Category: Vulnerability

  • New Google Gemini Vulnerability Exploited via Prompt Injections from WhatsApp, Slack, and SMS

    New Google Gemini Vulnerability Exploited via Prompt Injections from WhatsApp, Slack, and SMS A new class of indirect prompt injection (IPI) attacks targets Google Gemini’s voice assistant, allowing attackers to silently hijack the AI through malicious payloads delivered via everyday messaging apps, including WhatsApp, Slack, Signal, SMS, Instagram, and Messenger. The research, led by Or…

  • Smashing Security podcast #470: This AI security flaw might be impossible to fix

    Smashing Security podcast #470: This AI security flaw might be impossible to fix A website called “UK visa portal” has been quietly collecting passport scans, selfies, and personal data from thousands of travellers who thought they were applying through official channels. They weren’t. And when a journalist tried to warn the company, it was lawyers…

  • HTTP/2 Bomb — Remote DoS Exploit Hits nginx, Apache, IIS, Envoy, and Cloudflare Pingora

    HTTP/2 Bomb — Remote DoS Exploit Hits nginx, Apache, IIS, Envoy, and Cloudflare Pingora A newly disclosed remote denial-of-service exploit dubbed “HTTP/2 Bomb” targets the default HTTP/2 configurations of the world’s most widely deployed web servers, nginx, Apache httpd, Microsoft IIS, Envoy, and Cloudflare Pingora, enabling a single attacker on a home internet connection to…

  • 1-Click GitHub Token Vulnerability Lets Attackers Steal Users’ OAuth Tokens

    1-Click GitHub Token Vulnerability Lets Attackers Steal Users’ OAuth Tokens A critical security vulnerability in Visual Studio Code’s webview implementation allows attackers to steal GitHub OAuth tokens, including read/write access to private repositories, simply by tricking a victim into clicking a single malicious link. The bug was publicly disclosed on June 2, 2026, by security…

  • Police arrest man following hack of Ajax football club

    Police arrest man following hack of Ajax football club Dutch police have arrested a 35-year-old man suspected of hacking into the computer systems of Amsterdam football giant Ajax, after the personal data of hundreds of thousands of supporters was put at risk. Read more in my article on the Hot for Security blog. Graham Cluley…

  • Critical Notepad++ Vulnerabilities Allow Attackers to Execute Arbitrary Code

    Critical Notepad++ Vulnerabilities Allow Attackers to Execute Arbitrary Code Notepad++, one of the most widely used open-source text editors for Windows, has released an urgent security update addressing three vulnerabilities, including two arbitrary code execution flaws that could allow attackers to silently run malicious programs on a victim’s machine. The Notepad++ development team released version…

  • CISA Warns of Drupal Core SQL Injection Vulnerability Exploited in Attacks

    CISA Warns of Drupal Core SQL Injection Vulnerability Exploited in Attacks CISA has issued an urgent alert regarding a critical SQL injection vulnerability in Drupal Core, tracked as CVE-2026-9082, which is now being actively exploited in real-world attacks. The flaw, classified under CWE-89, affects Drupal’s database abstraction API and could allow attackers to execute malicious…

  • Google Publishes Exploit Code for Unfixed Chromium Bug Exposing Millions of Users

    Google Publishes Exploit Code for Unfixed Chromium Bug Exposing Millions of Users Google has publicly released proof-of-concept (PoC) exploit code for a critical, still-unpatched vulnerability in the Chromium codebase, potentially exposing millions of users across Chrome, Microsoft Edge, and other Chromium-based browsers to stealthy botnet-style abuse. The vulnerability, originally reported in late 2022 by independent…

  • Defenders fall behind, as AI rewrites the rules of a data breach

    Defenders fall behind, as AI rewrites the rules of a data breach For almost 20 years, stolen credentials have been the most common route for attackers into organizations, according to the Verizon Data Breach Investigations Report (DBIR). But that’s no longer the case. Read more in my article on the Fortra blog. Graham Cluley Go…

  • New Microsoft Defender 0‑Days Actively Exploited in the Wild

    New Microsoft Defender 0‑Days Actively Exploited in the Wild Two newly disclosed Microsoft Defender vulnerabilities are being actively exploited in the wild, enabling local attackers to elevate privileges to SYSTEM and potentially disrupt endpoint protection across Windows environments. The bugs, tracked as CVE‑2026‑41091 (Elevation of Privilege) and CVE‑2026‑45498 (Denial of Service), were published on May…

  • Smashing Security podcast #468: High-speed train hacks and homicidal lawnmowers

    Smashing Security podcast #468: High-speed train hacks and homicidal lawnmowers A 23-year-old radio enthusiast spent £300 on a piece of kit from the internet, and used it to bring four packed high-speed trains to a screeching halt. His defence in court? Possibly the most creative excuse we’ve heard all year. Meanwhile, owners of $4,000 robot…

  • First Public macOS Kernel Exploit on Apple M5 Prepared Using Mythos Preview in Five Days

    First Public macOS Kernel Exploit on Apple M5 Prepared Using Mythos Preview in Five Days Apple’s M5 silicon has reportedly been exploited for the first time in a public macOS kernel memory corruption attack, successfully bypassing the company’s notable hardware-level memory protection. Researchers from Calif, Bruce Dang, Dion Blazakis, and Josh Maine, developed a working…

  • Malicious JPEG Images Could Trigger PHP Memory Safety Vulnerabilities

    Malicious JPEG Images Could Trigger PHP Memory Safety Vulnerabilities Two critical memory-safety vulnerabilities in PHP’s image-processing functions could allow attackers to leak sensitive heap memory or to execute denial-of-service attacks via specially crafted JPEG files. The flaws, discovered in PHP’s ext/standard extension by Positive Technologies researcher Nikita Sveshnikov, affect the widely-used getimagesize and iptcembed functions…

