June 28, 2026
- CVE-2026-45504 lets any low-privileged Microsoft Exchange user read arbitrary files from the system without authorization; a write-up and working PoC are public. HawkTrace · Vulnerabilities & Exploits
in A WHQL-Signed Kernel Backdoor Hides in a WFP Callout as a "Clean" GitHub Repo Pwns AI Coding Agents