Tag: privilege escalation
109 articles

Unpatched Microsoft Exchange Servers Exposed to Hijack Attacks
Thousands of Microsoft Exchange servers remain vulnerable to a high-severity flaw, leaving 21,899 internet-facing systems open to hijack attacks that could give attackers control of every mailbox. This unpatched authentication-bypass vulnerability, CVE-2026-62911, was fixed by Microsoft in August, but many servers still haven't been updated.

CISA Red Team Exposes Defense Gap Between Water, Government Sectors
In a recent test, CISA's red team uncovered a shocking vulnerability in a government organization, breaching its defenses with ease by sending phishing emails from an internal address, then moving undetected to sensitive systems and cloud resources. The team was able to gain elevated privileges and spread laterally, exposing a significant gap in the organization's security.

Windows Named Pipes Expose Security Risks
Don't assume that just because a Windows Named Pipe is local, it's private - in reality, it can be a security risk if not properly defended, exposing your system to privilege escalation and other threats. A cybersecurity expert warns that architects must redesign pipes to prioritize identity and access control.

Ransomware gangs exploit Windows Task Host flaw
Ransomware gangs are exploiting a high-severity flaw in Windows Task Host, a core component that could allow them to escalate privileges and wreak havoc on your system. This vulnerability, already patched by Microsoft, poses significant risks to users, especially those with basic user permissions.

Certighost Exposes Hidden Privilege Risks in Certificate Authorities
A single misstep in a Certificate Authority can have devastating consequences, as seen in CVE-2026-54121, aka Certighost, which allows a low-privileged domain user to escalate to full domain compromise. This shocking vulnerability exploits a little-known "chase" functionality in Active Directory Certificate Services.

Windows Plug and Play Feature Exploited for SYSTEM Access via Fake USB Devices
Imagine a scenario where hackers can gain SYSTEM access to a Windows computer without needing a single click or logged-in user - and even exploit it remotely over RDP with no hardware involved. Researchers have just revealed a chilling new class of attacks, dubbed "Plug and Pwn", that takes advantage of Windows' Plug and Play feature to execute malicious software with alarming ease.

Lazarus Exploits Windows Zero-Day in Targeted Defense Sector Attacks
The notorious Lazarus threat group has been exploiting a newly patched Windows zero-day vulnerability, CVE-2026-68820, to gain SYSTEM privileges and escalate their attacks on high-value targets in the defense sector. This alarming exploit has been active since early July, making it crucial for organizations to stay vigilant.

Adobe Fixes Zero-Day Flaws in ColdFusion, Campaign Classic
Adobe has patched critical vulnerabilities in ColdFusion, Commerce, and Campaign Classic, including a zero-day flaw with a perfect 10.0 CVSS score that could allow hackers to execute arbitrary code or escalate privileges. These high-severity flaws, including operating system command injection and eval injection, require immediate attention to prevent exploitation.

Microsoft Defender Zero-Day Exploited to Gain System Privileges
A security researcher known as Nightmare Eclipse has unveiled a new exploit, ShieldBreak, which can bypass Microsoft's patch for the RoguePlanet vulnerability and grant SYSTEM privileges on fully patched Windows systems. This alarming development highlights a significant gap in Microsoft Defender's defenses, leaving users vulnerable to potential attacks.

Microsoft Disrupts Hundreds of Flaws in Massive Patch Update
Microsoft just dropped a massive patch update to fix a whopping 398 security flaws in Windows and its software, including a critical vulnerability that's already being exploited by hackers. This crucial update tackles a range of weaknesses, from a zero-day privilege-escalation flaw in a key Windows driver to other publicly known vulnerabilities.

OpenAI Bolsters Cybersecurity with GPT-5.6-Cyber Model, Two-Tier Access Program
OpenAI's new GPT-5.6-Cyber model is a game-changer in cybersecurity, capable of completing 95% of sensitive requests in advanced scenarios like exploit-chain development and privilege escalation. This purpose-trained model outperforms its general-access counterpart by a landslide, showcasing its potential to revolutionize cybersecurity.

Researchers Expose Windows 11 Vulnerability in USB Auto-Install Feature
Security researchers have uncovered a vulnerability in Windows 11's USB auto-install feature, allowing an unprivileged user to execute SYSTEM-level code on a fully updated machine. This clever hack, dubbed "Plug And Pwn," exploits the Plug and Play auto-install process to gain elevated access.

