Microsoft Defender Isolated a QNET Workstation in 128 Seconds
A Microsoft case study traces mshta execution to one isolated QNET host and shows which workstations qualify for the preview action.
Read article →Reader view
Choose the default article length.
Page 7 of 10
A Microsoft case study traces mshta execution to one isolated QNET host and shows which workstations qualify for the preview action.
Read article →A remote SCTP peer can trigger the kernel flaw, while Tencent separately demonstrated local privilege escalation and container escape. Defenders need both reachability and running-kernel checks.
Read article →Cisco's August IOS XE hardening release fixes seven vulnerability classes across five reviewed trains; affected devices need an upgrade.
Read article →An automated npm campaign uses hundreds of disposable packages to launch detached native malware, with DNS TXT records as a fallback delivery channel.
Read article →WordPress 7.0.3 fixes a pre-auth login-page XSS that can turn administrator interaction with a malicious site into PHP execution.
Read article →Remus uses an Ethereum smart contract to resolve changing command infrastructure before stealing browser sessions, credentials, and wallet data.
Read article →Code in a signed-in Windows session can invoke a TPM-backed Windows Hello for Business key, authenticate without a device identity claim, and create a path to durable Entra access.
Read article →BINDCLOAK collects Windows user and process tokens, duplicates them, and starts modular malware components inside more privileged security contexts.
Read article →SpecterOps shows how relayed WSUS machine-account access can forge targeted updates and bypass payload signature checks when SUSDB runs on a separate SQL Server.
Read article →CISA confirms exploitation of a TeamCity flaw that lets an unauthenticated network attacker run commands as the server process, putting secrets and build integrity at risk.
Read article →Langflow, N-central, and Tomcat flaws entered CISA's exploited catalog. One gives unauthenticated callers Python execution by default.
Read article →A targeted npm cluster split its downloader across ordinary-looking modules, then escaped Node.js vm isolation to install a cross-platform RAT on developer systems using Alibaba tools.
Read article →CVE-2026-41613 let crafted MCP install links persist settings that the VS Code preview did not show. Version 1.119.1 fixes the preview.
Read article →TP-Link TL-WR940N hardware revision 6 can let an unauthenticated attacker turn a LAN client's outbound RTSP session into code execution inside the router kernel.
Read article →Flare found that BTMOB's official operation now sits among resellers, source-code buyers, private servers, and offers of uncertain authenticity, weakening infrastructure-only detection.
Read article →The service preloads a payload-bearing PNG, copies a browser-specific command, and keys the final in-memory stage to the victim's public IP address.
Read article →