A Windows vulnerability allegedly patched in 2020 (CVE-2020-17103) can still be exploited on current systems for privilege escalation, and the exploit has been publicly released.
Pwn2Own Berlin 2026 concluded with $1.3 million in prize money and 47 zero-day vulnerabilities discovered, with Team DEVCORE winning $505,000 and Orange Tsai receiving the highest individual reward of $200,000 for a Microsoft Exchange exploitation.
Windows 11 KB5089549 aborts installation when the EFI System Partition has less than 10 MB free space and can be resolved through Known Issue Rollback or Group Policy configuration.
A working exploit now exists for the Linux vulnerability DirtyDecrypt (CVE-2026-31635), primarily affecting distributions like Fedora, Arch Linux, and openSUSE Tumbleweed; users should install kernel updates.
Four malicious npm packages from the same attacker distribute different malware: a DDoS botnet and infostealers, with one package cloning the newly published Shai-Hulud worm; users should immediately remove affected packages and reset their security credentials.
AI tools such as phishing-as-a-service and chatbots enable novices to commit fraud at scale, while organized crime groups can outsource technical aspects through them.
Fast16 malware was a pre-Stuxnet sabotage tool for manipulating nuclear weapons simulations, using 101 precise manipulation rules to sabotage high explosive simulations in LS-DYNA and AUTODYN, possibly developed from 2005 by the NSA-linked Equation Group.