Certighost exploit opens Active Directory certificate services to domain takeover

Researchers released a Certighost exploit for a critical AD CS flaw that lets authenticated users escalate privileges to full domain admin.

The Latest

Breaking News and Alerts

Chick-fil-A loyalty accounts drained in credential stuffing spree

Chick-fil-A disclosed a credential stuffing attack that compromised customer accounts in the Chick-fil-A One loyalty program.

Spotlight

Cybersecurity Profiles and Stories

Crafted SVG files exploit Bing image pipeline for SYSTEM-level code execution

Researchers found flaws in Microsoft's Bing Images service allowing crafted SVG files to execute arbitrary commands as SYSTEM on internal servers.

Ubuntu Snap sandbox race condition lets local attackers gain root privileges

A race condition in Ubuntu's Snap sandbox initialization, tracked as CVE-2026-8933, lets local attackers escalate privileges to root on default installations.

Adobe Acrobat browser extension flaw exposed WhatsApp chats on 329 million devices

A vulnerability chain in the Adobe Acrobat Chrome extension let any webpage silently steal WhatsApp Web chats from 329 million browsers without malware.

Google restricts powerful new Gemini Cyber AI to government partners only

Google DeepMind released Gemini 3.5 Flash Cyber, a specialized AI for vulnerability hunting, restricted to governments and trusted partners due to dual-use risks.

Features

Research and Thought Leadership