Visualização de leitura

Windows Defender ShieldCrash 0-Day Lets Attackers Read Arbitrary Files as SYSTEM

A newly published proof-of-concept (PoC) called ShieldCrash reveals an unpatched vulnerability in Microsoft Defender that allows a local attacker to gain arbitrary file-read access in the SYSTEM context. This disclosure, attributed to the researcher known as MSNightmare, comes shortly after Microsoft addressed an elevation-of-privilege flaw in the Microsoft Malware Protection Engine, tracked as CVE-2026-69414, referred […]

The post Windows Defender ShieldCrash 0-Day Lets Attackers Read Arbitrary Files as SYSTEM appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Metasploit Adds Exploit for PaperCut MF/NG Zero-Day RCE Vulnerabilities

Rapid7’s Metasploit Framework is set to add an exploit module targeting the actively exploited chain of vulnerabilities affecting PaperCut MF and PaperCut NG. This addition will provide public offensive tooling for a security emergency involving print management servers. The proposed module targets CVE-2026-81578 and CVE-2026-82078, two vulnerabilities that attackers can exploit to achieve remote code […]

The post Metasploit Adds Exploit for PaperCut MF/NG Zero-Day RCE Vulnerabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Cursor 0-Day Lets Attackers Execute Malicious Code by Opening a Repository

A recently disclosed security issue in Cursor IDE exposed a serious Windows binary-planting vulnerability that could allow malicious code to execute simply by opening an untrusted repository. This flaw, tracked as CVE-2026-63093, relates to Cursor’s executable resolution behavior and demonstrates how files controlled by attackers placed in a workspace could be executed with the current […]

The post Cursor 0-Day Lets Attackers Execute Malicious Code by Opening a Repository appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Check Point SmartConsole Zero-Day Lets Unauthenticated Attackers Gain Full Admin Access

A critical zero-day vulnerability in Check Point SmartConsole, identified as CVE-2026-16232, has been actively exploited, allowing unauthenticated attackers to gain full administrative access to impacted environments. This flaw affects both the Check Point Security Management Server and the Multi-Domain Security Management Server (MDS), specifically targeting the SmartConsole login process. Check Point SmartConsole Zero-Day According to […]

The post Check Point SmartConsole Zero-Day Lets Unauthenticated Attackers Gain Full Admin Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