Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

Cyber Kendra
cyberkendra.com > 2026 > 08 > microsofts-sccm-hotfix-fixes-only-one.html

Microsoft's SCCM Hotfix Fixes Only One of Four RCE Bugs

2+ hour, 55+ min ago   (359+ words) Security researcher Omri Baso has disclosed a remote code execution chain in Microsoft Configuration Manager (SCCM/ConfigMgr) that lets an ordinary Active Directory user seize SYSTEM control of a Primary Site Server — and every client it manages. Microsoft has patched…...

Cyber Kendra
cyberkendra.com > 2026 > 08 > zapscape-kvm-flaw-lets-guest-vms-seize.html

Zapscape KVM Flaw Lets Guest VMs Seize Host Root

1+ week, 3+ day ago   (239+ words) Security researcher Hyunwoo Kim closed out his KVM escape trilogy today with Zapscape (CVE-2026-64561), and this time he shipped the whole thing. Where the earlier Januscape disclosure went public with a proof-of-concept that only panicked the host, the full host…...

Cyber Kendra
cyberkendra.com > 2026 > 08 > researchers-chain-wordpress-rce-to.html

Researchers Chain WordPress RCE to Fileless Linux Root

1+ week, 3+ day ago   (186+ words) cyberkendra.com Security researchers have shown that the critical wp2shell WordPress flaw doesn't have to stop at a web shell — it can be chained all the way to full Linux root, without writing a single file to disk. More striking, they…...

Cyber Kendra
cyberkendra.com > 2026 > 08 > human-reviewer-caught-ai-agents-malware.html

Human Reviewer Caught AI Agent's Malware Pull Request

1+ week, 4+ day ago   (386+ words) The thing that stopped an AI agent from poisoning a public open-source project last month wasn't a firewall, a classifier, or a sandbox. It was one suspicious developer who decided to detonate a strange script in a throwaway container before…...

Cyber Kendra
cyberkendra.com > 2026 > 08 > npm-worm-hits-keyv-and-cacheable.html

npm Worm Hits keyv and cacheable, Spreads to 400 Packages

1+ week, 5+ day ago   (701+ words) A self-propagating worm tore through the npm registry on Tuesday morning, trojanizing the widely used keyv and cacheable caching libraries and spreading to more than 400 packages within hours. Wiz Research, Socket, and Microsoft Threat Intelligence are all tracking the campaign,…...

Cyber Kendra
cyberkendra.com > 2026 > 08 > github-source-code-allegedly-up-for.html

GitHub Source Code Allegedly Up for Sale Again

1+ week, 5+ day ago   (287+ words) The internal source code stolen from GitHub in May is allegedly back on the market, and this time the seller is showing samples to prove it. A listing surfaced today offers what is described as GitHub's internal source code for…...

Cyber Kendra
cyberkendra.com > 2026 > 07 > azure-cosmos-db-flaw-gave-up-keys-to.html

Azure Cosmos DB Flaw Gave Up Keys to Every Database

2+ week, 2+ day ago   (398+ words) Microsoft has closed a vulnerability chain in Azure Cosmos DB that would have let anyone with a throwaway test account read and write data in every database on the service — including the internal ones behind Entra ID, Teams, and Copilot....

Cyber Kendra
cyberkendra.com > 2026 > 07 > claude-ai-uploaded-malware-to-pypi.html

Claude AI Uploaded Malware to PyPI During a Safety Test

2+ week, 2+ day ago   (936+ words) For about an hour earlier this year, a working piece of malware sat on PyPI, the public registry that virtually every Python developer pulls from. Fifteen real machines downloaded and executed it. One of them belonged to a security company…...

Cyber Kendra
cyberkendra.com > 2026 > 07 > ai-agent-finds-firefox-jit-flaw-that.html

AI Agent Finds Firefox JIT Flaw That Also Broke Tor

2+ week, 5+ day ago   (283+ words) Mozilla has patched a JavaScript engine bug that let attackers run code inside Firefox's renderer process, and the Tor Project has now backported the fix to the browser its users rely on for anonymity. The flaw, tracked as CVE-2026-10702 and…...

Cyber Kendra
cyberkendra.com > 2026 > 07 > microsofts-cyber-ai-beats-frontier.html

Microsoft's Cyber AI Beats Frontier Models at Half the Cost

2+ week, 5+ day ago   (420+ words) Follow Cyber Kendra on Google News! | WhatsApp | Telegram Microsoft's answer to AI-powered attackers isn't a bigger model. It's a smaller, cheaper one that already knows what it's hunting for. The company announced MAI-Cyber-1-Flash on Monday, its first model purpose-built…...