The Nightmare-Eclipse and Microsoft saga continues with another major Windows Defender exploit following 'RoguePlanet.' ...
Lazarus-linked attacks exploit Windows CVE-2026-68820 as a zero-day to gain SYSTEM access and deploy Troy against defense and aerospace firms.
One security researcher discovered a previously unpatched vulnerability in Windows and reported it to the Microsoft Security Response Center. However, they didn’t ...
Nightmare Eclipse has dropped ShieldBreak, a Windows zero-day exploit that allows any user to gain System privileges.
The leak online of exploit code for an apparent Windows zero-day flaw dubbed "BlueHammer" could be the sign of a larger issue that security researchers face when collaborating with Microsoft on ...
Windows 11 hacked three times on day one of PWN2OWN. Update, May 17, 2025: This story, originally published May 16, has been updated with news of another successful Windows 11 hack at the Pwn2Own ...
This is the latest zero-day released by security researcher Nightmare Eclipse, despite Microsoft publicly threatening to take ...
On April 2, 2026, a security researcher using the name Chaotic Eclipse published a blog post stating that they were "doing it again." Under this warning, a link to a GitHub account page for a user ...
Forbes contributors publish independent expert analyses and insights. Davey Winder is a veteran cybersecurity writer, hacker and analyst. Update, May 15, 2025: This story, originally published May 14, ...
Rapid7’s SharePoint PoC was reportedly weaponized within a day, targeting servers vulnerable to CVE-2026-55040.
All Windows PCs come with a built-in security feature called Windows Defender Application Control (WDAC), which helps prevent unauthorized software from running by allowing only trusted applications.