AI Security Research238 Beyond Prompt Injection: Hacking Apple’s Private Cloud Compute (CVE-2026-20685)
A path traversal in darwin-init, the PID 1 process that provisions every Apple Private Cloud Compute node, gave a researcher an arbitrary…
AI Security Research238 A path traversal in darwin-init, the PID 1 process that provisions every Apple Private Cloud Compute node, gave a researcher an arbitrary…
Exploit Development169 A write-side fuzzing campaign against libpng18's APNG re-encode path found a per-frame buffer lifecycle defect that yields both a memory leak (CWE-401)…
Browser Security462 CVE-2026-40369 is an unprivileged twelve-byte arbitrary kernel write in nt!ExpGetProcessInformation, reachable via NtQuerySystemInformation from browser renderer sandboxes. Root-cause analysis and a full…
Exploit Development391 GhostLock (CVE-2026-43499) is a 15-year-old use-after-free in the Linux kernel's rtmutex/futex requeue-PI code. When a proxy lock hits a deadlock and rolls…
Browser Security326 CVE-2026-10702 is a miscompilation bug in Firefox's SpiderMonkey Ion/Warp JIT. The MObjectToIterator instruction produced by scalar-replacing Object.keys() declares a load-only alias set,…
Threat Intelligence318 CVE-2026-50522 is a critical (CVSS 9.8) unauthenticated, pre-auth deserialization RCE in on-premises Microsoft SharePoint Server. A single crafted WS-Federation POST to /_trust/default.aspx…
Browser Security348 CVE-2026-6307 is a single V8 vulnerability that pierces two security boundaries at once. A missing signature comparison lets TurboFan's global value numbering…
RCE398 Technical breakdown of OnlyShells — a five-vulnerability chain in ONLYOFFICE Desktop Editors combining zero-click XSS, a Chromium V8 RCE, and an update-service…
Vulnerability Analysis833 A detailed technical analysis of CVE-2026-49176, a local privilege escalation vulnerability in Windows WalletService that allows standard users to achieve SYSTEM access…
Exploit Development332 CVE-2026-58629 is a double-fetch bug in the Windows graphics kernel (dxgkrnl). When D3DKMTCreateAllocation rolls back a failed create, it re-reads a user-controlled…
Reverse Engineering547 A user-controlled 64-bit record count multiplied by the 0x228 record size wraps to zero in the Windows tcpip.sys WFP ALE deserialiser, defeating…
Privilege Escalation395 Cisco Talos disclosed CVE-2026-58613, a kernel use-after-free in cldflt.sys — the Windows Cloud Files Mini Filter Driver behind OneDrive Files On-Demand. An…