Cymulate researchers have uncovered critical vulnerabilities in Windows Task Scheduler (schtasks.exe) that allow attackers to gain SYSTEM-level privileges, bypass UAC prompts, and manipulate or erase audit logs. This enables privilege escalation and stealthy actions, significantly increasing risks within Windows environments, including potential data exfiltration and evasion of detection, even for low-privileged users.

400+ SAP NetWeaver Devices Vulnerable to 0-Day Attacks that Exploited in the Wild
Shadow Servers have identified 454 vulnerable SAP NetWeaver systems affected by a critical zero-day flaw, CVE-2025-31324, allowing unauthenticated file uploads and potential system compromise. Discovered