Missing authentication for critical function in Windows DHCP Server allows an authorized attacker to elevate privileges over a network.
Stack-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.
Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours.
Google Threat Intellig...
Out-of-bounds read in Windows USB Driver allows an authorized attacker to disclose information locally.
Integer overflow or wraparound in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
AI agents are automating parts of cyberattacks with less human involvement, including vulnerability scanning, credential harvesting, and troubleshooting, according to Google Threat Intelligence Group’s Q3 2026 AI Threat Tracker. (Source: Google) The report draws on Mandiant incident response engagem...
Heap-based buffer overflow in Volume Manager Driver allows an authorized attacker to elevate privileges over a network.
Use after free in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
Mars Security has announced Real-Time Intel-Based Detection, a capability that turns newly published threat intelligence into validated, ready-to-deploy detection rules within minutes of release. Built by former offensive operators, the new capability converts advisories from CISA, Mandiant, and oth...
Use after free in Audio Video Control Transport Protocol allows an authorized attacker to elevate privileges locally.
Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information locally.
Researchers with security company Calif have discovered, weaponized, and privately reported to Tencent a critical vulnerability that allowed them to create “WeWorm”, a worm that spreads via WeChat calls without any user interaction. During its rampage, the WeWorm compromises the WeChat account of ea...
Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. [...]
Stack-based buffer overflow in Windows Broker Infrastructure Service allows an authorized attacker to elevate privileges locally.
Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to elevate privileges locally.
Researchers got inside the crooks' admin panel and found 5,137 stolen records tied to 461 organizations
Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges over a network.
Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.