Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIResearchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
Security researchers at Nebula Security disclosed CVE-2026-10702, a high-severity Firefox JIT (Just-In-Time compiler) vulnerability that enables arbitrary code execution through a single malicious webpage visit, requiring no user interaction. The flaw affected both Firefox and Tor Browser, with Mozilla addressing it in Firefox version 151.0.3. The zero-click nature of the exploit makes it particul
AINightmare-Eclipse Drops Yet Another Microsoft Exploit, RoguePlanet
A researcher known as Nightmare-Eclipse has released another proof-of-concept exploit, this time targeting a Windows Defender vulnerability dubbed RoguePlanet that enables system takeover. This release continues an ongoing dispute between the researcher and Microsoft, with no indication of resolution.
AIGoogle June 2026 Android Update Patches 124 Flaws, One Actively Exploited
Google's June 2026 Android security update addresses 124 vulnerabilities, including CVE-2025-48595, a high-severity privilege escalation flaw in the Framework component that is being actively exploited in the wild. The vulnerability, with a CVSS score of 8.4, requires no user interaction, making it particularly dangerous for enterprise Android deployments.
AIIvanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Access
Ivanti has issued a warning about CVE-2026-6973, a high-severity remote code execution vulnerability in Endpoint Manager Mobile (EPMM) that is being actively exploited in limited attacks. The flaw, caused by improper input validation, allows authenticated users with administrative access to execute remote code on affected systems running EPMM versions prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1.
