Microsoft launches Cloud-Initiated Driver Recovery: a new feature enabling automatic rollback of faulty Windows drivers via Windows Update, becoming active from September 2026 and requiring no intervention from hardware partners or users.
Microsoft will update its Edge browser to stop loading stored passwords in memory at startup, following pressure from security researchers and customers, despite initially defending the practice.
The REMUS infostealer is operated like a professional software company, with continuous updates, customer-focused service, and scaling objectives; research shows that underground MaaS operations are adopting modern business practices to ensure persistence and revenue generation.
Two security vulnerabilities (CVE-2023-3153 and CVE-2026-4798) in the Avada Builder WordPress plugin enable attackers to read configuration files with database access credentials or extract password hashes via SQL injection.
Security researchers earn $385,750 at the Pwn2Own Berlin 2026 competition by disclosing 15 zero-day vulnerabilities in Windows 11 and Microsoft Exchange, with the prestigious hacking contest offering over one million dollars for successful exploits of fully patched systems.
The npm package node-ipc was compromised with credential-stealing malware; the tampered versions 9.1.6, 9.2.3, and 12.0.1 steal cloud credentials, SSH keys, and sensitive files via DNS exfiltration, likely due to a compromised maintainer account.
An unprotected security vulnerability in the Funnel Builder plugin for WordPress is being actively exploited to inject a payment card skimmer into WooCommerce checkout pages and steal credit card data and CVV codes.
The modernized Kazuar botnet uses a three-module system that minimizes external communication and obfuscates internal network communication to increase detection hurdles.
Microsoft is blocking CVE assignment for a CERT-confirmed Azure Backup vulnerability with privilege escalation potential, despite documentation suggesting a retroactive fix was applied.
The NGINX security vulnerability CVE-2026-42945 is already being actively exploited and enables worker process crashes or potentially remote code execution, with all NGINX versions from 0.6 being critically affected.
Imagine suddenly hearing your boss’s voice demanding an impromptu video call, with the familiar office, gestures, and tone in the background—but none of it is real.