~ / security

Security News.

Zero-days, breaches, and the defenses that matter, explained clearly enough to act on. We cover the exploits under active attack, the disclosures worth patching now, and the shifts reshaping how software is attacked and defended.

93 articles
EU Parliament Fast-Tracks Chat Control in 331-304 Vote, Security explainer Security

EU Parliament Fast-Tracks Chat Control in 331-304 Vote

The EU Parliament narrowly approved an urgency motion, 331 to 304, on July 7 to fast-track reviving Chat Control message scanning, setting up a decisive vote on Thursday.

Kore D · 2026-07-07 · 7 min read
Januscape: a 16-Year KVM Bug Escapes Guest to Host, Security explainer Security

Januscape: a 16-Year KVM Bug Escapes Guest to Host

Januscape (CVE-2026-53359) is a use-after-free in Linux KVM's shadow MMU that lets a guest VM corrupt host kernel memory, the first guest-to-host escape triggerable on both Intel and AMD.

Kore D · 2026-07-07 · 6 min read
A Windows Device ID Unmasked a Hacker Behind a VPN, Security explainer Security

A Windows Device ID Unmasked a Hacker Behind a VPN

A persistent Windows Global Device Identifier, generated at install and impossible to turn off, let the FBI unmask an alleged Scattered Spider hacker who hid behind a VPN and an ngrok tunnel. Microsoft telemetry tied his device to the attack, then to his personal Apple, Snapchat, and Facebook logins.

Kore D · 2026-07-07 · 7 min read
SimpleHelp Auth-Bypass Flaw Threatens MSPs at CVSS 10, Security explainer Security

SimpleHelp Auth-Bypass Flaw Threatens MSPs at CVSS 10

A maximum-severity flaw in SimpleHelp remote-support software, CVE-2026-48558 (CVSS 10.0), lets an unauthenticated attacker forge an identity token and take over a technician session, a supply-chain risk that could cascade from one managed service provider to all its clients.

Kore D · 2026-07-07 · 5 min read
Bad Epoll Flaw Hands Local Root on Most Linux Systems, Security explainer Security

Bad Epoll Flaw Hands Local Root on Most Linux Systems

A newly disclosed Linux kernel flaw, CVE-2026-46242 in the epoll subsystem, lets any unprivileged local user escalate to root across desktops, servers, and Android. A fix is out, and patching is the only real mitigation.

Kore D · 2026-07-06 · 6 min read
FatFs Flaws Let a Rigged USB Take Over IoT Devices, Security explainer Security

FatFs Flaws Let a Rigged USB Take Over IoT Devices

Researchers at runZero disclosed seven vulnerabilities in FatFs, a tiny filesystem library baked into the firmware of cameras, drones, industrial controllers, and hardware crypto wallets, where a booby-trapped USB drive or SD card can corrupt memory and run attacker code.

Kore D · 2026-07-06 · 6 min read
Kemp LoadMaster Bug (CVSS 9.6) Under Active Attack, Security explainer Security

Kemp LoadMaster Bug (CVSS 9.6) Under Active Attack

A critical command-injection flaw in Progress Kemp LoadMaster, CVE-2026-8037 (CVSS 9.6), is being actively exploited to run arbitrary OS commands on internet-facing load balancers, with attacks observed from June 29.

Kore D · 2026-07-06 · 5 min read
SharePoint RCE Flaw Is Under Active Attack, CISA Warns, Security explainer Security

SharePoint RCE Flaw Is Under Active Attack, CISA Warns

CISA added a high-severity Microsoft SharePoint Server flaw, CVE-2026-45659, to its Known Exploited Vulnerabilities catalog on July 2 after confirming active exploitation. The bug is a remote-code-execution hole from unsafe deserialization, patched in May, and every on-prem SharePoint server that skipped that update is exposed.

Kore D · 2026-07-05 · 6 min read
KDDI Breach Exposes 14M Users, Passwords in Plaintext, Security explainer Security

KDDI Breach Exposes 14M Users, Passwords in Plaintext

KDDI disclosed a breach of its email platform that may have exposed up to 14.22 million customers across six ISPs, and admitted only some passwords were hashed, meaning others sat in plaintext. Shared infrastructure widened the blast radius and weak storage turned it into a credential dump.

