Visualização de leitura

Windows Defender ShieldCrash 0-Day Lets Attackers Read Arbitrary Files as SYSTEM

A newly published proof-of-concept (PoC) called ShieldCrash reveals an unpatched vulnerability in Microsoft Defender that allows a local attacker to gain arbitrary file-read access in the SYSTEM context. This disclosure, attributed to the researcher known as MSNightmare, comes shortly after Microsoft addressed an elevation-of-privilege flaw in the Microsoft Malware Protection Engine, tracked as CVE-2026-69414, referred […]

The post Windows Defender ShieldCrash 0-Day Lets Attackers Read Arbitrary Files as SYSTEM appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Metasploit Adds Exploit for PaperCut MF/NG Zero-Day RCE Vulnerabilities

Rapid7’s Metasploit Framework is set to add an exploit module targeting the actively exploited chain of vulnerabilities affecting PaperCut MF and PaperCut NG. This addition will provide public offensive tooling for a security emergency involving print management servers. The proposed module targets CVE-2026-81578 and CVE-2026-82078, two vulnerabilities that attackers can exploit to achieve remote code […]

The post Metasploit Adds Exploit for PaperCut MF/NG Zero-Day RCE Vulnerabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Cursor 0-Day Lets Attackers Execute Malicious Code by Opening a Repository

A recently disclosed security issue in Cursor IDE exposed a serious Windows binary-planting vulnerability that could allow malicious code to execute simply by opening an untrusted repository. This flaw, tracked as CVE-2026-63093, relates to Cursor’s executable resolution behavior and demonstrates how files controlled by attackers placed in a workspace could be executed with the current […]

The post Cursor 0-Day Lets Attackers Execute Malicious Code by Opening a Repository appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

SonicWall SMA Zero-Days Let Attackers Turn One WebSocket Request Into Root Control

SonicWall SMA Secure Mobile Access appliances are again at the center of a zero-day storm, with chained flaws that let attackers turn a single crafted WebSocket request into root-level control on internet-facing VPN gateways. The campaign, dissected by Volexity and other researchers, shows how a previously undocumented threat actor, tracked as UTA0533, abused SonicWall’s wsproxy […]

The post SonicWall SMA Zero-Days Let Attackers Turn One WebSocket Request Into Root Control appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