“Showboat is a modular post-exploitation framework designed for Linux systems, capable of spawning a remote shell, transferring files, and functioning as a SOCKS5 proxy,” Lumen
Category Added in a WPeMatico Campaign
ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories
A token leaks. A bad package slips in. A login trick works. An old tool shows up again. At first, it feels like the usual mess. Then you see the pattern: attackers are not always breaking in. They are using the parts we already trust.
That is what makes it worrying. The danger is in normal things now – updates, apps, cloud buttons, support chats, trusted accounts. AI
Microsoft Warns of Two Actively Exploited Defender Vulnerabilities
The former, tracked as CVE-2026-41091, is rated 7.8 on the CVSS scoring system. Successful exploitation of the flaw could allow an attacker to gain SYSTEM privileges.
“Improper link resolution before file access (‘link following’) in Microsoft Defender
When Identity is the Attack Path
9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros
The vulnerability, tracked as CVE-2026-46333 (CVSS score: 5.5), is a case of improper privilege management that could permit an unprivileged local user to disclose sensitive files and execute arbitrary commands as root on default installations of several major
GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension
The development comes as the Nx team revealed that the extension, nrwl.angular-console, was breached after one of its developers’ systems was hacked in the
Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks
The vulnerability, now tracked as CVE-2026-9082, carries a CVSS score of 6.5 out of 10.0, per CVE.org. Drupal said the vulnerability resides in a database abstraction API that is
Microsoft Open-Sources RAMPART and Clarity to Secure AI Agents During Development
RAMPART, short for Risk Assessment and Measurement Platform for Agentic Red Teaming, functions as a Pytest-native safety and security testing framework for writing and running safety and security tests for AI agents, covering
Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks
The tech giant attributed the activity to a threat actor it calls Fox Tempest, which it said offered the MSaaS scheme
Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API
Webworm, first publicly documented by Broadcom-owned Symantec in September 2022, is assessed to be active since at least 2022, targeting government agencies
