Category: Vulnerability

  • 15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and Achieve Remote Code Execution

    15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and Achieve Remote Code Execution A newly disclosed flaw tracked as CVE-2026-42533 affects nginx’s script engine and has been silently exploitable since March 2011, when the map directive gained regex support. Security researcher Stan Shaw reported the bug to F5 SIRT, which coordinated a fix released in nginx…

  • Citrix Secure Access and Endpoint Client for Windows Vulnerability Enables Privilege Escalation

    Citrix Secure Access and Endpoint Client for Windows Vulnerability Enables Privilege Escalation Cloud Software Group has disclosed two security vulnerabilities affecting Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows, with one flaw allowing low-privileged attackers to gain full SYSTEM access on affected machines. The more severe issue, tracked as CVE-2026-53565,…

  • New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released

    New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released A critical pre-authentication remote code execution (RCE) vulnerability dubbed “wp2shell” has been discovered in WordPress Core, putting an estimated 500 million+ websites at risk of full takeover by unauthenticated attackers. Security researcher Adam Kues of Searchlight Cyber’s Assetnote research team uncovered the flaw,…

  • OpenSSL “HollowByte” Vulnerability Lets Hackers Crash Servers With Just 11 Bytes

    OpenSSL “HollowByte” Vulnerability Lets Hackers Crash Servers With Just 11 Bytes A newly disclosed vulnerability in OpenSSL, dubbed “HollowByte,” allows a remote, unauthenticated attacker to trigger a denial-of-service (DoS) condition using a malicious payload as small as 11 bytes. Discovered by the Okta Red Team, the flaw exploits how OpenSSL pre-allocates memory during the TLS…

  • Google’s Gemini lets strangers send messages from your locked Android phone

    Google’s Gemini lets strangers send messages from your locked Android phone Gemini, Google’s AI assistant, is supposed to make life easier for Android smartphone owners. But right now it may also be making life easier for anyone anyone who happens to pick up your phone. Read more in my article on the Hot for Security…

  • CISA Warns of Microsoft SharePoint Code Execution Vulnerability Exploited in Attacks

    CISA Warns of Microsoft SharePoint Code Execution Vulnerability Exploited in Attacks CISA has added a critical Microsoft SharePoint vulnerability, tracked as CVE-2026-58644, to its Known Exploited Vulnerabilities (KEV) catalog. This addition comes with a warning that attackers are actively exploiting the flaw in real-world attacks. The vulnerability stems from a weakness in deserializing untrusted data,…

  • Multiple TP-Link Cameras Vulnerability Allows Hackers to Launch MitM Attacks

    Multiple TP-Link Cameras Vulnerability Allows Hackers to Launch MitM Attacks TP-Link has released security updates for two vulnerabilities in its Kasa EC70 v4 and EC71 v4 smart cameras. These flaws, tracked as CVE-2026-9770 and CVE-2026-13230, could allow an attacker on the same local network to obtain sensitive information from vulnerable devices. The most serious issue,…

  • Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers

    Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers An app has appeared in India that lets anyone with a smartphone stop a passing e-rickshaw dead in its tracks – no login, no passwords, no permissions needed. Meanwhile, Geoff – swimming in money and Lamborghinis, as all published authors are – has been on…

  • Zoom Desktop Client for Windows Flaw Enables Account Takeover via Network Access

    Zoom Desktop Client for Windows Flaw Enables Account Takeover via Network Access Zoom has released updates for a critical Windows desktop client vulnerability, tracked as CVE-2026-53412, that could allow unauthenticated attackers to remotely take over user accounts. This flaw arises from improper input validation and may enable unauthenticated attackers to execute account takeover attacks via…

  • CISA Warns of Oracle E-Business Suite Vulnerability Actively Exploited in Attacks

    CISA Warns of Oracle E-Business Suite Vulnerability Actively Exploited in Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Oracle E-Business Suite, tracked as CVE-2026-46817, to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation in attacks. This flaw impacts Oracle Payments, a component of Oracle E-Business Suite.…

  • New LegacyHive Windows 0-day Vulnerability Allows Users to Load Another User’s Registry

    New LegacyHive Windows 0-day Vulnerability Allows Users to Load Another User’s Registry A proof-of-concept exploit dubbed LegacyHive has been released, enabling a Windows elevation-of-privilege vulnerability in the Windows User Profile Service that allows a standard user to load another user’s registry hive under their own registry classes root. Registry hives are files that store configuration…

  • New Ghostcommit Attack Hides Malicious Prompts in Images to Exploit AI Agents

    New Ghostcommit Attack Hides Malicious Prompts in Images to Exploit AI Agents A novel supply chain attack called “Ghostcommit” that conceals prompt-injection instructions within PNG images to bypass AI code reviewers and trick coding agents into leaking secrets such as .env files. The ASSET Research Group demonstrated that a pull request containing an explicit, plain-text…

