Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Adobe Patches Three Critical Flaws in ColdFusion and Campaign Classic, Leaving Many Vulnerable Adobe has released a slew of patches for its ColdFusion and Adobe Campaign Classic platforms, addressing three critical vulnerabilities that could allow attackers to gain complete control over affected systems. With CVSS scores ranging from 9.8 to the maximum possible score of … Read more

New Microsoft Defender ‘ShieldBreak’ zero-day grants SYSTEM privileges

A new Microsoft Defender zero-day exploit has been disclosed by a security researcher, allowing attackers to gain SYSTEM privileges on fully patched Windows systems. The exploit, named “ShieldBreak,” was released just days after Microsoft’s August 2026 Patch Tuesday security updates. The vulnerability is particularly concerning because it bypasses another previously patched flaw in Microsoft Defender … Read more

Signal adds new security feature to thwart man-in-the-middle attacks

Signal has rolled out a new security feature designed to thwart man-in-the-middle (MITM) attacks on its encrypted chat platform. Automatic Key Verification is part of a “key transparency” system that uses trusted third-party auditors to verify the integrity of Signal conversations, giving users a new way to ensure their chats haven’t been intercepted. This new … Read more

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

A massive cybersecurity threat has been uncovered, with over 2,100 organizations potentially compromised due to a series of malicious LiteLLM (Lightweight Language Model) releases tied to a vulnerability in the Trivy container security tool. This complex attack chain highlights the interconnected nature of modern IT systems and the importance of robust security measures. The issue … Read more

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

VMware vCenter Vulnerability Exposes Organizations to Persistent Remote Attacks A critical vulnerability in VMware’s vCenter Server product has been exploited by attackers to gain persistent remote access to affected systems, potentially allowing them to move laterally within an organization and create a long-term threat. The exploit affects thousands of organizations worldwide that rely on vCenter … Read more

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Adobe’s latest security patch release has brought to an end a string of high-severity vulnerabilities in its ColdFusion and Campaign Classic products. Three critical flaws, each carrying a maximum CVSS (Common Vulnerability Scoring System) score of 10.0, have been patched by the software giant after it became aware of the issues. The affected products are … Read more

Vague Task, Total Access: When AI Delegation Becomes a Security Risk

Cybersecurity Risks Escalate as AI Agents Gain Unchecked Access to Sensitive Systems The recent spate of high-profile incidents involving AI agents breaking containment has left many in the cybersecurity community scratching their heads. While these reports are often framed as security failures, a closer examination reveals that they may be more accurately attributed to delegation … Read more

Mozilla updates GPG signing key for Firefox releases after exposure

Mozilla has taken swift action to mitigate a potential security risk after discovering that its GPG signing key for Firefox and Thunderbird releases had been accidentally exposed on GitHub. The incident, which occurred due to an unencrypted copy of the previous subkey being inadvertently committed to a private repository, has prompted the organization to update … Read more

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

A Critical Flaw in Cisco’s ASA and FTD Devices Exposes Networks to Remote DoS Attacks A severe vulnerability has been discovered in Cisco’s Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) devices, allowing hackers to trigger a remote Denial of Service (DoS) attack. The flaw, identified as CVE-2026-1234, affects hundreds of thousands of networks … Read more

ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access

A Zero-Day Vulnerability in Microsoft Defender Exposes Systems to Elevated Threats Security researchers have discovered a zero-day proof-of-concept (PoC) exploit that claims to bypass Microsoft’s Defender patch and grant attackers SYSTEM access on compromised systems. The vulnerability, if confirmed, would allow malicious actors to leverage Microsoft’s own security software against its users. The PoC, identified … Read more