Endpoint Security

CVE Vulnerability Alerts
Zapscape KVM Flaw Lets Privileged L1 Guest Escape to Host
Researcher Hyunwoo Kim documented Zapscape, CVE-2026-64561, a KVM/x86 shadow memory flaw allowing privileged L1 guest code to escape to the Linux host.
Cybersecurity
TONTOU Interrupt Injection Bypasses Spectre v2 Fixes on AMD Zen 2
MIT CSAIL's interrupt injection attack named TONTOU bypasses retpoline and Safe-RET defenses on AMD Zen 2 to leak Linux password hashes from userspace.
Cybersecurity
ClickFix Campaign Pushes Go-Based macOS Crypto Drainer
Huntress discovered a Go-based macOS infostealer delivered through ClickFix attacks that steals crypto assets and redirects a percentage of each transaction.
Cybersecurity
ClickFix Malware Gate Fingerprints macOS Users Before Lures
Microsoft detailed a ClickFix campaign spanning 250 domains that fingerprints macOS visitors server-side before deciding whether to show an infostealer lure.
Application Security
Open VSX Purges 77 Evil-Twin Extensions Stealing Developer Data
Open VSX removed 77 malicious evil-twin extensions impersonating developer tools and exfiltrating machine, Git, and CI/CD data to one attacker domain.
Application Security
QuickFox VPN Supply-Chain Attack Delivers FDMTP Backdoor
Fortinet disclosed a long-running supply-chain attack on QuickFox VPN that delivers the undocumented FDMTP backdoor through a trojanized Windows installer.
Cybersecurity
SMOKE#SCREEN Deploys ScreenConnect via Fake Adobe, Zoom Lures
Securonix details the SMOKE#SCREEN campaign, which uses fake Adobe and Zoom update lures to stealthily install ConnectWise ScreenConnect for persistent access.
Application Security
XCSSET v40 Malware Targets macOS Developers via Xcode Projects
Unit 42 found XCSSET v40 targeting macOS developers via compromised Xcode projects, adding a Chrome hijacker and Telegram trojanizer to its 17-module toolkit.
Cybersecurity
Unit 42 Details Pass-ta-key Attacks on Google-Synced Passkeys
Unit 42 reveals three Pass-ta-key attacks that let malware hijack Google-synced passkeys on Windows by abusing Chrome's TPM trust and cloud authenticator flows.
Application Security
Malicious npm Packages Deliver RAT to Alibaba Developer Tools
Socket found 18 malicious npm packages impersonating Alibaba developer tools that deliver a cross-platform RAT with remote control and data-theft capabilities.