Similar Posts
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers
A crafted SVG submitted to Bing’s image search ran commands as NT AUTHORITY\SYSTEM on Microsoft’s production image-processing workers, and as root on the Linux machines in the same fleet. XBOW’s testing got the same result on workers across different hosts and network ranges, so the problem sat in Bing’s image tier, not on one bad…
Hackers Use Microsoft Account Security Alert Lures to Deliver NarwhalRAT Malware
An ongoing threat campaign distributing an advanced Python-based malware named NarwhalRAT, which initiates through targeted spear-phishing emails masquerading as urgent security notifications from the official Microsoft Account Team. These deceptive messages warn recipients of abnormal one-time password generation and urge them to review an attached security advisory. Analysts from IntCyberDigest note that this social engineering…
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
Swati KhandelwalJul 25, 2026Vulnerability / Application Security Security researcher Yuhang Wu at depthfirst has published a working proof-of-concept (PoC) exploit that executes commands as git on an unpatched self-managed GitLab 18.11.3 server. An ordinary authenticated user triggers it by committing two crafted Jupyter notebooks and requesting their diff. The chain needs no administrator rights, continuous…
Unpatched Cursor Vulnerability Exposes Users to Code Execution
An unpatched vulnerability in Cursor on Windows can be triggered for code execution when a developer opens a repository in the application, Mindgard reports. Cursor is one of the most popular AI-assisted development environments, with more than 7 million active users. The security defect, Mindgard says, is straightforward: when opening a repository, Cursor would automatically…
Chromium extension uses AI‑related branding to redirect browser search
In this article Microsoft Threat Intelligence has identified a malicious Chromium-based extension that spoofs the AI-powered answer engine Perplexity AI to trick unsuspecting users into installing it. Based on our observation of the extension’s behavior, we assess its primary objective to be search traffic interception and data collection, which might enable downstream use cases such…
Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy
Executive Summary We conducted this research in close partnership with Siemens, reflecting our shared commitment to advancing the security and resilience of critical infrastructure. This report details a critical, chained exploit comprising three zero-day vulnerabilities (CVE-2025-40948, CVE-2025-40947, and CVE-2025-40949) discovered in Siemens ROX II operational technology (OT) switches. Successful exploitation of this chain would allow…