Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
This article discusses the release of a new Windows Defender exploit named ShieldCrash by security researcher Nightmare Eclipse. The exploit bypasses Microsoft Defender protections to grant system-level access and can disable real-time protection.
Palo Alto Networks has released security updates for a high-severity buffer overflow vulnerability in PAN-OS, tracked as CVE-2026-0310. The flaw affects VM-Series and PA-Series firewalls, enabling denial-of-service or root-level code execution when attackers have network access to vulnerable interfaces.
IDScan has confirmed a data breach after hackers offered 153 million stolen driver license records for sale on a hacking forum. The identity verification company says the data includes names, addresses, and driver license numbers from customers across multiple countries.
Bad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. Early Access apps are apps that haven't been released on the official Android app marketplace.
Executive Summary In this research we introduce a prompt-crafting technique for bypassing quick LLM-based policy checks — using plain English (no emojis, base64, invisible formatting, etc.) A policy-violating payload (e.g. ”encrypt files in ~/Documents”, “give me a biohazard recipe”, “ignore all previous instructions and…”) is embedded in a specially crafted prose wrapper. An LLM with limited resources and attention fails to realize the payload is there, classifies the prompt as benign and passes it off to the target model.
A new exploit kit called BlueMoon is combining Windows and Chrome zero-day vulnerabilities to deliver malware. The kit targets users through drive-by downloads and compromised websites.