Kore D · 2026-07-05 · 7 min read
DirtyClone Hands Local Root on Default Linux Systems, Security explainer Security

DirtyClone Hands Local Root on Default Linux Systems

DirtyClone (CVE-2026-43503) is a Linux kernel flaw that lets any local user escalate to root by cloning network packets, and it works on default Debian, Ubuntu, and Fedora installs with standard namespace configurations.

Kore D · 2026-07-04 · 6 min read
Oracle PeopleSoft zero-day hit 100+ orgs, breached Nissan, Security explainer Security

Oracle PeopleSoft zero-day hit 100+ orgs, breached Nissan

A CVSS 9.8 zero-day in Oracle PeopleSoft (CVE-2026-35273) let the ShinyHunters extortion crew take over 300+ servers at 100+ organizations before Oracle's June 10 emergency patch. The unauthenticated SSRF-to-RCE flaw exposed employee Social Security and banking data at Nissan and hit dozens of universities.

Kore D · 2026-07-04 · 7 min read
SharePoint RCE Flaw Lands on CISA's Exploited List, Security explainer Security

SharePoint RCE Flaw Lands on CISA's Exploited List

CISA added CVE-2026-45659, a CVSS 8.8 remote code execution flaw in Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalog after confirming active attacks. Any authenticated user can trigger it, with no admin privileges required.

Kore D · 2026-07-03 · 6 min read
AirDrop and Quick Share Flaws Expose Billions of Phones, Security explainer Security

AirDrop and Quick Share Flaws Expose Billions of Phones

Researchers at CISPA disclosed six vulnerabilities in Apple AirDrop and Google and Samsung Quick Share on June 30, 2026, letting an attacker within wireless range crash nearby devices with no pairing or user tap, though the flaws cause denial of service rather than data theft or code execution.

Kore D · 2026-07-03 · 6 min read
Kemp LoadMaster Pre-Auth RCE Is Now Under Active Attack, Security explainer Security

Kemp LoadMaster Pre-Auth RCE Is Now Under Active Attack

CVE-2026-8037 is a pre-authentication remote code execution flaw in Progress Kemp LoadMaster, rated up to CVSS 9.8, that lets an unauthenticated attacker run system commands on the load balancer. Exploitation attempts began June 29, 2026, the same day a public proof-of-concept dropped. Patch now if the API is enabled.

Kore D · 2026-07-02 · 7 min read
DuneSlide Turns a Cursor Prompt Into Full Code Execution, Security explainer Security

DuneSlide Turns a Cursor Prompt Into Full Code Execution

Cato AI Labs disclosed DuneSlide, two 9.8-severity flaws (CVE-2026-50548 and CVE-2026-50549) that let a poisoned web page or MCP response escape Cursor's AI sandbox and run any command on a developer's machine, no click required.

Kore D · 2026-07-02 · 8 min read
A PraisonAI Flaw Was Exploited Within Hours of Disclosure, Security explainer Security

A PraisonAI Flaw Was Exploited Within Hours of Disclosure

Attackers began hitting the PraisonAI authentication-bypass flaw, CVE-2026-44338, less than four hours after it was publicly disclosed, because a legacy Flask API server shipped with authentication disabled by default.

Kore D · 2026-07-01 · 5 min read
A 9.8 Oracle E-Business Suite Flaw Is Under Active Attack, Security explainer Security

A 9.8 Oracle E-Business Suite Flaw Is Under Active Attack

CVE-2026-46817, a 9.8-severity unauthenticated takeover flaw in Oracle E-Business Suite's Payments module, is being exploited in the wild, first seen June 27, 2026, six weeks after a patch and before any public exploit existed.

Kore D · 2026-07-01 · 5 min read
BlueHammer Defender Zero-Day Hit SYSTEM in the Wild, Security explainer Security

BlueHammer Defender Zero-Day Hit SYSTEM in the Wild

CVE-2026-33825, nicknamed BlueHammer, is a Microsoft Defender flaw that let a low-privileged attacker win SYSTEM by racing Defender's own rollback engine; it was exploited in the wild and later tied to ransomware.

