supply-chain Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11 Researchers have discovered a method to leverage Windows Plug and Play to achieve SYSTEM-level access on Windows 11 machines. By emulating USB devices and exploiting a vulnerability in the driver installation process, an unprivileged user can execute code with SYSTEM privileges, even remotely via Remote Desktop if USB… The Hacker News · Aug 11, 2026 High usbremotedriver
vulnerability AutomationDirect Productivity Suite AutomationDirect Productivity Suite versions 4.6.2.2 and earlier are vulnerable to multiple out-of-bounds read and write vulnerabilities, potentially leading to kernel memory corruption, privilege escalation, system inst… CISA Advisories · Jul 16, 2026 High CVE-2026-60063CVE-2026-61389CVE-2026-60140cvevulnerabilityioctl
threat-intel Russian APT 'Gamaredon' Upgrades Its Arsenal, Requiring New Defenses The Russian cyber espionage group Gamaredon (also known as Aqua Blizzard) has significantly upgraded its arsenal and tactics, becoming a more effective threat actor, particularly in support of the war in Ukraine. The gro… Dark Reading · Jun 25, 2026 High RUUKaptespionagec2
threat-intel Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain Researchers at Paradigm Shift have developed ‘usbliter8’, an exploit that allows arbitrary code execution within the SecureROM of Apple’s A12 and A13 chips. The exploit leverages a hardware flaw in the Synopsys DWC2 USB… The Hacker News · Jun 19, 2026 High USsecureromusbdfu
threat-intel Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone A vulnerability in Apple’s Beats Studio Buds firmware allowed nearby attackers to potentially eavesdrop on users via the device’s microphone. The flaw, tracked as CVE-2025-20701, stemmed from incorrect authorization with… The Hacker News · Jun 19, 2026 Critical CVE-2025-20701CVE-2025-20700CVE-2025-20702GEbluetoothmicrophonesecurerom
malware Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2 Microsoft has detailed a new Windows-based malware campaign, dubbed Windows Clipper, that leverages USB LNK files and a Tor-based command-and-control infrastructure to steal cryptocurrency data. The clipper silently moni… The Hacker News · Jun 18, 2026 High clipboardtorusb
vulnerability Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit This report details a zero-day vulnerability, dubbed ‘YellowKey,’ affecting Windows 11 and Server 2025, allowing attackers to bypass BitLocker Device Encryption through a USB drive exploit. Microsoft has released a mitig… The Hacker News · May 20, 2026 High CVE-2026-45585USbitlockerwinrezero-day
threat-intel How the Story of a USB Penetration Test Went Viral This Dark Reading Confidential episode recounts the viral 2006 pen test conducted by Steve Stasiukonis at a credit union, focusing on his use of rigged USB drives to observe employee behavior. The story gained traction t… Dark Reading · May 5, 2026 Medium social engineeringusbpen testing