  • Critical Linux Kernel Flaw ‘ssh-keysign-pwn’ Exposes SSH Keys and Shadow Passwords

    Critical Linux Kernel Flaw ‘ssh-keysign-pwn’ Exposes SSH Keys and Shadow Passwords A newly disclosed Linux kernel vulnerability is raising serious concerns across the security community, as it allows attackers to access highly sensitive data, including SSH private keys and password hashes, on affected systems. Tracked as CVE-2026-46333, the flaw has been nicknamed “ssh-keysign-pwn” and impacts a wide range…

  • VMware Fusion Vulnerability Let Attackers Escalate Privilege to Root

    VMware Fusion Vulnerability Let Attackers Escalate Privilege to Root A high-severity privilege escalation vulnerability has been discovered in VMware Fusion, Broadcom’s popular macOS virtualization software, allowing local attackers to gain root-level access on affected systems. Tracked as CVE-2026-41702, the flaw was privately reported to Broadcom and patched on May 14, 2026, under security advisory VMSA-2026-0003.…

  • Critical Microsoft Exchange Server Vulnerability Actively Exploited in Attacks

    Critical Microsoft Exchange Server Vulnerability Actively Exploited in Attacks Microsoft issued an urgent security alert regarding a newly discovered vulnerability in Exchange Server that is currently being exploited in the wild. Tracked as CVE-2026-42897, this critical spoofing flaw carries a high CVSS 3.1 severity score of 8.1 and directly impacts on-premises email infrastructure. Threat actors…

  • PoC Exploit Released for Android Zero-Click Vulnerability that Enables Remote Shell Access

    PoC Exploit Released for Android Zero-Click Vulnerability that Enables Remote Shell Access In a chilling blow to mobile security, Google’s May 2026 Android Security Bulletin has unmasked a catastrophic zero-click vulnerability lurking within the core Android System. The CVE-2026-0073 flaw in Android’s adbd daemon lets nearby threat actors remotely gain full shell access without victim…

  • New cPanel and WHM Flaws Enable Code Execution, DoS Attacks

    New cPanel and WHM Flaws Enable Code Execution, DoS Attacks cPanel has disclosed three critical security vulnerabilities tracked as CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203 affecting its widely deployed cPanel & WHM web hosting control panel and WP Squared (WP2) platform. The flaws, patched on May 8, 2026, expose servers to arbitrary file reads, Perl code injection,…

  • Critical Microsoft 365 Copilot Vulnerabilities Expose sensitive Information

    Critical Microsoft 365 Copilot Vulnerabilities Expose sensitive Information Microsoft has disclosed and fully remediated three critical information disclosure vulnerabilities affecting Microsoft 365 Copilot and Copilot Chat in Microsoft Edge, all released on May 7, 2026, requiring no action from end users or administrators. Microsoft’s Security Response Center published advisories for CVE-2026-26129, CVE-2026-26164, and CVE-2026-33111 as…

  • Mozilla Patches 423 Firefox 0-Day Vulnerabilities with Claude Mythos and Other AI Models

    Mozilla Patches 423 Firefox 0-Day Vulnerabilities with Claude Mythos and Other AI Models Mozilla has fixed a total of 423 Firefox security bugs in April 2026 alone, a figure nearly 20 times higher than its monthly average of about 21 bugs throughout 2025, driven by a groundbreaking agentic AI pipeline built around Anthropic’s Claude Mythos…

  • Dirty Frag Linux Vulnerability Let Attackers Gain Root Privileges – PoC Released

    Dirty Frag Linux Vulnerability Let Attackers Gain Root Privileges – PoC Released Dirty Frag is a newly disclosed, CVE-pending Linux kernel local privilege escalation (LPE) vulnerability that chains two separate page-cache write flaws, the xfrm-ESP Page-Cache Write and the RxRPC Page-Cache Write, to achieve root access on virtually all major Linux distributions, with a public exploit…

  • Multiple Critical Vulnerabilities Patched in Next.js and React Server Components

    Multiple Critical Vulnerabilities Patched in Next.js and React Server Components Vercel has released an extensive set of security advisories for Next.js, addressing more than a dozen vulnerabilities, including denial-of-service, middleware bypass, server-side request forgery, and cross-site scripting. The flaws affect Next.js versions 13.x through 16.x using the App Router, as well as React Server Components…

  • Smashing Security podcast #466: Meta sees everything, Copy Fail, and a deepfake gets hired

    Smashing Security podcast #466: Meta sees everything, Copy Fail, and a deepfake gets hired Meta’s smart glasses promise privacy “designed for you” – but everything they record was being beamed off to workers in Nairobi to label by hand. When those workers blew the whistle, Meta sacked all 1,108 of them. Meanwhile, the IT press…

  • Critical Palo Alto Firewalls Vulnerability Exploited in the Wild to Gain Root Access

    Critical Palo Alto Firewalls Vulnerability Exploited in the Wild to Gain Root Access Palo Alto Networks has disclosed a critical buffer overflow vulnerability in PAN-OS software, tracked as CVE-2026-0300, that is already being actively exploited in the wild. The flaw carries a CVSS 4.0 score of 9.3 (CRITICAL) and allows unauthenticated attackers to execute arbitrary…

  • Microsoft Edge Stores All Saved Passwords in Cleartext Process Memory at Launch

    Microsoft Edge Stores All Saved Passwords in Cleartext Process Memory at Launch A security researcher has discovered that Microsoft Edge decrypts every stored password into process memory the moment the browser launches and keeps them there as cleartext, regardless of whether the user ever visits those sites. The finding, disclosed on April 29 by PaloAltoNtwks…

  • Critical Apache HTTP Server Flaw Exposes Millions of Servers to RCE Attacks

    Critical Apache HTTP Server Flaw Exposes Millions of Servers to RCE Attacks The Apache Software Foundation has released a critical security update for Apache HTTP Server, patching five vulnerabilities, including a dangerous double-free flaw capable of enabling Remote Code Execution (RCE) in version 2.4.67, released on May 4, 2026. All users running version 2.4.66 or…