Kore D · 2026-07-01 · 6 min read
FortiBleed Exposed Credentials for 86,000 Fortinet Firewalls, Security explainer Security

FortiBleed Exposed Credentials for 86,000 Fortinet Firewalls

FortiBleed leaked working admin credentials for roughly 86,000 internet-facing Fortinet firewalls across 194 countries. Because it exploits no software bug, there is nothing to patch: every affected organization must treat its credentials as compromised.

Kore D · 2026-06-30 · 6 min read
A Cisco Zero-Day Was Exploited for Two Months Before Anyone Knew, Security explainer Security

A Cisco Zero-Day Was Exploited for Two Months Before Anyone Knew

Mandiant found that CVE-2026-20245, a high-severity Cisco Catalyst SD-WAN flaw, was exploited as a zero-day at least two months before Cisco disclosed it on June 4, 2026. Patches began rolling out June 10, after attackers already had a long head start.

Kore D · 2026-06-30 · 5 min read
Microsoft Just Shipped Its Largest Patch Tuesday Ever, and That Is Not Good News, Security explainer Security

Microsoft Just Shipped Its Largest Patch Tuesday Ever, and That Is Not Good News

June 2026 was the most patch-dense month in Microsoft history: 200 vulnerabilities in one Patch Tuesday, including six zero-days. A record like this is a symptom, not an achievement.

Kore D · 2026-06-29 · 6 min read
A Self-Spreading Worm Is Eating the Open-Source Supply Chain. Its Name Is Shai-Hulud., Security explainer Security

A Self-Spreading Worm Is Eating the Open-Source Supply Chain. Its Name Is Shai-Hulud.

A self-propagating worm has compromised over 100 npm and PyPI packages in a single June wave, stealing developer credentials and using them to infect more packages. The source code is now public, and clones have arrived.

Kore D · 2026-06-28 · 6 min read
An Anonymous Account Is Dumping Zero-Days Into the Open. That Should Worry Everyone., Security explainer Security

An Anonymous Account Is Dumping Zero-Days Into the Open. That Should Worry Everyone.

An anonymous GitHub account is mass-publishing working exploits for flaws vendors never got to patch. It is a direct attack on the fragile bargain that keeps software security from becoming a free-for-all.

Kore D · 2026-06-28 · 5 min read
Passkeys Are Killing the Password, Finally, Security explainer Security

Passkeys Are Killing the Password, Finally

After decades of failed attempts to replace the password, a standard called passkeys is actually gaining ground. The reason is that it removes the part humans get wrong.

Kore D · 2026-06-27 · 5 min read
Why 'Zero Trust' Is More Than a Buzzword, Security explainer Security

Why 'Zero Trust' Is More Than a Buzzword

The phrase gets stamped on every security product, which makes it easy to dismiss. The idea underneath is a genuine and overdue shift in how networks are defended.

Kore D · 2026-06-27 · 5 min read
The Supply-Chain Attack Problem No One Has Solved, Security explainer Security

The Supply-Chain Attack Problem No One Has Solved

You can lock down your own code perfectly and still get breached, through a dependency you trusted. It's modern software's most uncomfortable weakness.

Kore D · 2026-06-27 · 5 min read
Ransomware Became a Business. Here's the Model., Security explainer Security

Ransomware Became a Business. Here's the Model.

The image of a lone hacker in a hoodie is badly out of date. Ransomware now runs on org charts, customer support, and affiliate programs.

Kore D · 2026-06-27 · 5 min read
Stop Reusing Passwords, Here's the Real Risk, Security explainer Security

Stop Reusing Passwords, Here's the Real Risk

Reusing one good password across sites feels safe because the password is strong. The danger isn't the password's strength. It's what happens when any one site is breached.

Kore D · 2026-06-27 · 4 min read
End-to-End Encryption, Without the Hype, Security explainer Security

End-to-End Encryption, Without the Hype

It's the feature privacy advocates demand and some governments want to weaken. Strip away the politics and end-to-end encryption is a simple, powerful idea.

Kore D · 2026-06-27 · 5 min read
Two-Factor Authentication: Not All Methods Are Equal, Security explainer Security

Two-Factor Authentication: Not All Methods Are Equal

Turning on two-factor authentication is one of the best security moves you can make. But the method you choose matters more than most people realize.

Kore D · 2026-06-27 · 4 min read