Daily News
SimpleHelp CVE-2026-48558 RMM Bypass Exploited
A critical SimpleHelp CVE-2026-48558 authentication bypass is letting attackers forge a login token and seize a fully authenticated technician session in the remote monitoring and management (RMM) software thousands of managed service providers use to run client networks. CISA added the flaw to its Known Exploited Vulnerabilities catalog on June 29, and researchers have already…
Read MoreSignal Backup Recovery Key Russian intelligence
Signal Backup Recovery Key Russian intelligence theft is now formally attributed by three governments. The FBI, CISA, and Ukraine’s Security Service (SSU) jointly disclosed on June 26–27, 2026 that FSB-linked UNC5792 and GRU-linked UNC4221 are stealing these keys via fake support SMS messages — granting persistent access to complete message archives even after victims reset…
Read MorePTC Windchill RCE CVE-2026-12569: Web Shells Actively Deployed
The PTC Windchill RCE CVE-2026-12569 (CVSS 9.3) is actively exploited — and this is the second attack wave targeting the same product in three months. Attackers are deploying persistent JSP web shells inside Windchill PDMLink and FlexPLM installations right now. CISA added the flaw to its Known Exploited Vulnerabilities catalog on June 25, 2026; the…
Read MoreGaslight: North Korea’s macOS Malware That Deceives AI Security Tools
North Korea has built macOS malware that attacks your AI security tools — not by evading them technically, but by lying to them. SentinelOne disclosed a Rust-based macOS implant on June 25, 2026, codenamed Gaslight, attributed with high confidence to North Korea-aligned threat actors. It is the first documented malware to embed fabricated system-failure messages…
Read MoreGreatXML — No Patch: BitLocker Bypass via WinRE Survives Incident Response
Your BitLocker-encrypted Windows devices may not be as protected as your NIS2 compliance report says. This week a researcher published GreatXML — a technique that achieves a SYSTEM-level shell with full access to a BitLocker-encrypted volume using nothing more than two XML files placed on the recovery partition. No patch exists. Microsoft is still assessing…
Read More
