Tracked as CVE-2026-43503 (CVSS 8.8), it lets a local user corrupt file-backed memory through a cloned network packet and gain root. The patch landed in
Guardian Agents: The Next Layer of Identity Governance
Linux Foundation Unveils New Open Source Security Project Akrites
It will provide the tools and channels to report, patch, and disclose open source software vulnerabilities.
The post Linux Foundation Unveils New Open Source Security Project Akrites appeared first on SecurityWeek.
Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack
“The latest activity includes malicious npm releases affecting LeoPlatform and RStreams packages, GitHub Actions workflow abuse, and a related Go
$3 Million Reportedly Stolen in Polymarket Hack
The decentralized prediction market said hackers targeted some of its users through a compromise of a third-party vendor.
The post $3 Million Reportedly Stolen in Polymarket Hack appeared first on SecurityWeek.
Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant
The company has not attributed the activity to a known threat actor, and the operators’ end goal is still unclear.
The lure plays to how hotels work.
Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets
Turla has been using the backdoor against government and military organizations in Ukraine for espionage.
The post Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets appeared first on SecurityWeek.
Russia Used Cellebrite on Jailed Activist’s iPhone Months After Sales Cutoff
The finding, published June 25 by the Citizen Lab, rests on two things that rarely line up: traces on the phone itself and an official Russian
First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild
CISA has added the remote code execution flaw CVE-2026-12569 to its Known Exploited Vulnerabilities catalog.
The post First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild appeared first on SecurityWeek.
New Enterprise-Ready MCP Specification Brings New Security Challenges
A major overhaul of the Model Context Protocol shifts critical security responsibilities from the protocol itself to developers and platform operators.
The post New Enterprise-Ready MCP Specification Brings New Security Challenges appeared first on SecurityWeek.
