Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

Tech Insider
tech-insider.org

PaperCut AI Swarm Attack Breaches 395 Orgs [2026]

1+ day, 5+ hour ago   (416+ words) Silverfort frames the incident as a warning specifically about identity security. Its analysis argues that automated, AI-driven credential harvesting and lateral movement can escalate to domain-admin control far faster than most organizations’ detection and response processes are built to handle,…...

Tech Insider
tech-insider.org

FudModule Rootkit Hides 5 Weeks via CVE-2026-68820

1+ day, 11+ hour ago   (300+ words) Lazarus has steadily upgraded FudModule’s delivery mechanism over four years, and the trajectory tells its own story about how APT groups adapt to defender countermeasures. FudModule is the most documented example of an “EDR-killer” rootkit, but it sits inside a…...

Forkast
forkast.news > the-chain-that-opened-the-crisis-how-sonicwall-sma1000s-first-zero-day-turned-vpn-appliances-into-mfa-harvesting-machines

The Chain That Opened the Crisis: How SonicWall SMA1000’s First Zero-Day Turned VPN Appliances Into MFA Harvesting Machines

1+ day, 4+ hour ago   (129+ words) CVE-2026-15409 chained SSRF and code injection to achieve root on SMA1000 appliances, stealing TOTP MFA seeds and turning the VPN gateway into a persistent surveillance platform. CISA flagged it for ransomware exploitation. We covered the second chain but never the first…...

4sysops
4sysops.com > archives > dutch-ncsc-says-check-point-vpn-flaw-exploitation-is-imminent

Dutch NCSC says Check Point VPN flaw exploitation is imminent – 4sysops

1+ day, 20+ hour ago   (25+ words) The Dutch NCSC now expects attackers to target two critical Check Point VPN flaws soon, despite no public proof-of-concept exploit. The warning raises the urgen...

SecurityWeek
securityweek.com > bluemoon-exploit-kit-chains-recent-chrome-windows-zero-days

BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

3+ day, 3+ hour ago   (602+ words) Multiple espionage groups have been using a new exploit kit dubbed BlueMoon in seemingly opportunistic and rushed deployments, cybersecurity firm Proofpoint reports. The China-linked APT Violet Typhoon (also tracked as APT31, JungleBamboo, TA412, and Tide Castle) was the first to use it…...

DEV Community
dev.to > sarthakagrawal927 > memory64-moved-the-browser-ceiling-and-exposed-an-abi-gap-14o5

Memory64 moved the browser ceiling and exposed an ABI gap

2+ day, 10+ hour ago   (364+ words) A 32-bit WebAssembly heap put the browser playground near a 4 GB ceiling. With weights and AdamW state, that limited the fp32 model size to roughly 250 million parameters. Compiling the same C++ source with Memory64 and BigInt support changed the pointer width. One…...

Forkast
forkast.news > once-in-a-bluemoon-how-a-chrome-patch-gap-turned-three-v8-zero-days-into-an-espionage-kit

Once in a BlueMoon: How a Chrome Patch-Gap Turned Three V8 Zero-Days Into an Espionage Kit

2+ day, 12+ hour ago   (65+ words) Three V8 bugs, individually medium-severity, chain into SYSTEM-level access through the patch-gap window. Four espionage clusters adopted the kit within days. The structural shift: browser-based AI agents inherit the same attack surface. Heath Callahan Trust, Identity & Security All stories by Heath…...

Windows Report
windowsreport.com > bluemoon-exploit-kit-can-escape-chrome-and-elevate-windows-privileges

BlueMoon Exploit Kit Can Escape Chrome and Elevate Windows Privileges

3+ day, 6+ hour ago   (355+ words) Published on September 11, 2026 BlueMoon exploit kit chains Windows and Chrome zero-days in targeted attacks, giving cyber-espionage groups a way to execute code, escape Chrome’s sandbox, and gain elevated Windows privileges. Proofpoint observed attacks involving BlueMoon starting on August 28, 2026, while Volexity…...

CSO Online
csoonline.com > article > 4220939 > attackers-are-weaponizing-the-gap-between-chromium-fixes-and-chrome-patches.html

Attackers are weaponizing the gap between Chromium fixes and Chrome patches

3+ day, 13+ hour ago   (642+ words) A new exploit kit is revealing the perils of the “patch later” mentality. According to the Proofpoint Threat Research team, espionage-motivated threat actors are using a new malicious toolkit to chain together four separate Chrome browser and Microsoft Windows vulnerabilities…...

4sysops
4sysops.com > archives > check-point-rushes-fixes-for-two-cvss-9-8-quantum-vpn-certificate-rces

Check Point rushes fixes for two CVSS 9.8 Quantum VPN certificate RCEs – 4sysops

4+ day, 27+ min ago   (23+ words) Check Point has released same-day fixes for two CVSS 9.8 vulnerabilities in Quantum VPN certificate processing that could let unauthenticated remote attackers e...