  • cPanelSniper – PoC Exploit Disclosed for cPanel Vulnerability, 44,000 Servers Compromised

    cPanelSniper – PoC Exploit Disclosed for cPanel Vulnerability, 44,000 Servers Compromised A weaponized proof-of-concept (PoC) exploit framework dubbed “cPanelSniper” has been publicly released for CVE-2026-41940, a maximum-severity authentication bypass in cPanel & WHM that has already led to the compromise of tens of thousands of servers worldwide with attack activity traced as far back as…

  • Alleged Silk Typhoon hacker extradited to the United States to face charges

    Alleged Silk Typhoon hacker extradited to the United States to face charges A man accused of working as a hacker for China’s Ministry of State Security has been extradited to the USA from Italy, and faces – if found guilty – the prospect of decades behind bars. Read more in my article on the Hot…

  • Critical Pack2TheRoot Vulnerability Let Attackers Gain Root Access or Compromise the System

    Critical Pack2TheRoot Vulnerability Let Attackers Gain Root Access or Compromise the System A high-severity privilege escalation vulnerability, dubbed Pack2TheRoot (CVE-2026-41651, CVSS 3.1: 8.8), has been publicly disclosed by Deutsche Telekom’s Red Team, affecting multiple major Linux distributions in their default installations. The flaw allows any local unprivileged user to silently install or remove system packages,…

  • Smashing Security podcast #464: Rockstar got hacked. The data was junk. The secrets it revealed were not

    Smashing Security podcast #464: Rockstar got hacked. The data was junk. The secrets it revealed were not A company that ran anonymous tip lines for 35,000 American schools – handling reports of bullying, weapons, and self-harm – boasted on its website that it had suffered zero security breaches in over 20 years. A hacker called…

  • Critical Atlassian Bamboo Data Center and Server Flaw Enables Command Injection Attacks

    Critical Atlassian Bamboo Data Center and Server Flaw Enables Command Injection Attacks Atlassian has disclosed two significant security vulnerabilities affecting its Bamboo Data Center and Server product, including a critical OS command injection flaw and a high-severity denial-of-service issue tied to a third-party dependency. Organizations running affected versions are strongly urged to apply patches immediately.…

  • CrowdStrike LogScale Vulnerability Allows Remote Attackers to Read Arbitrary Files from Server

    CrowdStrike LogScale Vulnerability Allows Remote Attackers to Read Arbitrary Files from Server CrowdStrike has issued an urgent security advisory for a critical unauthenticated path-traversal vulnerability (CVE-2026-40050) affecting its LogScale platform, warning that a remote attacker could exploit the flaw to read arbitrary files directly from the server’s filesystem without authentication. The vulnerability resides in a…

  • Claude Code, Gemini CLI, and GitHub Copilot Vulnerable to Prompt Injection via GitHub Comments

    Claude Code, Gemini CLI, and GitHub Copilot Vulnerable to Prompt Injection via GitHub Comments A critical cross-vendor vulnerability class dubbed “Comment and Control” is a new category of prompt injection attacks that weaponizes GitHub pull request titles, issue bodies, and issue comments to hijack AI coding agents and steal API keys and access tokens directly from CI/CD…

  • Smashing Security podcast #463: This AI company leaked its own code. It’s also built something terrifying

    Smashing Security podcast #463: This AI company leaked its own code. It’s also built something terrifying A hacking group claims to have broken into the flood defence system protecting Venice’s Piazza San Marco – and is offering to sell access to whoever wants it. The asking price? A frankly insulting $600. Meanwhile, Anthropic accidentally leaked…

  • Google Unveils Device-Bound Chrome Sessions in Anti-Cookie-Theft Move

    Google Unveils Device-Bound Chrome Sessions in Anti-Cookie-Theft Move Google officially announced the public rollout of Device Bound Session Credentials (DBSC) for Windows users on Chrome 146. According to the Google Account Security and Chrome teams, this major security update aims to eliminate session hijacking, a primary method for attackers to compromise user accounts. The feature…

  • Juniper Networks Default Password Vulnerability Let Attacker Take Full Control of the Device

    Juniper Networks Default Password Vulnerability Let Attacker Take Full Control of the Device A critical security alert warns of a severe default password vulnerability affecting Support Insights Virtual Lightweight Collector (vLWC) appliances. This flaw enables unauthenticated network-based attackers to gain full administrative control of exposed network devices easily. Formally tracked as CVE-2026-33784, this vulnerability has…

  • Critical Claude Code Flaw Silently Bypasses Developer-Configured Security Rules

    Critical Claude Code Flaw Silently Bypasses Developer-Configured Security Rules A high-severity security bypass vulnerability in Anthropic’s Claude Code AI coding agent allows malicious actors to silently evade user-configured deny rules through a simple command-padding technique, exposing hundreds of thousands of developers to credential theft and supply chain compromise. According to Adversa, the flaw was traced…

  • Smashing Security podcast #461: This man hid $400 million in a fishing rod. Then it vanished

    Smashing Security podcast #461: This man hid $400 million in a fishing rod. Then it vanished A cannabis-growing, beekeeping, gyrocopter-flying Irishman invested his drug money in Bitcoin back in 2011 – and now sits on a fortune worth $400 million. There’s just one small problem: the access codes were tucked inside his fishing rod case,…

  • New Windows Error Reporting Vulnerability Lets Attackers Escalate to Gain SYSTEM Access

    New Windows Error Reporting Vulnerability Lets Attackers Escalate to Gain SYSTEM Access A newly analyzed local privilege escalation vulnerability in the Windows Error Reporting (WER) service allows attackers to easily gain full SYSTEM access. The flaw, tracked as CVE-2026-20817, was considered so structurally dangerous that Microsoft completely removed the vulnerable feature rather than attempting a…

