Certighost and the Privilege Hiding in Your Certificate Authority

A recently disclosed vulnerability in Microsoft’s Active Directory Certificate Services has exposed a hidden privilege that can be exploited to gain control over an entire domain. The flaw, tracked as CVE-2026-54121, is known as Certighost and it allows an attacker to coerce a Certification Authority (CA) into issuing a valid authentication certificate for a Domain … Read more

Microsoft confirms GitHub is down worldwide

GitHub’s Global Outage Leaves Developers Reeling A massive disruption is affecting developers worldwide as GitHub, a popular platform for collaboration and version control, has gone dark. The outage, which began early on August 17th, has crippled various services, including API Requests, Actions, Webhooks, Issues, and Pull Requests, leaving many users unable to access their projects. … Read more

Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

A Critical Vulnerability in Unisoc’s VoLTE Technology Exposes Android Devices to Kernel Access Attacks A devastating exploit chain has been discovered in Unisoc’s Voice over LTE (VoLTE) technology, which is used by numerous Android device manufacturers worldwide. The vulnerability allows attackers to gain full access to the Android kernel, essentially giving them free rein to … Read more

How MCP Servers Can Expose Enterprise Secrets

A newly discovered vulnerability in MCP servers is allowing hackers to gain access to sensitive enterprise data, putting thousands of organizations worldwide at risk. The issue, which affects a broad range of businesses and industries, stems from the way MCP systems handle identity exposure, creating an open door for attackers to exploit. The problem arises … Read more

⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More

Security experts are sounding the alarm over a concerning trend: identity exposure is being used as a key enabler for active attack paths. What this means in plain terms is that hackers are exploiting vulnerabilities in how companies manage user identities, effectively creating backdoors into networks and systems. This can happen even when robust security … Read more

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

A suspected China-nexus cyber actor has been linked to a series of high-profile attacks that exploit a critical vulnerability in VMware vCenter, leading to the deployment of Babuk-derived ransomware on compromised systems. The attacks have affected multiple organizations across various industries, with some reports indicating that sensitive data has already been exfiltrated. The vulnerability in … Read more

Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

A sophisticated Linux botnet, dubbed Evooo1Bot, has been discovered exploiting known vulnerabilities to hijack edge devices and turn them into SOCKS5 proxies. This malicious network is capable of bypassing traditional security measures and could be used for a wide range of nefarious activities, from data exfiltration to DDoS attacks. Evooo1Bot specifically targets Linux-based systems, including … Read more

Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

A critical vulnerability has been discovered in the VoLTE (Voice over LTE) implementation of Unisoc’s Android-based chipsets, allowing attackers to gain full kernel access and potentially seize control of affected devices. This exploit chain, which affects a wide range of devices, has significant implications for users’ security and privacy. The vulnerability, revealed by researchers, lies … Read more

How MCP Servers Can Expose Enterprise Secrets

A recent investigation has revealed that a significant number of enterprise organizations are unwittingly exposing sensitive information and creating potential attack paths through their Microsoft Clustered Server (MCS) environments. What’s particularly concerning is that this vulnerability can be exploited without requiring any prior access to the network or systems, making it an attractive target for … Read more