A local Windows Defender vulnerability, CVE-2026-50656, let any logged-in user reach SYSTEM for nearly 29 days before Microsoft shipped a fix.
News
-
-
GhostLock’s real lesson isn’t the bug, it’s the eleven weeks most businesses spent unpatched after the fix shipped. Linux kernel patching needs urgency.
-
BeyondTrust has fixed two pre-authentication bypass flaws in Remote Support and Privileged Remote Access. Here is a practical checklist for IT teams still running self-hosted appliances.
-
A 16-year-old hypervisor escape vulnerability in Linux KVM shows guest isolation is an assumption, not a fact. Here’s why that should change how you scope security testing.
-
What happens during a thick client penetration test, what testers find most often, and how to choose a provider.
-
A US county paid roughly $1 million to a group that never encrypted a single file, exposing how far data-theft extortion has moved beyond classic ransomware.
-
Researchers at JFrog traced a fresh npm supply chain attack to North Korea’s Lazarus group, six lookalike packages built to steal developer credentials and cloud keys.
-
A newly exploited SharePoint server vulnerability lets low-privilege accounts run code on your server. Here’s how to check exposure and patch it this week.
-
A second maximum-severity flaw in Kemp LoadMaster in two years shows why load balancers need the same patch discipline as public web servers.
-
Ransomware via search results is now a documented attack route. A Bing search for IT software led to full network encryption in 44 hours. Here is why your download policy …