  • Oracle Issues Urgent Security Update for Critical RCE Flaw in Identity Manager and Web Services Manager

    Oracle Issues Urgent Security Update for Critical RCE Flaw in Identity Manager and Web Services Manager Oracle has issued an out-of-band Security Alert addressing a critical remote code execution (RCE) vulnerability, CVE-2026-21992, affecting two widely deployed Fusion Middleware components, Oracle Identity Manager and Oracle Web Services Manager. The vulnerability carries a CVSS 3.1 base score…

  • Cisco Firewall 0-day Vulnerability Exploited in the Wild to Deploy Interlock Ransomware

    Cisco Firewall 0-day Vulnerability Exploited in the Wild to Deploy Interlock Ransomware An active campaign by the Interlock ransomware group is exploiting a critical zero-day vulnerability (CVE-2026-20131) in Cisco Secure Firewall Management Center (FMC) Software. The vulnerability may allow an unauthenticated remote attacker to execute arbitrary Java code with root privileges on an affected device.…

  • Microsoft to Block Windows 11 and Server 2025 Automated Installation After Critical RCE Vulnerability

    Microsoft to Block Windows 11 and Server 2025 Automated Installation After Critical RCE Vulnerability Microsoft has announced a two-phase plan to disable the hands-free deployment feature in Windows Deployment Services (WDS) following the discovery of a critical remote code execution (RCE) vulnerability tracked as CVE-2026-0386. The flaw, rooted in improper access control, allows an unauthenticated…

  • Microsoft Releases Out-of-Band Patch For Critical RRAS RCE Vulnerabilities in Windows 11

    Microsoft Releases Out-of-Band Patch For Critical RRAS RCE Vulnerabilities in Windows 11 Microsoft released an out-of-band hotpatch update on March 13, 2026, addressing serious security vulnerabilities in Windows 11 versions 24H2 and 25H2. Tracked as KB5084597 and targeting OS Builds 26200.7982 and 26100.7982, this update patches three actively concerning flaws in the Windows Routing and…

  • Critical LangSmith Account Takeover Vulnerability Puts Users at Risk

    Critical LangSmith Account Takeover Vulnerability Puts Users at Risk Miggo Security researchers have identified a critical vulnerability in LangSmith, tracked as CVE-2026-25750, that exposes users to potential token theft and complete account takeover. As a central hub for debugging and monitoring large language model data, LangSmith processes billions of events daily, making this a high-stakes…

  • OpenSSH GSSAPI Vulnerability Allow an Attacker to Crash SSH Child Processes

    OpenSSH GSSAPI Vulnerability Allow an Attacker to Crash SSH Child Processes A significant vulnerability in the GSSAPI Key Exchange patch was applied by numerous Linux distributions on top of their OpenSSH packages. The flaw, tracked as CVE-2026-3497, was uncovered by security researcher Jeremy Brown. It allows an attacker to crash SSH child processes reliably and…

  • GitLab Security Update – Patch for XSS and API DoS Vulnerabilities

    GitLab Security Update – Patch for XSS and API DoS Vulnerabilities GitLab has released urgent security updates for its Community Edition (CE) and Enterprise Edition (EE) to address a wide range of vulnerabilities. The newly released versions 18.9.2, 18.8.6, and 18.7.6 fix a total of 15 security issues, including critical Cross-Site Scripting (XSS) and Denial-of-Service…

  • Microsoft SQL Server Zero-Day Vulnerability Allows Attackers to Escalate Privileges

    Microsoft SQL Server Zero-Day Vulnerability Allows Attackers to Escalate Privileges Microsoft has disclosed a critical zero-day vulnerability in SQL Server that allows authenticated attackers to escalate their privileges to the highest administrative level on affected database systems. Tracked as CVE-2026-21262, the flaw was officially released on March 10, 2026, and has already been publicly disclosed,…

  • Smashing Security podcast #457: How a cybersecurity boss framed his own employee

    Smashing Security podcast #457: How a cybersecurity boss framed his own employee When a top cybersecurity firm discovered it had a leak, you would expect the FBI to be called. Instead, the person put in charge of the investigation was the actual leaker… who promptly sent an innocent colleague into a career-ending ambush. In this…

  • Phishing Schemes Abuse .arpa TLD and IPv6 Tunnels to Evade Detection

    Phishing Schemes Abuse .arpa TLD and IPv6 Tunnels to Evade Detection Cybersecurity researchers at Infoblox Threat Intel have uncovered a highly sophisticated phishing campaign that exploits the foundational plumbing of the internet to bypass enterprise security controls. In a novel evasion tactic, threat actors are weaponizing the .arpa top-level domain (TLD) and utilizing IPv6 tunnels to host…

  • Hackers Abuse Windows File Explorer and WebDAV for Stealthy Malware Delivery

    Hackers Abuse Windows File Explorer and WebDAV for Stealthy Malware Delivery Cybercriminals are increasingly abusing a legacy feature within Windows File Explorer to distribute malware, bypassing traditional web browser security and endpoint detection controls. According to a threat report by Kahng An of the Cofense Intelligence Team, threat actors are leveraging Web-based Distributed Authoring and…

  • Metasploit Adds New Modules Targeting Linux RC4, BeyondTrust, and Registry Persistence

    Metasploit Adds New Modules Targeting Linux RC4, BeyondTrust, and Registry Persistence The latest Metasploit update, released on February 27, 2026, brings significant firepower to security professionals and penetration testers. The release introduces seven new modules, nine feature enhancements, and critical bug fixes. Standout additions include unauthenticated remote code execution (RCE) exploits for Ollama, BeyondTrust, and…

