Security researchers at Graz University of Technology have discovered that standard file-change notification systems in Linux, Windows, Android, and macOS can be weaponized by unprivileged local processes to monitor user behavior. Without requiring administrative access, bad actors can observe file names and event timing to reconstruct sensitive activities, such as keystroke rhythms (with over 93% accuracy), website browsing histories, and media exchanges on apps like WhatsApp. While the attacks...
Read More
21Sep
Austin Armstrong |
21 Sep, 2026
|
GitLab,
ConnectWise,
ScreenConnect,
JFrog,
Vite,
WSO2,
Acronis,
Active Exploits,
RCE,
Privilege Escalation,
Authentication Bypass,
Credential Theft,
CISA KEV,
Vulnerability Management,
Threat Intelligence,
DevSecOps,
Enterprise Security,
Patch Management |
CISA is tracking a surge in actively exploited vulnerabilities across enterprise software, development tools, and remote access platforms. Threat actors are targeting unpatched systems like GitLab, VMware vCenter, and ConnectWise ScreenConnect to deploy ransomware, steal cloud credentials, and establish persistent backdoors. Organizations must prioritize immediate patching and verify the security posture of third-party integrations before attackers automate these exploits at scale.
Read More