Install
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Droid ASC: A High-Performance Tool for Android Reverse Engineering and Vulnerability Discovery
5+ hour, 27+ min ago (309+ words) Article Summary: Droid ASC is a high-performance tool for Android reverse engineering and mobile... Tagged with android, cybersecurity, security, vulnerabilities....
BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days
1+ day, 15+ hour ago (602+ words) Multiple espionage groups have been using a new exploit kit dubbed BlueMoon in seemingly opportunistic and rushed deployments, cybersecurity firm Proofpoint reports. The China-linked APT Violet Typhoon (also tracked as APT31, JungleBamboo, TA412, and Tide Castle) was the first to use it…...
The PaperCut Pipeline: How Two Vulnerabilities Became an Automated RCE Factory
16+ hour, 37+ min ago (148+ words) Two PaperCut vulnerabilities are now chained into a fully automated attack pipeline with in-memory persistence—and 47% of installations can't patch. On August 26, security researchers at Huntress identified anomalous activity in customer logs involving base64-encoded commands like whoami and tasklist. This…...
One HTTP Request, Every File on the Server: GitLab’s CVSS 10 Commits-API Flaw Hits Active Exploitation Within Hours
1+ day, 10+ min ago (170+ words) A single HTTP POST to the commits API bypasses all security controls and reads arbitrary files from a GitLab server. CISA gave agencies until September 14 to patch. watchTowr saw exploitation attempts starting six hours after disclosure. The vulnerability was reported…...
Once in a BlueMoon: How a Chrome Patch-Gap Turned Three V8 Zero-Days Into an Espionage Kit
1+ day, 36+ min ago (65+ words) Three V8 bugs, individually medium-severity, chain into SYSTEM-level access through the patch-gap window. Four espionage clusters adopted the kit within days. The structural shift: browser-based AI agents inherit the same attack surface. Heath Callahan Trust, Identity & Security All stories by Heath…...
BlueMoon Exploit Kit Can Escape Chrome and Elevate Windows Privileges
1+ day, 18+ hour ago (355+ words) Published on September 11, 2026 BlueMoon exploit kit chains Windows and Chrome zero-days in targeted attacks, giving cyber-espionage groups a way to execute code, escape Chrome’s sandbox, and gain elevated Windows privileges. Proofpoint observed attacks involving BlueMoon starting on August 28, 2026, while Volexity…...
Social Media Account Recovery: Account Recovery Specialist | Best Freelance Certified Ethical…
1+ day, 1+ hour ago (23+ words) Social Media Account Recovery: Account Recovery Specialist | Best Freelance Certified Ethical Hackers for Hire > Smatchoicehackers.com Professional social media account unblocking and recovery …...
Meta's Project Phoenix Leaks via Firmware Before Connect 2026
1+ day, 8+ hour ago (212+ words) Firmware graphics buried in a Horizon app update reveal a sub-110-gram frame, tethered compute puck, and 2027 launch target A prescription lens pairing update quietly pushed through the Horizon mobile app turned into Meta‘s most revealing Phoenix disclosure yet....
StyleSmuggler Turns Adobe Commerce’s Own Template Engine Into an Unauthenticated RCE Chain
2+ day, 17+ min ago (117+ words) CVE-2026-75650 lets attackers inject PHP through Magento's email template system, then triggers execution automatically. Multiple threat groups are already inside. The authentication gap has reached the payment layer. Simultaneously, a separate attacker group has been observed dropping a 485-byte PHP…...
Attackers are weaponizing the gap between Chromium fixes and Chrome patches
2+ day, 1+ hour ago (642+ words) A new exploit kit is revealing the perils of the “patch later” mentality. According to the Proofpoint Threat Research team, espionage-motivated threat actors are using a new malicious toolkit to chain together four separate Chrome browser and Microsoft Windows vulnerabilities…...