  • Critical Claude Code Vulnerabilities Enables Remote Code Execution Attacks

    Critical Claude Code Vulnerabilities Enables Remote Code Execution Attacks A critical security flaw in Anthropic’s Claude Code demonstrates how threat actors can exploit repository configuration files to execute malicious code and steal sensitive API keys. The vulnerabilities, tracked as CVE-2025-59536 and CVE-2026-21852, highlight a significant shift in the software supply chain threat landscape as AI…

  • Critical Jenkins Vulnerability Exposes Build Environments to XSS Attacks

    Critical Jenkins Vulnerability Exposes Build Environments to XSS Attacks Security Advisory has revealed multiple vulnerabilities in Jenkins Core, including a stored Cross-Site Scripting (XSS) flaw that could expose build environments to severe security risks. The issues, identified as CVE-2026-27099 and CVE-2026-27100, were responsibly disclosed under the Jenkins Bug Bounty Program sponsored by the European Commission. The most critical of the…

  • Critical Windows Admin Center Vulnerability Allows Privilege Escalation

    Critical Windows Admin Center Vulnerability Allows Privilege Escalation A critical security update addressing a high‑severity elevation of privilege vulnerability in Windows Admin Center (WAC), identified as CVE‑2026‑26119. The flaw, rated CVSS 8.8 (Critical), stems from improper authentication (CWE‑287) that could allow an authorized attacker to gain elevated network privileges. According to Microsoft, this vulnerability affects Windows Admin Center version 2.6.4, and…

  • Apache NiFi Vulnerability Enables Authorization Bypass

    Apache NiFi Vulnerability Enables Authorization Bypass A newly disclosed high-severity vulnerability in Apache NiFi exposes systems to an authorization bypass that could allow lower-privileged users to modify restricted components. Tracked as CVE-2026-25903, the flaw impacts Apache NiFi versions 1.1.0 through 2.7.2 and has been fixed in version 2.8.0. According to the Apache NiFi security advisory, the issue arises from missing…

  • Langchain Community SSRF Bypass Vulnerability Enables Access to Internal Services

    Langchain Community SSRF Bypass Vulnerability Enables Access to Internal Services A Server‑Side Request Forgery (SSRF) vulnerability has been identified in the langchain/community package, affecting versions up to 1.1.13. The flaw, tracked as CVE‑2026‑26019, has a moderate severity rating, with a CVSS 3.1 score, due on its potential to expose sensitive cloud metadata and internal infrastructure. The vulnerability originates from the RecursiveUrlLoader class, which…

  • 25 Vulnerabilities in Cloud Password Managers Allow Unauthorized Access and Modifications

    25 Vulnerabilities in Cloud Password Managers Allow Unauthorized Access and Modifications Researchers from ETH Zurich have uncovered 25 serious vulnerabilities in three leading cloud-based password managers: Bitwarden, LastPass, and Dashlane. These flaws enable a malicious server to bypass zero-knowledge encryption claims, allowing unauthorized access, modification, and recovery of users’ stored passwords and vault data. Bitwarden,…

  • Critical BeyondTrust Vulnerability Exploited in the Wild to Gain Full Domain Control

    Critical BeyondTrust Vulnerability Exploited in the Wild to Gain Full Domain Control A critical vulnerability tracked as CVE-2026-1731 is being actively exploited in the wild, enabling attackers to gain full domain control over affected systems. Threat actors are leveraging this flaw to execute operating system commands remotely without authentication. The flaw, discovered in self-hosted BeyondTrust deployments, allows unauthenticated…

  • Threat Actors Exploit Claude Artifacts and Google Ads to Target macOS Users

    Threat Actors Exploit Claude Artifacts and Google Ads to Target macOS Users A sophisticated malware campaign targeting macOS users through Google-sponsored search results and legitimate platforms, including Anthropic’s Claude AI and Medium. The campaign has already reached over 15,000 potential victims through two distinct attack variants that exploit users’ trust in established online services. 15,000…

  • Palo Alto Networks Firewall Vulnerability Allows an Attacker to Force Firewalls into a Reboot Loop

    Palo Alto Networks Firewall Vulnerability Allows an Attacker to Force Firewalls into a Reboot Loop A critical denial-of-service (DoS) flaw in Palo Alto Networks’ PAN-OS software could let unauthenticated attackers crash firewalls into endless reboot cycles, potentially crippling enterprise networks. Dubbed CVE-2026-0229, the vulnerability lurks in the Advanced DNS Security (ADNS) feature. An attacker sends…

  • Windows Notepad Vulnerability Allows Attackers to Execute Malicious Code Remotely

    Windows Notepad Vulnerability Allows Attackers to Execute Malicious Code Remotely Microsoft has patched a critical remote code execution (RCE) flaw in the Windows Notepad app, tracked as CVE-2026-20841, which could let attackers run malicious code on victims’ machines. Disclosed on February 10, 2026, Microsoft Patch Tuesday updates, the vulnerability stems from improper neutralization of special…

  • Augustus – Open-source LLM Vulnerability Scanner With 210+ Attacks Across 28 LLM Providers

    Augustus – Open-source LLM Vulnerability Scanner With 210+ Attacks Across 28 LLM Providers Augustus is a new open-source vulnerability scanner designed to secure Large Language Models (LLMs) against an evolving landscape of adversarial threats. Built by Praetorian, Augustus aims to bridge the gap between academic research tools and production-grade security testing, offering a single-binary solution…

  • Critical FortiClientEMS Vulnerability Let Attackers Execute Malicious Code Remotely

    Critical FortiClientEMS Vulnerability Let Attackers Execute Malicious Code Remotely Fortinet has issued a critical security advisory warning administrators to immediately patch instances of FortiClientEMS, its central management solution for endpoint protection. The vulnerability, tracked as CVE-2026-21643, carries a CVSSv3 score of 9.1 and could allow unauthenticated, remote attackers to execute arbitrary code or unauthorized commands…

