Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.
Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.
Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours.
Google Threat Intellig...
Use after free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges over a network.
Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally.
AI agents are automating parts of cyberattacks with less human involvement, including vulnerability scanning, credential harvesting, and troubleshooting, according to Google Threat Intelligence Group’s Q3 2026 AI Threat Tracker. (Source: Google) The report draws on Mandiant incident response engagem...
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
Double free in Windows Registry allows an authorized attacker to elevate privileges over a network.
Mars Security has announced Real-Time Intel-Based Detection, a capability that turns newly published threat intelligence into validated, ready-to-deploy detection rules within minutes of release. Built by former offensive operators, the new capability converts advisories from CISA, Mandiant, and oth...
Use after free in Windows Kernel allows an authorized attacker to elevate privileges over a network.
Use after free in Windows DNS allows an authorized attacker to elevate privileges locally.
Researchers with security company Calif have discovered, weaponized, and privately reported to Tencent a critical vulnerability that allowed them to create “WeWorm”, a worm that spreads via WeChat calls without any user interaction. During its rampage, the WeWorm compromises the WeChat account of ea...
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.
Heap-based buffer overflow in Microsoft JScript allows an unauthorized attacker to execute code over a network.
Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. [...]
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges over a network.
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
Researchers got inside the crooks' admin panel and found 5,137 stolen records tied to 461 organizations
Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
Double free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges locally.