Microsoft testing new Cloud Rebuild Windows 11 recovery feature
CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware
“An attacker can exploit this vulnerability, tracked as CVE-2026-11405, to bypass the password verification process
BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA
The vulnerabilities are listed below –
CVE-2026-40138 (CVSS score: 9.2) – A pre-authentication vulnerability exists in the
Phishing poses as big-brand job interview to steal Google accounts
Fake IT support calls on Microsoft Teams push EtherRAT malware
Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks
Securonix says the sophisticated framework abuses compromised websites, Blogspot, PowerShell, and fileless techniques to evade detection and deploy the PureLog information stealer.
The post Blogspot-Hosted Payloads Delivered in ‘Veil#Drop’ Attacks appeared first on SecurityWeek.
Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations
The activity, which has primarily singled out IT providers and government sectors, has been attributed to a threat cluster tracked by Check Point Research
Vietnam arrests suspects behind HiAnime anime piracy service
16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems
Dubbed ‘Januscape’ and tracked as CVE-2026-53359, the flaw sits in the shadow MMU code that KVM shares across both Intel and AMD. The public proof-of-concept panics the host; the researcher claims that a separate, unreleased exploit
