Npav Lab
-
Read moreA severe MongoDB vulnerability (CVE-2026-8053) enables attackers to execute arbitrary code on affected servers, risking full system takeover and data theft. Self-hosted deployments must patch immediately to prevent potential exploitation.
-
Read moreA newly disclosed Windows zero-day vulnerability named MiniPlasma affects the Cloud Files Mini Filter Driver (cldflt.sys), allowing attackers to gain SYSTEM privileges on fully patched Windows systems. The flaw is reportedly still unpatched despite prior fixes and can be reliably exploited under certain conditions.
-
Read moreDell confirms a SupportAssist update is causing blue-screen crashes and random reboots on Windows 10 and Windows 11 systems. Users are advised to remove the affected service.
-
Read moreMicrosoft warns of a new Microsoft Teams Android vulnerability that could allow spoofing attacks on local devices. Update immediately to stay protected.
-
Read moreCybersecurity researchers have discovered fake GitHub repositories impersonating DeepSeek TUI to deliver malware. The campaign uses compressed archives and multi-stage payloads to bypass detection, disable Windows Defender, and establish persistent access on infected systems.
-
Posted: May 12, 2026Views: 124Read moreCybersecurity researchers uncovered 28 fake Android apps on Google Play Store with over 7.3 million downloads that falsely promised call history access. Instead, the apps tricked users into subscriptions and generated fake data, leading to financial losses, mainly targeting users in India and APAC.
-
Read moreA data breach involving NVIDIA GeForce NOW provider GFN.AM exposed user personal information, raising concerns over phishing and identity fraud attacks.
-
Read moreHackers are using fake Claude AI installer pages and Google Ads to spread malware, steal credentials, and infect Windows and macOS systems.
-
Read moreHackers compromised official DAEMON Tools installers with malware in a major supply chain attack affecting users worldwide. Learn how to stay protected.
-
Read moreA critical PAN-OS vulnerability (CVE-2026-0300) in the User-ID Captive Portal allows unauthenticated remote code execution with root privileges. Limited exploitation has been linked to state-sponsored activity involving log tampering, Active Directory enumeration, and deployment of tunneling tools like EarthWorm and ReverseSocks5.