  • Claude Opus 4.6 Released with Improved Cybersecurity, Validating 500+ high-severity Vulnerabilities

    Claude Opus 4.6 Released with Improved Cybersecurity, Validating 500+ high-severity Vulnerabilities Anthropic’s latest AI model autonomously identifies critical flaws in decades-old codebases, raising the stakes for both defenders and attackers Anthropic released Claude Opus 4.6 on February 5, 2026, with dramatically enhanced cybersecurity capabilities that have already identified more than 500 previously unknown high-severity vulnerabilities…

  • F5 Patches Critical Vulnerabilities in BIG-IP, NGINX, and Related Products

    F5 Patches Critical Vulnerabilities in BIG-IP, NGINX, and Related Products F5 released its February 2026 Quarterly Security Notification on February 4, announcing several medium and low-severity CVEs, plus a security exposure affecting BIG-IP, NGINX, and container services. These issues primarily stem from denial-of-service (DoS) risks and configuration weaknesses, potentially disrupting high-traffic environments like web application…

  • Chrome Vulnerabilities Let Attackers Execute Arbitrary Code and Crash System

    Chrome Vulnerabilities Let Attackers Execute Arbitrary Code and Crash System Google has released a critical security update for the Chrome Stable channel, addressing two high-severity vulnerabilities that expose users to potential arbitrary code execution (ACE) and denial-of-service (DoS) attacks. The update pushes the browser version to 144.0.7559.132/.133 for Windows and macOS, and 144.0.7559.132 for Linux.…

  • Critical Johnson Controls Products Vulnerabilities Enables Remote SQL Injection Attacks

    Critical Johnson Controls Products Vulnerabilities Enables Remote SQL Injection Attacks A critical advisory addressing a severe SQL injection vulnerability affecting multiple Johnson Controls industrial control system products. The vulnerability, tracked as CVE-2025-26385, carries a maximum CVSS v3 severity score of 10.0, indicating the highest level of risk to affected infrastructure. The flaw stems from improper…

  • SCADA Vulnerability Triggers DoS, Potentially Disrupting Industrial Operations

    SCADA Vulnerability Triggers DoS, Potentially Disrupting Industrial Operations A medium-severity vulnerability in the Iconics Suite SCADA system that could allow attackers to trigger denial-of-service conditions on critical industrial control systems. The flaw, tracked as CVE-2025-0921, affects supervisory control and data acquisition infrastructure widely deployed across automotive, energy, and manufacturing sectors. Vulnerability Overview CVE-2025-0921 stems from…

  • Critical Solarwinds Web Vulnerability Allows Remote Code Execution and Security Bypass

    Critical Solarwinds Web Vulnerability Allows Remote Code Execution and Security Bypass Multiple critical vulnerabilities in SolarWinds Web Help Desk (WHD), culminating in unauthenticated remote code execution (RCE) via Java deserialization in CVE-2025-40551, were uncovered by Horizon3.ai researchers. These flaws chain static credentials, security bypasses, and deserialization weaknesses, affecting versions prior to 2026.1. SolarWinds WHD, an…

  • Smashing Security podcast #452: The dark web’s worst assassins, and Pegasus in the dock

    Smashing Security podcast #452: The dark web’s worst assassins, and Pegasus in the dock In episode 452, a London-based YouTuber wins a landmark court case against Saudi Arabia after his phone was hacked with Pegasus spyware — exposing how a single, seemingly harmless text message can turn a smartphone into a round-the-clock surveillance device. Plus,…

  • New Instagram Vulnerability Exposes Private Posts to Anyone

    New Instagram Vulnerability Exposes Private Posts to Anyone A critical server-side vulnerability in Instagram’s infrastructure allowed unauthenticated attackers to access private photos and captions without a login or follower relationship, according to a disclosure released this week by security researcher Jatin Banga. The vulnerability, which was reportedly patched silently by Meta in October 2025, relied…

  • Hackers Exploiting telnetd Vulnerability for Root Access – Public PoC Released

    Hackers Exploiting telnetd Vulnerability for Root Access – Public PoC Released Active exploitation of a critical authentication bypass vulnerability in the GNU InetUtils telnetd server (CVE-2026-24061) has been observed in the wild, allowing unauthenticated attackers to gain root access to Linux systems. The vulnerability, which affects GNU InetUtils versions 1.9.3 through 2.7, enables remote code…

  • Cisco Unified Communications 0-day RCE Vulnerability Exploited in the Wild to Gain Root Access

    Cisco Unified Communications 0-day RCE Vulnerability Exploited in the Wild to Gain Root Access Cisco has disclosed a critical zero-day remote code execution (RCE) vulnerability, CVE-2026-20045, actively exploited in the wild. Affecting key Unified Communications products, this flaw allows unauthenticated attackers to run arbitrary commands on the underlying OS, potentially gaining root access. The Cisco…

  • Fortinet SSO Vulnerability Actively Exploited to Hack Firewalls and Gain Admin Access

    Fortinet SSO Vulnerability Actively Exploited to Hack Firewalls and Gain Admin Access A critical vulnerability in Fortinet’s Single Sign-On (SSO) feature for FortiGate firewalls, tracked as CVE-2025-59718, is under active exploitation. Attackers are leveraging it to create unauthorized local admin accounts, granting full administrative access to internet-exposed devices. Multiple users have reported identical attack patterns,…

  • Smashing Security podcast #451: I hacked the government, and your headphones are next

    Smashing Security podcast #451: I hacked the government, and your headphones are next In episode 451 of “Smashing Security,” we meet the cybercriminal who hacked the US Supreme Court, Veterans Affairs, and more – and then helpfully posted screenshots (and even someone’s blood type) on an account called “I hacked the government.” Plus we discuss…

  • Critical Oracle WebLogic Server Proxy Vulnerability Lets Attackers Compromise the Server

