Skip to content

Latest alerts

RSS feed

NatJack attacks: hijack TCP and spoof DNS

Security researcher Malcolm Stagg disclosed a new NAT-focused attack class called NatJack. It can hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables.

Microsoft and Apple Security Updates: Key Fixes

Microsoft and Apple have released new security updates addressing vulnerabilities across multiple platforms. The updates include critical remote code execution and authorization-related flaws.

Malware and Windows Hello for Business access

Security researcher Dirk-jan Mollema showed how malware running in an active Windows session can silently use Windows Hello for Business keys to authenticate to Entra ID. This can enable longer-term access through device registration and PRT-based workflows, depending on tenant policies.

CI Secrets at Risk: Claude Code & Gemini CLI

Security researchers found that crafted GitHub issue activity could lead to code execution in CI workflows tied to agent tooling from Anthropic and Google, exposing secrets. Gemini CLI and Claude Code have patches; Codex guidance focuses on workflow changes.

Chrome 151: 41 Critical Bugs Patched

Google’s Chrome 151 update fixes 41 critical- and high-severity vulnerabilities. The release includes six critical memory-safety issues and additional high-risk bugs.

TeamPCP Redis Attacks: Links Back to 2020

New research traces TeamPCP’s operations to campaigns active since 2020, including long-running abuse of internet-facing infrastructure like Redis servers.

Zapscape KVM flaw lets L1 escape to host

A new KVM vulnerability, tracked as the Zapscape KVM flaw (CVE-2026-64561), could let an attacker escape isolation from a nested L1 guest. Administrators should update kernels or vendor packages that include the fix.

Interrupt Injection: New Spectre v2 Bypass Risk

Researchers describe an interrupt injection technique that can interfere with Spectre v2 branch-protection windows. They report proof-of-concept leakage on an AMD Zen 2 system without privileges.