Windows 11 And Edge Hacked At Pwn2Own Berlin 2026
Windows 11 and Microsoft Edge fall to hackers at Pwn2Own Berlin. Day one: $523K paid out for 24 zero-day exploits. The bugs are real and they’re spectacular.
Windows 11 and Microsoft Edge fall to hackers at Pwn2Own Berlin. Day one: $523K paid out for 24 zero-day exploits. The bugs are real and they’re spectacular.
Russian state-sponsored hackers are actively targeting Signal messenger users to steal backup recovery keys, according to a recent FBI alert. These attackers are shifting tactics to compromise encrypted communications by exploiting the backup and recovery features rather than attempting to break Sig
Threat actors are increasingly targeting cloud logging infrastructure as a primary defense evasion technique. By disabling, deleting, or manipulating cloud audit logs across AWS CloudTrail, Azure Monitor, and Google Cloud Logging, attackers effectively blind security teams during intrusions. This ta
Cybercriminals are exploiting human psychology and Microsoft 365’s OAuth consent mechanisms through sophisticated social engineering attacks dubbed “ConsentFix” and “ClickFix.” These attacks bypass multi-factor authentication (MFA) entirely by tricking users into granting malicious OAuth application
A critical vulnerability (CVE-2026-42530) has been discovered in NGINX’s HTTP/3 implementation that allows unauthenticated attackers to trigger denial-of-service conditions and potentially achieve remote code execution. The flaw affects NGINX versions 1.25.0 through 1.26.3 with HTTP/3 enabled, stemm
A sophisticated supply chain attack orchestrated by the threat group TeamPCP has successfully infiltrated GitHub and Microsoft infrastructure, with malicious activity detected through May 24, 2026. The campaign leverages compromised developer accounts and poisoned packages to distribute malware acro
A critical authentication bypass vulnerability in SimpleHelp remote support software (CVE-2024-48558) is being actively exploited by threat actors to deploy TaskWeaver malware and the Djinn information stealer. The flaw allows unauthenticated attackers to gain unauthorized access to systems running
Mozilla to UK government: Breaking encryption and banning VPNs won’t solve your age verification problems—it’ll just destroy basic security for everyone.
A highly critical SQL injection vulnerability (CVE-2026-9082) has been discovered in Drupal core affecting sites running PostgreSQL databases. With a CVSS score of 9.8, this flaw allows unauthenticated attackers to execute arbitrary SQL queries, potentially leading to complete database compromise. A
Competitive intelligence platform Klue suffered an OAuth token breach that exposed Salesforce customer data in connection with the widespread ‘Icarus’ attack campaign. Threat actors exploited compromised OAuth credentials to access sensitive sales and customer relationship data stored in connected S