  • Dell BIOS Flaw Lets Attackers Recover Admin Passwords From SPI Flash in Milliseconds

    Dell BIOS Flaw Lets Attackers Recover Admin Passwords From SPI Flash in Milliseconds A critical flaw in how Dell stores BIOS administrator and user passwords allows full password recovery from a flash dump in milliseconds, with no brute force required. The vulnerability, tracked as CVE-2026-40639 (DSA-2026-197), stems from a broken XOR encryption scheme rather than…

  • Palo Alto PAN-OS Vulnerability Allows Arbitrary Code Execution Through Malicious Network Traffic

    Palo Alto PAN-OS Vulnerability Allows Arbitrary Code Execution Through Malicious Network Traffic Palo Alto Networks has disclosed a high-severity vulnerability in PAN-OS that could allow unauthenticated attackers to execute arbitrary code or trigger a denial-of-service (DoS) condition by sending specially crafted network traffic. Tracked as CVE-2026-0288, the flaw carries a CVSS-B score of 9.2 (HIGH,…

  • Tenda Authentication Backdoor Grants Attackers Full Administrative Access

    Tenda Authentication Backdoor Grants Attackers Full Administrative Access A newly disclosed vulnerability in Tenda network devices exposes a critical authentication backdoor that allows attackers to gain full administrative access without valid credentials. The flaw affects multiple firmware versions across several Tenda router models, including the FH1201, W15E, AC10, AC5, and AC6 series. The issue, tracked…

  • Opera GX 0-Click Vulnerability Lets Attackers Exfiltrate User Data via Malicious Website

    Opera GX 0-Click Vulnerability Lets Attackers Exfiltrate User Data via Malicious Website A newly disclosed vulnerability in Opera GX allowed attackers to silently exfiltrate sensitive user data with no interaction required, simply by luring victims to a malicious website. The issue, documented in recent research titled “One trigram at a time: XSLeak via Universal CSS…

  • Multiple FatFs Vulnerabilities Expose Millions of Embedded Devices to Cyber Risks

    Multiple FatFs Vulnerabilities Expose Millions of Embedded Devices to Cyber Risks Security researchers at runZero have disclosed seven new CVEs affecting FatFs, the ubiquitous lightweight FAT/exFAT filesystem driver used across embedded and IoT ecosystems. The vulnerabilities range from CVSS Medium to High, with no Critical-rated findings, but their reach is significant: FatFs underpins platforms including…

  • Microsoft Exchange SSRF Vulnerability Details Released Along With Public PoC Exploit

    Microsoft Exchange SSRF Vulnerability Details Released Along With Public PoC Exploit Security researchers from HawkTrace have disclosed technical details of a high-severity server-side request forgery (SSRF) vulnerability in Microsoft Exchange, tracked as CVE-2026-45504. The flaw, which carries a CVSS score of 8.8, allows authenticated, low-privileged users to read arbitrary files from vulnerable Exchange servers, raising…

  • WinRAR 7.23 Fixes Heap Overflow Vulnerability that Leads to Application Crashes

    WinRAR 7.23 Fixes Heap Overflow Vulnerability that Leads to Application Crashes WinRAR 7.23 addresses a newly disclosed heap overflow vulnerability in the RAR5 recovery volume processing code, tracked as CVE-2026-14191. Closing a memory-corruption flaw that could be triggered by malicious recovery volume (.rev) data and potentially lead to application crashes or further exploitation. WinRAR 7.23…

  • Smashing Security podcast #474: Polymarket can predict the future. So how did it miss this hack?

    Smashing Security podcast #474: Polymarket can predict the future. So how did it miss this hack? Polymarket has built an entire business on predicting the future. So how did it manage to spectacularly fail to predict its own hack? Plus, the Google engineer with a million-dollar secret, and the curious case of the airport hairdryer.…

  • Multiple Apache Tomcat Vulnerabilities Allow Attackers to Bypass Authentication

    Multiple Apache Tomcat Vulnerabilities Allow Attackers to Bypass Authentication The Apache Software Foundation has disclosed two vulnerabilities affecting Apache Tomcat that could allow attackers to bypass authentication and security constraints protecting web applications. The flaws, tracked as CVE-2026-55957 and CVE-2026-55956, impact multiple major versions of the widely deployed servlet container, prompting urgent upgrade recommendations across…

  • New DirtyClone Linux Vulnerability Allows Attackers to Gain Root Access Via Cloned Packets

    New DirtyClone Linux Vulnerability Allows Attackers to Gain Root Access Via Cloned Packets A new Linux kernel local privilege escalation vulnerability, dubbed “DirtyClone” (CVE-2026-43503), that allows unprivileged local users to gain full root access by manipulating cloned network packets through the XFRM/IPsec subsystem, all without leaving a trace in kernel logs or audit records. DirtyClone…