Linux KVM Flaw Lets Privileged Guests Escape to Host
A newly discovered flaw in Linux KVM, dubbed "Zapscape," allows attackers with kernel privileges inside a virtual machine to break free from isolation and execute code on the host system. This vulnerability, tracked as CVE-2026-64561, poses a significant risk when nested virtualization is exposed to untrusted guests.

cPanel Flaw Exposes Database Vulnerability to Authenticated Users
A critical cPanel flaw, CVE-2026-58048, with a near-perfect CVSS score of 9.4, allows authenticated users to execute SQL commands with root-level access, putting databases at risk. This vulnerability lets users with basic cPanel access escalate privileges and take control of the server's administrative database.

Spirals Ransomware Encrypts Network in Record Time
In a lightning-fast attack, the newly identified Spirals ransomware gang compromised a network and encrypted its entire system in under 24 hours, showcasing an alarming level of speed and sophistication. The attack began with a simple vulnerability - an exposed IIS server - which allowed hackers to upload a web shell and rapidly escalate their privileges.

Browser, Software Updates Fix Critical Flaws
Major tech players, including Adobe, Mozilla, Google, and Broadcom, have just rolled out critical security updates to fix dozens of vulnerabilities - and it's crucial to install them ASAP to avoid potential code execution and privilege escalation threats. Adobe alone is patching 88 flaws, including eight high-risk issues in ColdFusion that could lead to serious security breaches.

Microsoft Fixes Defender Flaw That Exposes Systems to SYSTEM Privileges
Microsoft has patched a critical flaw in its Defender software, known as RoguePlanet, that could have allowed hackers to gain SYSTEM privileges and take control of vulnerable systems. The vulnerability, tracked as CVE-2026-50656, has been fixed with the latest security updates.

Ubiquiti Fixes Flaws in UniFi Ecosystem
Ubiquiti has patched a critical vulnerability in its UniFi ecosystem, specifically a command injection flaw with a perfect 10.0 CVSS score, that could let hackers take control of your device. The update fixes issues across UniFi products, shielding you from potential attacks that could escalate privileges or make unauthorized changes.

Ransomware gangs exploit Windows BlueHammer flaw
Ransomware gangs are actively exploiting a critical Microsoft Defender flaw, nicknamed BlueHammer, which has been added to CISA's list of Known Exploited Vulnerabilities. This vulnerability is a prime target for malicious cyber actors, posing a significant risk to those who haven't yet applied the necessary patches.

Linux Kernel Flaw Exposes Local Users to Root Privilege Escalation
A newly discovered Linux Kernel flaw, CVE-2026-43503, allows local users to easily escalate their privileges to root level, putting systems at risk. This vulnerability, dubbed DirtyClone, lets attackers corrupt file-backed memory and gain unrestricted access with just a few clever steps.

macOS Flaw Enables Users to Disable EDR, MDM Tools
A security flaw in macOS has been discovered that allows users to quietly disable crucial enterprise security tools, including EDR and MDM, without needing administrator privileges. This gap in endpoint security models could leave businesses vulnerable to attacks.

Cisco SD-WAN Zero-Day Exploited for Root Access
A shocking new discovery reveals that a Cisco SD-WAN zero-day vulnerability, CVE-2026-20245, was exploited for root access at least two months before its public disclosure. This highly critical flaw, with a CVSS score of 7.8, allows attackers to execute arbitrary commands with elevated privileges.

Hackers Exploit Cisco Zero-Day for High-Level Access at Telecom Provider
In a chilling cyberattack, hackers exploited a previously unknown Cisco zero-day vulnerability to gain unrestricted access to a major telecom provider's system, creating a rogue admin account with full control. The breach, detected in March, was carried out in two waves, allowing the attackers to infiltrate the provider's SD-WAN Manager devices.

Microsoft Tackles RoguePlanet Defender Flaw with Imminent Patch
Microsoft is working on a patch to fix a serious security flaw in Microsoft Defender, known as RoguePlanet, which could allow hackers to gain elevated privileges on affected systems. A high-quality security update is imminent to address this vulnerability and protect users.