Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence

Claw Chain flaws in OpenClaw 2026.4.22 enable data theft, privilege escalation, and persistence when chained.

The Hacker News
Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own

​During the second day of Pwn2Own Berlin 2026, competitors collected $385,750 in cash awards after exploiting 15 unique zero-day vulnerabilities in multiple products, including Windows 11, Microsoft Exchange, and Red Hat Enterprise Linux for Workstations.

BleepingComputer
NGINX Rift Heap Buffer Overflow https://packetstorm.news/files/221121 #exploit
Packet Storm

Information Security Services, News, Files, Tools, Exploits, Advisories, and Whitepapers

Microsoft Exchange: Zero-Day-Lücke wird angegriffen

In Microsofts Exchange klafft eine Zero-Day-Lücke, die Angreifer bereits missbrauchen. Admins sollten rasch handeln.

https://www.heise.de/news/Microsoft-Exchange-Zero-Day-Luecke-wird-angegriffen-11295799.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon

#XSS #Cyberangriff #MicrosoftExchange #Exploit #IT #Microsoft #Security #news

Microsoft Exchange: Zero-Day-Lücke wird angegriffen

In Microsofts Exchange klafft eine Zero-Day-Lücke, die Angreifer bereits missbrauchen. Admins sollten rasch handeln.

heise online

First public macOS kernel memory corruption exploit on Apple M5 (calif.io)

https://blog.calif.io/p/first-public-kernel-memory-corruption

#macos #kernel #bug #exploit #m5 #apple #mythos

First public macOS kernel memory corruption exploit on Apple M5

Apple spent five years building hardware and software to make memory corruption exploits dramatically harder. Our engineers, working together with Mythos Preview, built a working exploit in five days.

Calif
A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens

We recently published an exploit chain for the Google Pixel 9 that demonstrated it was possible t...

Zero-day exploit completely defeats default Windows 11 BitLocker protections

It's not entirely clear how the exploit works. Microsoft says it's investigating.

Ars Technica

We urgently need information on bug reporting and #responsibleDisclosure process that is available and easily understandable.

There should be a web page with resources in text and video form with examples on how to do this right.

I am fed up by people, exposing #security issues with a working #exploit out in the wild before affected bodies had the possibility to respond accordingly.

But why? BECAUSE!

#informationsecurity #floss #opensource #advisory

AI Notkilleveryoneism Memes (@AISafetyMemes)

Mythos가 5일 만에 macOS를 크랙했다는 주장과 함께, MacOS/iOS급 제로데이는 매우 고가이며 기존 최고 수준 팀도 상당한 시간이 걸린다는 점을 강조한다. 다만 구체적 기술 내용은 제한적이지만 보안 연구/취약점 시장의 위협 규모를 시사한다.

https://x.com/AISafetyMemes/status/2055008395162497038

#macos #security #zeroday #exploit

AI Notkilleveryoneism Memes ⏸️ (@AISafetyMemes) on X

Mythos cracked MacOS in 5 days WHY THIS MATTERS: - It takes Google Project Zero - the most prestigious bug-finding team in the world - ***6 months*** per zero-day at the MacOS/iOS level - MacOS zero-days are worth ~$2 million+ each - Apple's threat model assumed a world with

X (formerly Twitter)
A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens

We recently published an exploit chain for the Google Pixel 9 that demonstrated it was possible t...