Cyber Security News News

The latest cyber security news stories, summarized by AI

Public PoC Reveals Local Root Exploit for DirtyDecrypt Linux Kernel
cyber-security-news57.895 min read

Public PoC Reveals Local Root Exploit for DirtyDecrypt Linux Kernel

7 days agoSource: CyberSecurityNews
View original source
Public PoC Unleashes Windows 'MiniPlasma' Privilege-Escalation to SYSTEM
cyber-security-news
57.31 min9 days ago

Public PoC Unleashes Windows 'MiniPlasma' Privilege-Escalation to SYSTEM

A publicly released PoC for the Windows 'MiniPlasma' zero-day privilege-escalation flaw lets unprivileged users gain SYSTEM privileges by exploiting the Cloud Filter driver’s HsmOsBlockPlaceholderAccess race condition and writing to the .DEFAULT hive. The bug traces to CVE-2020-17103 (originally patched in 2020 by Microsoft) but the PoC shows the flaw remains exploitable; Nightmare-Eclipse released the exploit on GitHub on May 13, 2026, after May Patch Tuesday, increasing risk as weaponized code circulates and affects all Windows versions. Organizations should monitor Microsoft’s response and apply patches when available.

More Cyber Security News Stories

Threat Actors Weaponize Teams Messaging to Breach Enterprises
cyber-security-news1 month ago

Threat Actors Weaponize Teams Messaging to Breach Enterprises

UNC6692 runs a multistage intrusion that begins with mass email bombardment and escalates via impersonation of IT staff in Microsoft Teams, guiding victims to a phishing landing page hosted on AWS S3. The campaign then harvests credentials, deploys a modular malware suite (SNOWBELT), and uses cloud-based C2 and data staging to exfiltrate data and compromise domain controllers, highlighting the need to restrict external Teams access and monitor cloud egress and browser extensions for anomalous activity.

RedSun: Defender zero-day grants SYSTEM access on Windows
cyber-security-news1 month ago

RedSun: Defender zero-day grants SYSTEM access on Windows

A newly disclosed zero-day in Microsoft Defender, dubbed RedSun, lets an unprivileged user escalate to SYSTEM on patched Windows 10/11 and Windows Server 2019+ by abusing Defender’s cloud file handling. The attack rewrites a malicious file back to a system path via cldapi.dll and oplocks, overwriting a system binary in System32 (e.g., TieringEngineService.exe) and gaining full code execution as SYSTEM. CVE-2026-33825 carries a CVSS of 7.8; there is currently no patch. Security teams should monitor Defender file-write activity to System32, look for cldapi.dll-issued redirects, and apply endpoint detection until Microsoft issues a fix.

Active Fortinet SQL Flaw Targets FortiClient EMS, CISA Warns
cyber-security-news1 month ago

Active Fortinet SQL Flaw Targets FortiClient EMS, CISA Warns

CISA added CVE-2026-21643, a critical unauthenticated SQL injection in Fortinet FortiClient EMS, to the Known Exploited Vulnerabilities (KEV) catalog, signaling active exploitation in the wild. The flaw enables remote code execution without authentication, risking full database compromise on affected FortiClient EMS deployments. Fortinet has released patches; federal agencies must patch by April 16, 2026, and private-sector admins are urged to patch within three days, monitor for unusual HTTP requests targeting EMS, and take the server offline if patching isn’t possible.

Windows 11 Shutdown Bug Emerges After January Patch
cyber-security-news4 months ago

Windows 11 Shutdown Bug Emerges After January Patch

Microsoft’s January 13, 2026 security update KB5073455 for Windows 11 23H2 (OS Build 22621.6491) triggers a shutdown bug on Enterprise and IoT editions, causing devices to reboot instead of powering down or entering hibernation due to interference with Secure Launch (a virtualization-based security feature). IT teams report power-management issues and potential data loss; a workaround is to force shutdown via shutdown /s /t 0, while a fix is promised in a future update. Disabling Secure Launch via Group Policy can restore normal shutdown but weakens boot integrity.

Unauthenticated PAN-OS DoS Flaw Forces Quick GlobalProtect Patch
cyber-security-news4 months ago

Unauthenticated PAN-OS DoS Flaw Forces Quick GlobalProtect Patch

Palo Alto Networks patched a critical PAN-OS vulnerability (CVE-2026-0227) that lets unauthenticated attackers trigger a denial-of-service on GlobalProtect gateways/portals. The flaw, rated CVSS 7.7 (HIGH), stems from improper handling of unusual conditions and affects multiple PAN-OS versions (Cloud NGFW is spared). A PoC exists, exploitation is not yet observed, and no workarounds are available. Administrators should upgrade to the latest hotfixes (PAN-OS 12.1.4 or 11.2.10-h2) and verify configurations via Palo Alto’s support portal while monitoring for DoS attempts.