Kaspersky endpoint security Windows 14.0.0.504 HardBreacher privilege escalation privilege-escalation flaw
Vulnerability
Summary
Hide ▲
Show ▼
A public HardBreacher PoC exposes a privilege escalation in Kaspersky's endpoint security product for Windows 14.0.0.504, creating local permission-escalation risk and product instability on affected systems.
Related Happenings
DoFun Android head unit malware spread through built-in updaters
Malware Activity
H score31
First: 21.08.2026 18:41
Last: 21.08.2026 18:41
Sources 1
About this happening:
Kaspersky found a supply-chain attack against Android-based DoFun car head units that used the legitimate TWCore update path to deliver JarService malware. The...
DoFun Android head unit malware spread through built-in updaters
Malware ActivityAbout this happening: Kaspersky found a supply-chain attack against Android-based DoFun car head units that used the legitimate TWCore update path to deliver JarService malware. The...
Microsoft Defender signature update fixes scan-crash bug on Windows 10 and Windows 11
Security Tool/Service
H score11
First: 19.08.2026 14:14
Last: 19.08.2026 14:14
Sources 1
About this happening:
Microsoft Defender now has a fix for a crash bug that broke scans on some Windows 10 and Windows 11 systems, restoring malware protection after a recent security updat...
Microsoft Defender signature update fixes scan-crash bug on Windows 10 and Windows 11
Security Tool/ServiceAbout this happening: Microsoft Defender now has a fix for a crash bug that broke scans on some Windows 10 and Windows 11 systems, restoring malware protection after a recent security updat...
NightLedger, BridgeHead, and ArcBridge covert-access deployment
Malware Activity
H score23
First: 28.07.2026 14:55
Last: 28.07.2026 14:55
Sources 1
About this happening:
Nimbus Manticore has expanded its covert-access malware set with NightLedger, BridgeHead, and ArcBridge in intrusions across the Middle East, Africa, and Sou...
NightLedger, BridgeHead, and ArcBridge covert-access deployment
Malware ActivityAbout this happening: Nimbus Manticore has expanded its covert-access malware set with NightLedger, BridgeHead, and ArcBridge in intrusions across the Middle East, Africa, and Sou...
Latest development: 26.08.2026 18:35
Group-IB found additional Tortoiseshell infrastructure spanning Europe and the Middle East, including a reverse SSH tunneling tool that masquerades as the Windows Terminal Server SDK API and connects to 172.86.98[.]113 on port 443, plus a C++ backdoor that mimics wtsapi32.dll and uses hard-coded C2 servers to download and upload files, execute binaries or DLLs, gather host information, list directories, and delete files.
HelloNet ViPNet update-abuse campaign targeting Russian organizations
Campaign
H score33
First: 19.07.2026 17:23
Last: 19.07.2026 17:23
Sources 1
About this happening:
The HelloNet campaign is abusing the ViPNet update mechanism to target Russian organizations, including government agencies, with activity active since at least...
HelloNet ViPNet update-abuse campaign targeting Russian organizations
CampaignAbout this happening: The HelloNet campaign is abusing the ViPNet update mechanism to target Russian organizations, including government agencies, with activity active since at least...
HelloInjector/HelloProxy malware activity in ViPNet update abuse
Malware Activity
H score23
First: 19.07.2026 17:23
Last: 19.07.2026 17:23
Sources 1
About this happening:
HelloNet is an ongoing ViPNet update-abuse malware activity that has targeted Russian organizations in government and other sectors since at least May 2026. The lo...
HelloInjector/HelloProxy malware activity in ViPNet update abuse
Malware ActivityAbout this happening: HelloNet is an ongoing ViPNet update-abuse malware activity that has targeted Russian organizations in government and other sectors since at least May 2026. The lo...
Timeline
-
03.09.2026 09:26 2 articles · 1h ago
Chaotic Eclipse releases HardBreacher PoC for Kaspersky endpoint security
Initial DisclosureChaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse, released HardBreacher, a proof-of-concept privilege escalation flaw targeting Kaspersky's endpoint security product for Windows version 14.0.0.504. The PoC reportedly is unstable and may require repeated runs, can create C:\Windows\System32\MY_SNAKE_IS_SOLID.dll with full permissions for the current user, and can make the affected Kaspersky product stop functioning while granting or blocking access to files it is not supposed to handle.
Show sources
- Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon — thehackernews.com — 03.09.2026 09:26
- Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon — thehackernews.com — 03.09.2026 09:26