Endpoint Security

CVE Vulnerability Alerts
Dell Patches Root-Level Flaw CVE-2026-86360 in System Update Tool
Dell fixed a critical path traversal, CVE-2026-86360, in its System Update CLI that lets unauthenticated remote attackers run code as root, plus four more bugs.
CVE Vulnerability Alerts
Android October 2026 Update Patches 25 Flaws, Seven Rated Critical
Google's Android security bulletin for patch level 2026-10-01 fixes 25 vulnerabilities, seven of them critical, with no in-the-wild exploitation reported.
Cybersecurity
ClickFix Variant Smuggles Payloads Through Browser Cache
Microsoft Threat Intelligence says a new ClickFix variant hides a script in the browser cache as a PNG, sidestepping the Windows Run dialog's character limit.
CVE Vulnerability Alerts
ClingSTUN Botnet Abuses STUN Protocol for C2, Exploits Dozens of Flaws
FortiGuard and Nozomi detail Cling, a Linux botnet that hides command traffic in STUN requests and exploits about two dozen router and IoT vulnerabilities.
Cybersecurity
Russia’s Star Blizzard Targets 100+ Orgs With Fake Invites
Microsoft says Russian state-backed group Star Blizzard used fake event invitations to install a Windows backdoor at more than 100 Ukraine-linked organizations.
Cybersecurity
New Spectre-v2 BTR Attack Leaks Linux Root Password Hashes
Academics disclosed a Spectre-v2 variant called BTR that bypasses existing mitigations and recovers Linux root password hashes on Intel systems in minutes.
Cybersecurity
Fake ChatGPT Custom GPTs Push ClickFix Attacks to Drop RAT
Threat actors use sponsored Google search ads for fake ChatGPT tools to run ClickFix attacks that trick victims into installing remote access trojan malware.
Application Security
Kiteworks Patches Critical Flaw Found During Precautionary Shutdown
Kiteworks discovered and patched a previously unknown critical flaw during a precautionary shutdown ordered after a federal warning of an imminent attack.
Application Security
Apple Patches CoreGraphics Zero-Day Used in Targeted Attacks
Apple patched CVE-2026-86950, an out-of-bounds write vulnerability in CoreGraphics exploited in extremely sophisticated targeted attacks reported by Meta.
Cybersecurity
Ransomware Attack Disrupts Keio Corporation Business Systems
Keio Corporation confirmed a ransomware attack disrupted business systems over the weekend. Railway operations continued but administrative functions impacted.