New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries

A flaw in the Linux kernel’s traffic-control subsystem can let a local unprivileged user gain root on affected systems.

CVE-2026-46331, nicknamed “pedit COW,” is an out-of-bounds write in the packet-editing action (act_pedit) that corrupts shared page… Continue reading New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries

Posted in Uncategorized

CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical remote code execution vulnerability impacting PTC Windchill PDMlink and PTC FlexPLM enterprise Product Data Management (PDM) and Product Lifecycle Management … Continue reading CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue

Posted in Uncategorized

Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack

Cybersecurity researchers have flagged yet another evolution of the supply chain attack linked to the Mini Shai-Hulud, Miasma, and Hades malware family that has compromised a new set of npm packages, even as it has propagated to the Go ecosystem.

“The… Continue reading Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack

Posted in Uncategorized

Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant

An active phishing campaign has been targeting hotel and other hospitality organizations across Europe and Asia since April 2026, using photo-themed ZIP files to drop a Node.js implant and dig into front-desk machines, Microsoft says.

The company has&… Continue reading Microsoft Warns of Photo ZIP Phishing Campaign Targeting Hotels with Node.js Implant

Posted in Uncategorized