Back

Vulnerability

vulnerability

Six Zero-Days in Six Weeks: Inside Chaotic Eclipse's Windows Exploit Spree

A researcher publishing as Chaotic Eclipse has released six Windows zero-days since April 2026 — escalation flaws, a BitLocker bypass, and a post-exploitation tool — each one following a failed or incomplete vendor response. The latest, MiniPlasma, escalates to SYSTEM on fully patched Windows 11 using a bug Microsoft believed it fixed in 2020.

vulnerability

The Auth Check Is the Attack Surface

A pre-authentication SQL injection in LiteLLM's API key verification path gave attackers read/write access to every credential the proxy manages — and the 401 it returned made each successful query look like a failed login.

vulnerability

When the Firewall Is the Vulnerability

CVE-2026-0300 gives an unauthenticated attacker root-level code execution on PAN-OS firewalls — no credentials, no interaction required. Here's how the Captive Portal became the entry point, what the attackers did next, and why owning the perimeter is a different category of problem.