Toggle light / dark theme

Get the latest international news and world events from around the world.

Log in for authorized contributors

Researchers Disclose AIAssisted SharePoint Exploit Chain Reaching Unauthenticated RCE

The flaw, tracked as CVE-2026–55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft’s affected-product list covers only those three on-premises editions, and SharePoint Online is not among them.

It lets a remote unauthenticated attacker assume a chosen user’s identity. The attack has one prerequisite: the intruder has to know which account they want to become, either by its Active Directory security identifier (SID) or its user principal name (UPN), which is formatted like an email address.

Rapid7 then chained the bypass to a separate remote code execution flaw and ran code on the server with no credentials. Microsoft and the firm disclosed that second flaw on August 11 as CVE-2026–63520 (CVSS 8.1), an unsafe. NET type instantiation in SharePoint’s Business Connectivity Services.

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

A malicious SIM card can order the device it sits in to run commands of the attacker’s choosing. On the cellular modules built into electric-vehicle chargers, industrial routers, and car telematics units, that is enough to take the whole device over.

Researchers at the University of Birmingham and the security firm Fuzzware tested 26 phones and cellular modules for the capability, found it switched on in 9 of them, and used it to run their own code on a commercial EV charger.

Six of the eight cellular modules they tested accepted the command. Only 3 of 18 phones did: the OPPO Find X5, the OPPO Reno 14 F 5G, and the ASUS Zenfone 9. No iPhone or Pixel was among them.

Researchers Turn USB AutoInstall Into a Full SYSTEM Takeover on Windows 11

Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine.

The same PnP path can be triggered over Remote Desktop without physical hardware when supported Plug and Play or low-level USB redirection is enabled; Microsoft says that redirection is not allowed by default.

Security researchers Alejandro Hernando and Borja Martinez described the technique in “Plug And Pwn: Weaponizing Windows PnP Auto-Install,” research prepared for DEF CON 34.

DDoS attacks over 1 Tbps surged fivefold in the second quarter

Cloudflare says it mitigated more than 800 network-layer distributed denial-of-service (DDoS) attacks exceeding 1 Tbps in the second quarter of the year.

Compared with the first quarter, when the company recorded just 130 attacks above 1 Tbps, the latest figure represents a more than fivefold increase.

Cloudflare is a major web infrastructure and security firm that provides CDN, DNS, reverse-proxy, and DDoS protection services to customers worldwide, protecting roughly 20% of the web.

Mozilla updates GPG signing key for Firefox releases after exposure

Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub.

However, in a Monday blog post, it noted that the risk of a supply chain attack in which threat actors could distribute malicious installers signed with the exposed key is low because only a limited number of individuals had access to the GitHub repository.

Additionally, Mozilla has yet to find evidence that the previous GPG key was accessed by unauthorized parties while being exposed.

Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse

Google says Chrome’s anti-abuse systems reduced unwanted notifications on Android by more than 7 billion per day during the first quarter of 2026.

In a new blog post, Google argues that notification abuse has increasingly been used to distribute scams, malware, phishing attempts, and fraudulent payment requests.

To reduce the abuse, Google developed a “Swiss cheese” defense model, where several overlapping systems try to stop abuse at different stages.

New AI chip mimics the human brain’s capacity for splitsecond motor control problems using 10,000 times fewer calculations

A new brain-inspired device is designed to kick AI systems into gear only when they detect something unusual. Could it reduce dependence on power-guzzling data centers?

Crew Works Vein Scans For Health and Suit Checks for Spacewalk

Vein scans and spacesuit checks were the top duties for the Expediton75 crew aboard the International Space Station on Tuesday. The orbital residents also continued their Earth photography sessions, cargo operations, and life support maintenance.

Station commander Jessica Meir kicked off her shift collecting blood samples inside the Columbus laboratory module for the Venous Flow investigation that is exploring how microgravity affects the circulatory system. Afterward, she spun the samples in a centrifuge, analyzed the samples for signs of space-caused blood issues, then stowed the samples in a science freezer for preservation.

NASA flight engineer Jack Hathaway took charge of Tuesday’s first set of vein scans operating the Ultrasound 3 biomedical device to observe Meir’s internal jugular veins then measured her blood pressure. Meir and Hathaway also took part in the second set of vein scans after lunchtime taking turns using the Ultrasound 3 with flight engineers Anil Menon of NASA, Sophie Adenot of ESA (European Space Agency) and Pyotr Dubrov and Anna Kikina, both from Roscosmos. Doctors on the ground monitored the ultrasound scans in real-time to understand the risk of blood flow anomalies and blood clots during a spaceflight.

/* */