BlackTree Security · Infrastructure · Automation · AI

News

News

ShieldBreak Shows Why “Patched” Is Not the Same as Fixed

ShieldBreak patch bypass concept: the Microsoft logo on a patched shield while an alternate attack path reaches a managed Windows endpoint fleet

ShieldBreak is now CVE-2026-69414, a Microsoft Defender elevation-of-privilege vulnerability assessed as exploitation more likely and still awaiting a verifiable fix. This update separates it from RoguePlanet CVE-2026-50656, explains the different CFAPI attack path, conflicting Windows 11 reproduction results, affected-build uncertainty, and the operational controls security teams should use instead of treating patch deployment as proof that exposure is fixed.

Belgium’s Digital ID Trust Layer Was One Download Away From RCE

Belgian flag beside an eID smart card and browser-extension attack chain

Researchers found that Belgium’s widely used Connective signing extension could expose eID and Maestro card data, recover PINs and execute attacker-controlled code through its native host. The flaws were fixed in July, but the case shows how a powerful browser extension can quietly undermine an otherwise strong national identity system.

CVE-2026-68820 Turns a Windows Foothold Into SYSTEM

Red exploit path crossing a Windows network-driver layer into a privileged kernel core

Microsoft’s August 2026 updates fix a WinSock privilege-escalation flaw used by North Korea’s Lazarus group against defence, aerospace and aviation organisations. The exploit helped Operation Dream Job turn a local Windows foothold into SYSTEM access, deploy a kernel rootkit and interfere with endpoint-security controls.