Microsoft out-of-band updates fixed critical ASP.NET Core privilege escalation flaw

Microsoft fixed critical ASP.NET Core vulnerability, tracked as CVE-2026-40372 (CVSS score of 9.1), that lets attackers escalate privileges. Microsoft released out-of-band updates to address a serious ASP.NET Core vulnerability tracked as CVE-2026-40372 (CVSS score of 9.1). Microsoft fixed the flaw in ASP.NET Core version 10.0.7. An attacker could exploit the flaw to gain SYSTEM-level privileges, access […]

April 22, 2026
Read More >>

Defensive Security Podcast Episode 345

Please consider supporting the DefSec podcast here.

Links to this week’s stories:

https://www.darkreading.com/threat-intelligence/axios-attack-complex-social-engineering-industrialized
https://www.bleepingcomputer.com/news/security/new…

April 22, 2026
Read More >>

Critical BRIDGE:BREAK flaws impact Lantronix and Silex Technology converters

22 BRIDGE:BREAK flaws hit Lantronix and Silex Technology converters, exposing approximately 20,000 devices to hijacking and data tampering. Researchers at Forescout Research Vedere Labs found 22 BRIDGE:BREAK flaws in serial-to-IP devices from Lantronix and Silex Technology. Serial-to-IP converters, also known as serial device servers, connect legacy serial equipment to modern IP networks for remote monitoring […]

April 22, 2026
Read More >>

Tesla is Pouring Cancer Into Texas

Hexavalent chromium. Arsenic. Where? Tesla’s lithium refinery wastewater near Corpus Christi. In a ditch. Both are IARC Group 1 carcinogens. Both are absent from Tesla’s state wastewater permit. Why can Group 1 carcinogens be dumped by Tesl…

April 22, 2026
Read More >>

Cash is Back, Baby!

Australians are using more cash, because cash is cool. Cash is availability. Cash is privacy. The Reserve Bank of Australia survey shows the share rising for regular purchases after two decades of displacement by payment card brand pressure. Two-thirds…

April 22, 2026
Read More >>