News

Application Security
BigDiskBuster Zero-Day Blocks Defender Updates, No Patch Issued
Researcher Abdelhamid Naceri published BigDiskBuster proof-of-concept on September 19, preventing Microsoft Defender updates by filling disk space. No patch available.
Application Security
Arista VeloCloud CVSS 10.0 Flaw Under Active Exploitation
CVE-2026-93952 (CVSS 10.0) in on-premises VeloCloud Orchestrator under active exploit. Unauthenticated attackers access privileged internal functions.
CVE Vulnerability Alerts
Linux KVM Flaw on ARM64 Exposes Host Memory to Guest VMs
CVE-2026-89775 in Linux kernel KVM for ARM64 processors exposes freed host memory to guest VMs, enabling guest-to-host privilege escalation when nested virtualization is enabled.
Application Security
SharePoint Flaw Enables Authenticated RCE Despite Spoofing Rating
CVE-2026-65660, initially classified by Microsoft as spoofing with CVSS 6.5, enables authenticated remote code execution on SharePoint Server per researcher analysis.
Application Security
Malicious npm Package indexed-btree Hides Payload in Runtime Code
indexed-btree npm package hides malicious behavior in application runtime code instead of lifecycle scripts, evading npm security controls, per Checkmarx researchers.
Application Security
SideCopy Expands India Targeting to Academic Institutions
SideCopy threat actor expanded targeting from Indian government to academic institutions using spear-phishing with ReverseRAT and mshta.exe abuse, per Trellix research.
Application Security
Meta Muse AI App Flaw Lets Local Malware Redirect Voice Input
Researcher Patrick Wardle published proof-of-concept on September 21 showing malware can hijack Meta Muse AI assistant by changing a hidden setting to redirect voice input.
Application Security
WordPress Patches Comment2Shell Anonymous-to-RCE Attack Chain
WordPress patched CVE-2026-93485 (Comment2Shell) in version 7.1.1 on September 17, a flaw allowing anonymous comments to achieve RCE when viewed by administrators.
Application Security
Fake LastPass Authenticator Uses Signed Driver to Disable EDR
Fake LastPass Authenticator installer distributed via GitHub installs Microsoft-signed kernel driver to disable antivirus and EDR before deploying password stealer.
Issabel Framework Flaw Enables Unauthenticated OS Command Execution
CVE Vulnerability Alerts
Issabel Framework Flaw Enables Unauthenticated OS Command Execution
CVE-2026-89026 in Issabel Framework under active exploitation allows unauthenticated attackers to execute arbitrary OS commands remotely via hard-coded credentials.