§ Archive
Month

August 2026

CM

LegacyHive Mounts Another Account’s Registry Hive Into a Session You Control, and the Write That Sets It Up Happens Where Your Auditing Isn’t

A working Windows exploit dropped roughly half an hour after July’s Patch Tuesday, with no CVE and no Microsoft advisory. LegacyHive edits a registry hive while it is unmounted, so live registry auditing never sees the write, and the payoff is another account’s hive mounted into a session the attacker controls. Here is what actually fires, what the first published rule got wrong, and which controls cut the class.

·
Artificial Intelligence

Half the Validated Prompt Injections in a Web-Scale Corpus Rode in HTTP Response Headers, Where a DOM-Only Scanner Can’t Reach

An indicator-driven study built a corpus from 1.2 billion Common Crawl URLs plus indicator-matched Censys and Shodan snapshots, and 51.2% of its 15,387 validated injections sat in custom HTTP response headers rather than page content. Here is what that number does and does not measure, why header presence is a serialization problem rather than a protocol problem, and why the representation your pipeline hands the model matters more than the header namespace.

·