Tag Archives: privilege escalation
MiniPlasma Zero-Day Exploit Released for Windows 11 and Server
A rogue security researcher has publicly released a working MiniPlasma zero-day exploit, allowing local privilege escalation to SYSTEM level on fully patched Windows installations. Continue reading
Windows Zero-Day Exploits: YellowKey and GreenPlasma Released
New Windows zero-day exploits known as YellowKey and GreenPlasma have been publicly released, posing a critical threat to BitLocker encryption and system privilege security. Continue reading
Dirty Frag Linux Kernel Zero-Day: CVE-2026-43284 Security Alert
The Dirty Frag Linux kernel zero-day (CVE-2026-43284) allows local unprivileged users to gain full root access on major distributions like Ubuntu and Red Hat. Continue reading
Copy Fail Linux Vulnerability (CVE-2026-31431) Threatens Cloud Security
The critical Copy Fail Linux vulnerability (CVE-2026-31431) allows unprivileged users to gain root access, bypassing container isolation and threatening global cloud infrastructure. Continue reading
Microsoft Patch Tuesday April 2026: BlueHammer and Critical SharePoint Fixes
IT departments face a massive Microsoft Patch Tuesday update in April 2026, addressing 167 vulnerabilities including the BlueHammer privilege escalation and critical SharePoint zero-day threats. Continue reading
PhantomRPC Vulnerability: Critical Windows Privilege Escalation Exposed
The newly disclosed PhantomRPC vulnerability reveals a critical architectural flaw in the Windows RPC runtime, allowing attackers to escalate local privileges to SYSTEM-level access. Continue reading
Microsoft Defender Zero-Days: Active Exploitation of RedSun and UnDefend Flaws
Security researchers and CSIRT-ITA warn of the active exploitation of two unpatched Microsoft Defender zero-days, codenamed RedSun and UnDefend, which allow attackers to bypass security updates and gain SYSTEM-level access. Continue reading
BlueHammer Zero-Day: CISA Issues Urgent 14-Day Patch Mandate
CISA has officially added the BlueHammer Zero-Day (CVE-2026-33825) to its Known Exploited Vulnerabilities catalog, requiring federal agencies to patch the Microsoft Defender flaw within 14 days. Continue reading
Microsoft Defender Zero-Day: BlueHammer (CVE-2026-33825) Under Active Exploitation
A critical Microsoft Defender Zero-Day, known as BlueHammer, is being actively exploited via a TOCTOU race condition to grant attackers SYSTEM-level privileges. Continue reading