Find notable cyber news and cases, enriched with sources, timelines, and signals.

Kaspersky endpoint security Windows 14.0.0.504 HardBreacher privilege escalation privilege-escalation flaw

Vulnerability
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

A public HardBreacher PoC exposes a privilege escalation in Kaspersky's endpoint security product for Windows 14.0.0.504, creating local permission-escalation risk and product instability on affected systems.

Related Happenings

DoFun Android head unit malware spread through built-in updaters

Malware Activity
H score31 First: 21.08.2026 18:41 Last: 21.08.2026 18:41 Sources 1

About this happening: Kaspersky found a supply-chain attack against Android-based DoFun car head units that used the legitimate TWCore update path to deliver JarService malware. The...

Microsoft Defender signature update fixes scan-crash bug on Windows 10 and Windows 11

Security Tool/Service
H score11 First: 19.08.2026 14:14 Last: 19.08.2026 14:14 Sources 1

About this happening: Microsoft Defender now has a fix for a crash bug that broke scans on some Windows 10 and Windows 11 systems, restoring malware protection after a recent security updat...

NightLedger, BridgeHead, and ArcBridge covert-access deployment

Malware Activity
H score23 First: 28.07.2026 14:55 Last: 28.07.2026 14:55 Sources 1

About this happening: Nimbus Manticore has expanded its covert-access malware set with NightLedger, BridgeHead, and ArcBridge in intrusions across the Middle East, Africa, and Sou...

Latest development: 26.08.2026 18:35

Group-IB found additional Tortoiseshell infrastructure spanning Europe and the Middle East, including a reverse SSH tunneling tool that masquerades as the Windows Terminal Server SDK API and connects to 172.86.98[.]113 on port 443, plus a C++ backdoor that mimics wtsapi32.dll and uses hard-coded C2 servers to download and upload files, execute binaries or DLLs, gather host information, list directories, and delete files.

HelloNet ViPNet update-abuse campaign targeting Russian organizations

Campaign
H score33 First: 19.07.2026 17:23 Last: 19.07.2026 17:23 Sources 1

About this happening: The HelloNet campaign is abusing the ViPNet update mechanism to target Russian organizations, including government agencies, with activity active since at least...

HelloInjector/HelloProxy malware activity in ViPNet update abuse

Malware Activity
H score23 First: 19.07.2026 17:23 Last: 19.07.2026 17:23 Sources 1

About this happening: HelloNet is an ongoing ViPNet update-abuse malware activity that has targeted Russian organizations in government and other sectors since at least May 2026. The lo...

Timeline

  1. 03.09.2026 09:26 2 articles · 1h ago

    Chaotic Eclipse releases HardBreacher PoC for Kaspersky endpoint security

    Initial Disclosure

    Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse, released HardBreacher, a proof-of-concept privilege escalation flaw targeting Kaspersky's endpoint security product for Windows version 14.0.0.504. The PoC reportedly is unstable and may require repeated runs, can create C:\Windows\System32\MY_SNAKE_IS_SOLID.dll with full permissions for the current user, and can make the affected Kaspersky product stop functioning while granting or blocking access to files it is not supposed to handle.

    Show sources