Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

Cyber Kendra
cyberkendra.com > 2026 > 09 > falconflank-zero-day-hits-crowdstrike.html

FalconFlank Zero-Day Hits CrowdStrike Falcon Sensor

1+ day, 7+ hour ago   (281+ words) A security researcher known as Chaotic Eclipse has released FalconFlank, a proof-of-concept zero-day that escalates privileges on fully patched Windows machines running CrowdStrike Falcon. The researcher — who also uses the aliases Nightmare-Eclipse, MSNightmare, and INFINITE NIGHTMARE — published working exploit code…...

Cyber Kendra
cyberkendra.com > 2026 > 09 > chatgpt-claude-grok-outage-two-causes.html

ChatGPT, Claude, Grok Outage: Two Causes, Not One

1+ day, 6+ hour ago   (473+ words) Updated 5 September 2026: SpaceXAI has confirmed that the Grok outage of 3 September 2026 began at its Memphis compute center, and an OpenAI engineer says the ChatGPT failure that morning was a separate routing error. Neither company has published a full technical postmortem....

Cyber Kendra
cyberkendra.com > 2026 > 08 > stale-github-token-let-chaindrop-worm.html

Stale GitHub Token Let ChainDrop Worm Poison Keyv, Cacheable

5+ day, 14+ hour ago   (298+ words) Jared Wray, founder and CEO of Hyphen AI and maintainer of the Keyv and Cacheable npm packages, has published a postmortem confirming that a stale full-access GitHub personal access token was the entry point for the ChainDrop supply chain worm....

Cyber Kendra
cyberkendra.com > 2026 > 08 > prettyprague-zero-day-exploit-hits.html

PrettyPrague Zero-Day Exploit Hits Avast Antivirus

5+ day, 14+ hour ago   (245+ words) A security researcher known as Chaotic Eclipse has released a working proof-of-concept exploit for an unpatched privilege escalation vulnerability in Avast Antivirus, the consumer security suite owned by Gen Digital. The exploit, named PrettyPrague, abuses a flaw in the Avast…...

Cyber Kendra
cyberkendra.com > 2026 > 08 > virtualizor-compromised-via-bgp-hijack.html

Virtualizor Compromised via BGP Hijack, Hosts Hit Hard

5+ day, 15+ hour ago   (141+ words) cyberkendra.com A BGP hijack against Virtualizor's update infrastructure pushed a malicious package onto VPS hypervisors running the panel, handing attackers root on every node that installed it. Hosting provider DreamIT raised the alarm on LowEndTalk shortly after midnight on…...

Cyber Kendra
cyberkendra.com > 2026 > 08 > why-speed-not-volume-decides-your.html

Why Speed, Not Volume Decides Your Exposure Window

5+ day, 16+ hour ago   (749+ words) Vulnerability exploitation timelines have been falling steadily for years. Frontier AI tools have made them collapse. The exposure window - the time between vulnerability disclosure and remediation - has all but disappeared. This new reality leaves vulnerability management (VM) teams in something of…...

Cyber Kendra
cyberkendra.com > 2026 > 08 > signal-contact-discovery-enclave-flaws.html

Signal Contact Discovery Enclave Flaws Allow Code Execution

1+ week, 3+ day ago   (478+ words) This matters more than it might sound. Per V12, the Signal apps on Android and iOS submit the user's address book to CDSI every 48 hours, and the feature is enabled by default. Because ORAM is computationally expensive, CDSI splits queries across…...

Cyber Kendra
cyberkendra.com > 2026 > 08 > top-5-osint-services-for-uk-businesses.html

Top 5 OSINT Services for UK Businesses in 2026

2+ week, 2+ day ago   (564+ words) A fraud team we heard about nearly signed a six-figure supplier contract with a company that, as it turned out, didn't exist past a website and a LinkedIn page. One afternoon of digging found the gap. That's the entire pitch…...

Cyber Kendra
cyberkendra.com > 2026 > 08 > elementor-pro-rce-flaw-cve-2026-32475.html

Elementor Pro RCE Flaw CVE-2026-32475 Hits Form Uploads

2+ week, 3+ day ago   (247+ words) A critical flaw in Elementor Pro lets an unauthenticated visitor upload a PHP file through an ordinary contact form and execute it on the server. Researcher Tin Pham, also known as TF1T, reported the bug to Patchstack, and Elementor shipped the…...

Cyber Kendra
cyberkendra.com > 2026 > 08 > t-mobile-cut-cable-to-eject-salt.html

T-Mobile Cut Cable to Eject Salt Typhoon Hackers

2+ week, 3+ day ago   (236+ words) T-Mobile ended its months-long hunt for Salt Typhoon in November 2024 by driving to a data center and physically cutting the network cable feeding a compromised router. Jeff Simon — the carrier's chief security officer during the campaign and now its chief…...