    Critical Oracle WebLogic Server Proxy Vulnerability Lets Attackers Compromise the Server Oracle has disclosed a severe security vulnerability affecting its Fusion Middleware suite, specifically targeting the Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. Assigned CVE-2026-21962, this flaw carries the maximum severity rating and poses an immediate threat to enterprise environments that use…

  • Azure Private Endpoint Deployments Exposes Azure Resources to DoS Attack

    Azure Private Endpoint Deployments Exposes Azure Resources to DoS Attack A critical architectural flaw in Microsoft Azure’s Private Endpoint implementation that enables denial-of-service (DoS) attacks against production Azure resources. The vulnerability affects over 5% of Azure storage accounts, exposing organizations to service disruptions across Key Vault, CosmosDB, Azure Container Registry, Function Apps, and OpenAI accounts.…

  • Windows SMB Client Vulnerability Enables Attacker to Own Active Directory

    Windows SMB Client Vulnerability Enables Attacker to Own Active Directory A critical vulnerability in Windows SMB client authentication that enables attackers to compromise Active Directory environments through NTLM reflection exploitation. Classified as an improper access control vulnerability, this vulnerability allows authorized attackers to escalate privileges via carefully orchestrated authentication relay attacks over network connections. Seven…

  • Mandiant Releases Rainbow Tables Enabling NTLMv1 Admin Password Hacking

    Mandiant Releases Rainbow Tables Enabling NTLMv1 Admin Password Hacking Google-owned Mandiant has publicly released a comprehensive dataset of Net-NTLMv1 rainbow tables, marking a significant escalation in demonstrating the security risks of legacy authentication protocols. The release underscores an urgent message: organizations must immediately migrate away from Net-NTLMv1, a deprecated protocol that has been cryptographically broken…

  • Go 1.25.6 and 1.24.12 Patch Critical Vulnerabilities Lead to DoS and Memory Exhaustion Risks

    Go 1.25.6 and 1.24.12 Patch Critical Vulnerabilities Lead to DoS and Memory Exhaustion Risks The Go programming language team has rolled out emergency point releases, Go 1.25.6 and 1.24.12, to address six high-impact security flaws. These updates fix denial-of-service (DoS) vectors, arbitrary code execution risks, and TLS mishandlings that could expose developers to remote attacks.…

  • Fortinet FortiSIEM Vulnerability CVE-2025-64155 Actively Exploited in Attacks

    Fortinet FortiSIEM Vulnerability CVE-2025-64155 Actively Exploited in Attacks Fortinet FortiSIEM vulnerability CVE-2025-64155 is under active exploitation, as confirmed by Defused through their honeypot deployments. This critical OS command injection flaw enables unauthenticated remote code execution, posing severe risks to enterprise security monitoring systems. CVE-2025-64155 stems from improper neutralization of special elements in OS commands within…

  • Microsoft SQL Server Vulnerability Allows Attackers to Elevate Privileges over a Network

    Microsoft SQL Server Vulnerability Allows Attackers to Elevate Privileges over a Network Microsoft released security updates on January 13, 2026, addressing a critical elevation of privilege vulnerability in SQL Server that enables authorized attackers to bypass authentication controls and gain elevated system privileges remotely. Tracked as CVE-2026-20803, the vulnerability stems from missing authentication mechanisms for…

  • New Angular Vulnerability Enables an Attacker to Execute Malicious Payload

    New Angular Vulnerability Enables an Attacker to Execute Malicious Payload A critical Cross-Site Scripting (XSS) vulnerability has been discovered in Angular’s Template Compiler, affecting multiple versions of both @angular/compiler and @angular/core packages. Tracked as CVE-2026-22610, this vulnerability allows attackers to bypass Angular’s built-in security protections and execute arbitrary JavaScript code within victim browsers. The Vulnerability…

  • Multiple Hikvision Vulnerabilities Let Attackers Cause Device Malfunction Using Crafted Packets

    Multiple Hikvision Vulnerabilities Let Attackers Cause Device Malfunction Using Crafted Packets Hikvision, a leading provider of surveillance and access control systems, faces serious security risks from two newly disclosed stack overflow vulnerabilities. These flaws, tracked as CVE-2025-66176 and CVE-2025-66177, allow attackers on the same local area network (LAN) to trigger device malfunctions by sending specially…

  • Critical Zlib Vulnerability Let Attackers Trigger Buffer Overflow by Invoking untgz

    Critical Zlib Vulnerability Let Attackers Trigger Buffer Overflow by Invoking untgz A severe global buffer overflow vulnerability has been discovered in the zlib untgz utility version 1.3.1.2. Allowing attackers to corrupt memory and potentially execute malicious code through specially crafted command-line input.​ The security flaw resides in the TGZfname() function of the untgz utility, where…

  • Phishing Campaign Uses Maduro Arrest Story to Deliver Backdoor Malware

    Phishing Campaign Uses Maduro Arrest Story to Deliver Backdoor Malware Cybercriminals are leveraging the recent arrest of Venezuelan President Nicolás Maduro to distribute sophisticated backdoor malware. The threat actors exploited news surrounding Maduro’s arrest on January 3, 2025, demonstrating how geopolitical events continue to serve as effective lures for malicious campaigns. The attack likely begins…

  • pcTattletale founder pleads guilty in rare stalkerware prosecution

    pcTattletale founder pleads guilty in rare stalkerware prosecution The founder of a spyware company that encouraged customers to secretly monitor their romantic partners has pleaded guilty to federal charges – marking one of the few successful US prosecutions of a stalkerware operator. Read more in my article on the Hot for Security blog. Graham Cluley…

  • SmarterTools SmarterMail Vulnerability Enables Remote Code Execution Attack – PoC Released

