Cyber Security

Cyber Security
Cyber Security

New Windows Defender 0-Day Exploit RoguePlanet Grants SYSTEM Access to Attackers

new-windows-defender-0-day-exploit-rogueplanet-grants-system-access-to-attackers

A researcher known as Nightmare Eclipse (also tracked as Chaotic Eclipse or Dead Eclipse) has publicly released a new proof-of-concept (PoC) exploit named RoguePlanet, targeting a previously undisclosed race condition vulnerability in Microsoft Windows Defender. When successfully executed, the exploit spawns a command shell running under SYSTEM-level privileges, granting an attacker the highest possible access […]

New MagicAd Android Malware Flood Device With Ads Bypassing Restrictions

new-magicad-android-malware-flood-device-with-ads-bypassing-restrictions

A newly discovered Android trojan called MagicAd has been found flooding infected devices with ads, cleverly slipping past the built-in restrictions of the Android operating system. What makes this threat stand out is not just what it does, but how it does it. It uses multiple techniques to keep showing ads in the background, even […]

Apache HTTP Server 2.4.68 Released With Fix For Use-After-Free, DoS, XSS, and Buffer Overflow Flaws

apache-http-server-24.68-released-with-fix-for-use-after-free,-dos,-xss,-and-buffer-overflow-flaws

The Apache Software Foundation released Apache HTTP Server version 2.4.68 on June 8, 2026, addressing 13 security vulnerabilities spanning multiple modules. The patched flaws include use-after-free conditions, cross-site scripting, heap-based buffer overflows, denial-of-service, privilege escalation, and out-of-bounds read issues affecting all versions from 2.4.0 through 2.4.67. Administrators running any prior release are strongly urged to […]

OWASP Releases AI Security Report to Empower Security Professionals with New Tools

owasp-releases-ai-security-report-to-empower-security-professionals-with-new-tools

OWASP has released the “State of Agentic AI Security and Governance v2.01” report, a technical blueprint aimed at security teams racing to secure rapidly proliferating autonomous AI agents in production. The report, part of the OWASP GenAI Security Project’s Agentic Security Initiative, reframes AI security as an operational reality rather than a theoretical concern, backed […]

Hackers Can Hijack Claude Code MCP Traffic to Steal OAuth Tokens

hackers-can-hijack-claude-code-mcp-traffic-to-steal-oauth-tokens

A five-step attack chain that silently redirects Claude Code’s Model Context Protocol (MCP) traffic through attacker-controlled infrastructure, intercepting OAuth bearer tokens that grant persistent, broadly scoped access to connected SaaS platforms like Jira, Confluence, and GitHub with no patch incoming from Anthropic. Researchers at Mitiga Labs have demonstrated the attack, with the entry point being […]

New EDRChoker Tool Uses Policy-Based Quality of Service to Block EDR Processes

new-edrchoker-tool-uses-policy-based-quality-of-service-to-block-edr-processes

A newly released open-source red team tool called EDRChoker introduces a novel technique for silencing cloud-connected Endpoint Detection and Response (EDR) agents not by killing their processes or injecting code, but by quietly choking their network bandwidth to near-zero using Windows’ native Policy-Based Quality of Service (QoS) engine. Developed by security researcher @TwoSevenOneT, the tool exploits Windows […]

Instagram Fixes Password Reset Flaw That Exposes User Emails and Phone Numbers

instagram-fixes-password-reset-flaw-that-exposes-user-emails-and-phone-numbers

A critical logic bug in Instagram’s web-based password reset flow on June 6, 2026, exposed unredacted email addresses and phone numbers associated with user accounts, including those belonging to high-profile individuals such as Meta CEO Mark Zuckerberg and model Georgina Rodriguez. Instagram’s parent company Meta deployed an emergency hotfix within hours of the disclosure, but […]

CISA Warns of Linux Kernel Improper Authentication Vulnerability Exploited in Attacks

cisa-warns-of-linux-kernel-improper-authentication-vulnerability-exploited-in-attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Linux kernel vulnerability, tracked as CVE-2022-0492, to its Known Exploited Vulnerabilities (KEV) catalog, warning that the flaw is being actively leveraged in real-world attacks. The issue, categorized as improper authentication, affects Linux systems using the cgroups v1 release_agent feature and may allow attackers […]