Saturday 27 June 2026 00:18:14 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContact
EnglishItalianoArabic

#script execution


Fake Updates, Real Risk: The macOS Lure That Turns Trust Into Execution

Published: 17 June 2026 12:49Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A macOS targeting campaign shows how a convincing prompt can matter more than a technical exploit when attackers are trying to make the victim run the payload themselves.

npm 12 Tightens the Gates on Dependency Scripts

Published: 13 June 2026 18:02Category: Technology, Innovation & Digital InfrastructureGeo: North America / USAAuthor: TRUSTBREAKER

A coming default change will stop dependency scripts from running during npm install unless they are explicitly allowed, shifting a long-standing trust decision from automatic to deliberate.

Exchange’s New OWA Flaw Shows How One Email Can Turn Into Browser Risk

Published: 11 June 2026 11:47Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

CVE-2026-42897 is a reminder that a mail server bug can become a web attack when Outlook Web Access is part of the path, and that patch timing matters as much as the vulnerability itself.

The Hosting Add-On That Turned cPanel Access Into a Root-Level Risk

Published: 23 May 2026 14:08Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

A zero-day in the LiteSpeed user-end cPanel plugin shows how one small control-panel extension can become a server-wide escalation path.

When a Hosting Convenience Tool Crosses the Line Into Root Control

Published: 23 May 2026 12:14Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

CVE-2026-48172 turns a user-facing LiteSpeed cPanel feature into a privilege-boundary failure, showing how backend trust mistakes can collapse into server-level risk.

MSHTA Still Opens a Quiet Door for Windows Intruders

Published: 21 May 2026 17:58Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A legacy Microsoft utility can still be turned into a stealthy execution path, showing that retiring Internet Explorer does not retire every browser-era risk.