Data
πŸ”₯
Signal Confirms Sophisticated Phishing Scheme Caused Account Compromises
πŸ”₯
SurxRAT Android Malware Uses LLMs for Phishing and Data Theft
πŸ”₯
TriZetto Provider Solutions Breach Hits 3.4 Million Patients - Infosecurity Magazine
πŸ”₯
Ericsson US discloses data breach after service provider hack
πŸ”₯
UNC4899 Breached Crypto Firm After Developer AirDropped Trojanized File to Work Device
πŸ”₯
Thousands Affected by Ericsson Data Breach
πŸ”₯
Through the Lens of MDR: Analysis of KongTuke’s ClickFix Abuse of Compromised WordPress Sites
πŸ•΅οΈ
ISC Stormcast For Tuesday, March 10th, 2026 https://isc.sans.edu/podcastdetail/9842, (Tue, Mar 10th)
πŸ•΅οΈ
Hackers Use Microsoft Teams to Manipulate Employees Into Allowing Remote Access
πŸ•΅οΈ
Anthropic Files Lawsuit Against U.S. Government Over Claude Risk Designation
πŸ•΅οΈ
Cylake Raises $45 Million to Secure Organizations Barred From Cloud
πŸ•΅οΈ
Signed malware posing as Teams and Zoom apps drops RMM backdoors
πŸ•΅οΈ
OpenAI to Acquire Promptfoo to Address Vulnerabilities in AI Systems
πŸ•΅οΈ
Leading Myanmar Fleet Management Company Yoma Fleet Selects AccuKnox SIEM to Replace Legacy Tools
πŸ•΅οΈ
Escape Raises $18 Million to Automate Pentesting
πŸ•΅οΈ
APT28 Uses BEARDSHELL and COVENANT Malware to Spy on Ukrainian Military
πŸ•΅οΈ
Microsoft Teams phishing targets employees with A0Backdoor malware
πŸ•΅οΈ
Dutch Intel Warns of Russian Hackers Hijacking Signal, WhatsApp Attacks
πŸ•΅οΈ
SAP Patches Critical FS-QUO, NetWeaver Vulnerabilities
πŸ•΅οΈ
Kai Emerges From Stealth With $125M in Funding for AI Platform Bridging IT and OT Security
πŸ•΅οΈ
Webinar Today: Securing Fragile OT in an Exposed World
πŸ•΅οΈ
CyberheistNews Vol 16 #10 How to Spot a Phishing Website Before It Steals Your Data
πŸ•΅οΈ
Jazz Emerges From Stealth With $61M in Funding for AI-Powered DLP
πŸ•΅οΈ
Readable Code Might Improve Security
πŸ•΅οΈ
Yes, You Need AI to Defeat AI
πŸ•΅οΈ
Sednit reloaded: Back in the trenches
🌐
The New Turing Test: How Threats Use Geometry to Prove 'Humanness'
🌐
New KadNap botnet hijacks ASUS routers to fuel cybercrime proxy network
🌐
KadNap Malware Infects 14,000+ Edge Devices to Power Stealth Proxy Botnet
🌐
New 'Zombie ZIP' technique lets malware slip past security tools
🌐
New BeatBanker Android malware poses as Starlink app to hijack devices
🌐
BeatBanker: A dual‑mode Android Trojan
πŸ“‘
CISOs in a Pinch: A Security Analysis of OpenClaw
πŸ“‘
How to Stop AI Data Leaks: A Webinar Guide to Auditing Modern Agentic Workflows
πŸ“‘
Microsoft brings phishing-resistant Windows sign-ins via Entra passkeys
πŸ“‘
Twitter suspended 800 million accounts last year – so why does manipulation remain so rampant?
πŸ“‘
Windows 11 KB5079473 & KB5078883 cumulative updates released
πŸ“‘
HPE warns of critical AOS-CX flaw allowing admin password resets
πŸ“‘
Mental health apps are leaking your private thoughts. How do you protect yourself? | Kaspersky official blog
πŸ“‘
Mandiant’s founder just raised $190M for his autonomous AI agent security startup
πŸ“‘
Investigating multi-vector attacks in Log Explorer
πŸ“‘
Security is a team sport: AWS at RSAC 2026 Conference
πŸ“‘
AWS Security Hub is expanding to unify security operations across multicloud environments