    SmarterTools SmarterMail Vulnerability Enables Remote Code Execution Attack – PoC Released A critical pre-authentication remote code execution vulnerability, identified as CVE-2025-52691, has been discovered in SmarterTools’ SmarterMail solution. The flaw received a maximum CVSS score of 10.0, indicating its severe nature and potential impact on affected systems. SmarterTools describes SmarterMail as “a secure, all-in-one business…

  • Linux Battery Utility Flaw Lets Hackers Bypass Authentication and Tamper System Settings

    Linux Battery Utility Flaw Lets Hackers Bypass Authentication and Tamper System Settings A critical security vulnerability has been discovered in TLP, a widely used Linux laptop battery optimization utility, allowing local attackers to bypass authentication controls and manipulate system power settings without authorization. Security researchers from openSUSE identified a severe authentication bypass flaw in the…

  • Forcepoint DLP Vulnerability Enables Memory Manipulation and Arbitrary Code Execution

    Forcepoint DLP Vulnerability Enables Memory Manipulation and Arbitrary Code Execution A critical security flaw in Forcepoint One DLP Client has been disclosed, allowing attackers to bypass vendor-implemented Python restrictions and execute arbitrary code on enterprise endpoints. The vulnerability, tracked as CVE-2025-14026, undermines the data loss prevention security controls designed to protect sensitive organizational data. The…

  • 10 Best Vulnerability Assessment and Penetration Testing (VAPT) Tools in 2026

    10 Best Vulnerability Assessment and Penetration Testing (VAPT) Tools in 2026 Vulnerability Assessment and Penetration Testing (VAPT) tools form the cornerstone of any cybersecurity toolkit, enabling organizations to identify, analyze, and remediate vulnerabilities across systems, networks, applications, and IT infrastructure. These tools empower proactive security by exposing weaknesses and attack vectors before threat actors can…

  • Eaton Vulnerabilities Let Attackers Execute Arbitrary Code On the Host System

    Eaton Vulnerabilities Let Attackers Execute Arbitrary Code On the Host System A critical security advisory addressing multiple vulnerabilities discovered in the Eaton UPS Companion (EUC) software. These security flaws, if exploited, could allow attackers to execute arbitrary code on the host system, potentially giving them complete control over affected devices. The advisory, identified as ETN-VA-2025-1026, highlights…

  • GHOSTCREW – AI-based Red Team Toolkit for Penetration Testing Invoking Metasploit, Nmap and Other Tools

    GHOSTCREW – AI-based Red Team Toolkit for Penetration Testing Invoking Metasploit, Nmap and Other Tools GHOSTCREW emerges as a game-changing open-source toolkit for red teamers and penetration testers. This AI-powered assistant leverages large language models, integrates the MCP protocol, and supports the optional RAG architecture to orchestrate security tools via natural-language prompts.​ Developed by GH05TCREW,…

  • Infostealers Enable Attackers to Hijack Legitimate Business Infrastructure for Malware Hosting

    Infostealers Enable Attackers to Hijack Legitimate Business Infrastructure for Malware Hosting A dangerous cybercrime feedback loop has emerged where stolen credentials from infostealer malware enable attackers to hijack legitimate business websites and turn them into malware distribution platforms. Recent research by the Hudson Rock Threat Intelligence Team reveals this self-sustaining cycle transforms victims into unwitting…

  • Lessons From Mongobleed Vulnerability (CVE-2025-14847) That Actively Exploited In The Wild

    Lessons From Mongobleed Vulnerability (CVE-2025-14847) That Actively Exploited In The Wild The cybersecurity community was alarmed in late December 2025 when MongoDB announced a serious vulnerability called “Mongobleed” (CVE-2025-14847). This high-severity flaw allows unauthenticated attackers to steal sensitive data directly from server memory. With a CVSS score of 8.7 and over 87,000 potentially vulnerable MongoDB…

  • Apache NuttX Vulnerability Let Attackers to Crash Systems

    Apache NuttX Vulnerability Let Attackers to Crash Systems A newly disclosed use-after-free vulnerability in Apache NuttX RTOS could allow attackers to cause system crashes and unintended filesystem operations, prompting urgent security warnings for users running network-exposed services. The flaw, tracked as CVE-2025-48769 and rated moderate in severity, affects a wide range of NuttX versions and…

  • Critical IBM API Connect Vulnerability Let Attackers Bypass Logins

    Critical IBM API Connect Vulnerability Let Attackers Bypass Logins A critical security alert regarding a severe vulnerability in the IBM API Connect platform that could allow remote attackers to bypass authentication mechanisms. Discovered during internal testing, the flaw poses a significant risk to organizations relying on the platform for API management. It grants unauthorized actors…

  • Critical Apache StreamPipes Vulnerability Let Attackers Seize Admin Control

    Critical Apache StreamPipes Vulnerability Let Attackers Seize Admin Control A security patch addressing a critical privilege escalation vulnerability that allows unauthorized users to gain administrative access to the data streaming platform. The flaw, tracked as CVE-2025-47411 and rated important, affects Apache StreamPipes versions 0.69.0 through 0.97.0. The vulnerability stems from a flawed user ID creation…

  • MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

    MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847) An open-source detection tool to help organizations identify potential exploitation of MongoBleed (CVE-2025-14847), a critical memory disclosure vulnerability affecting MongoDB databases.​ The vulnerability allows attackers to extract sensitive information, including credentials, session tokens, and personally identifiable information, directly from server memory without requiring authentication. The flaw exists…

  • MongoBleed (CVE-2025-14847) Now Exploited in the Wild: MongoDB Servers at Critical Risk

    MongoBleed (CVE-2025-14847) Now Exploited in the Wild: MongoDB Servers at Critical Risk A high-severity unauthenticated information-leak vulnerability in MongoDB Server, dubbed MongoBleed after the infamous Heartbleed bug, is now being actively exploited in real-world attacks. MongoDB has disclosed CVE-2025-14847, a critical flaw affecting multiple supported and legacy server versions that allows unauthenticated remote attackers to…