RegPwn” (CVE-2026-24291), identified by MDSec, is a newly fixed Elevation of Privilege flaw impacting Microsoft Windows. It enables a low-privileged user to escalate privileges and gain full SYSTEM-level access by exploiting how Windows manages registry data for built-in accessibility features.Accessibility tools like the On-Screen Keyboard and Narrator run with high integrity to function across applications, even though they operate in the user’s context. When these tools are used, Windows creates registry entries to store configuration settings. The flaw lies in how these registry keys are handled and transferred between user-level and SYSTEM-level processes. During login, Windows grants users write access to a specific accessibility related registry key in the Local Machine hive. When the system switches to the Secure Desktop (e.g., during a lock screen or User Account Control prompt), two instances of atbroker.exe are launched one under the user account and another under the SYSTEM account. These processes copy configuration data from user-controlled registry locations to protected SYSTEM registry areas. An attacker can exploit this behavior using registry symbolic links. By carefully timing the operation—often aided by file locks on related XML files they can redirect the SYSTEM process to write malicious data to arbitrary registry locations. This can allow overwriting critical settings, such as service image paths, leading to execution of attacker-controlled code with SYSTEM privileges.The exploit requires precise timing but has been proven effective in real-world red team scenarios since early 2025. With proof-of-concept code now publicly available, Microsoft patched the issue in its March 2026 Patch Tuesday update. Immediate system updates are strongly recommended to mitigate active exploitation risk
Charter Communications has confirmed a cybersecurity incident impacting millions of customers following a breach allegedly conducted by the ShinyHunters extortion gang. According t...
A critical Remote Code Execution (RCE) vulnerability has been identified in Samba, the widely used open-source SMB/CIFS file-sharing software for Linux and Unix systems. The flaw c...
A sophisticated cyber-espionage campaign linked to the Iran-aligned threat group Seedworm has targeted at least nine organizations across multiple countries during early 2026. The ...