  • Amazon Q Vulnerability Let Attackers Execute Code and Access Sensitive Cloud Environments

    Amazon Q Vulnerability Let Attackers Execute Code and Access Sensitive Cloud Environments A high-severity vulnerability in the Amazon Q Developer Extension for Visual Studio Code (VS Code), Amazon’s AI-powered coding assistant. Tracked as CVE-2026-12957 and CVE-2026-12958 and disclosed by Wiz Research, the flaws allowed attackers to achieve arbitrary code execution and cloud credential theft simply…

  • Chrome 149 Security Update — Patch for Critical Flaws that Enable Code Execution Attacks

    Chrome 149 Security Update — Patch for Critical Flaws that Enable Code Execution Attacks Google has released a critical security update for its Chrome browser, pushing the Stable channel to version 149.0.7827.196/197 for Windows and Mac, and 149.0.7827.196 for Linux. The update addresses 18 security vulnerabilities, including four rated Critical and fourteen rated High severity,…

  • Smashing Security podcast #473: How a hacker could have Rickrolled the entire World Cup

    Smashing Security podcast #473: How a hacker could have Rickrolled the entire World Cup A polite caller from your bank says there is a problem with your account. Don’t worry – they’ll send someone round to help. They’ll even take your cards away to keep them safe. The scam has run rampant, until Dutch police…

  • Microsoft Confirms Defender RoguePlanet 0-Day Exploit and Working to Release Patch

    Microsoft Confirms Defender RoguePlanet 0-Day Exploit and Working to Release Patch Microsoft has officially acknowledged a critical zero-day vulnerability in Microsoft Defender, publicly dubbed “RoguePlanet,” and confirmed it is actively developing a security patch to address the flaw. Tracked as CVE-2026-50656, the vulnerability was formally published on June 16, 2026, by the Microsoft Security Response…

  • Smashing Security podcast #472: AI gets hacked, and BitLocker gets bypassed

    Smashing Security podcast #472: AI gets hacked, and BitLocker gets bypassed What if your AI coding assistant could be tricked into stealing your own company’s secrets – by reading a single booby-trapped bug report? No phishing email. No malware. No password ever stolen. Just an AI doing exactly what it was told. Meanwhile, someone themselves…

  • OptinMonster Plugin Hack Exposes 1.2 Million WordPress Sites to Cyberattack

    OptinMonster Plugin Hack Exposes 1.2 Million WordPress Sites to Cyberattack A large-scale supply chain attack targeting widely used WordPress plugins has exposed more than 1.2 million websites to potential compromise after attackers injected malicious code into legitimate JavaScript files distributed through trusted CDN infrastructure. Security researchers at Sansec discovered an ongoing campaign targeting plugins developed…

  • LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild

    LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild A critical zero-day vulnerability in the LiteSpeed cPanel user-end plugin is being actively exploited in the wild, posing a serious threat to shared hosting environments worldwide. The flaw, tracked as CVE-2026-54420, enables privilege escalation to root level, allowing attackers to take full control of affected…

  • Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks

    Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Cisco has disclosed a critical security issue in its Catalyst SD-WAN Manager (formerly vManage) that is now being actively exploited in zero-day attacks, raising concerns for enterprise network environments worldwide. The vulnerability, tracked as CVE-2026-20262, is an arbitrary-file-write flaw in the web-based management interface. It carries a…

  • Splunk Enterprise Pre-Auth RCE Chain Exposes Database With Zero Authentication

    Splunk Enterprise Pre-Auth RCE Chain Exposes Database With Zero Authentication A critical vulnerability chain in Splunk Enterprise has been disclosed, enabling unauthenticated attackers to achieve remote code execution (RCE) through a misconfigured PostgreSQL sidecar service. Tracked as CVE-2026-20253, the flaw has a CVSS score of 9.8 and affects Splunk Enterprise 10 and later. The issue…

  • Hackers Exploiting LiteLLM RCE Vulnerability in the Wild to Run Arbitrary Commands

    Hackers Exploiting LiteLLM RCE Vulnerability in the Wild to Run Arbitrary Commands Threat actors are actively exploiting a critical chained vulnerability in LiteLLM, a popular open-source AI gateway proxy, allowing unauthenticated remote code execution (RCE) on vulnerable deployments. Researchers at Horizon3.ai confirmed that combining two CVEs creates a CVSS 10.0 Critical attack path requiring zero…

  • SAP Security Patch Day – Critical Vulnerabilities in SAP NetWeaver Patched

    SAP Security Patch Day – Critical Vulnerabilities in SAP NetWeaver Patched SAP’s June 2026 Security Patch Day, observed on Tuesday, June 9, delivered 15 new security notes addressing a broad range of vulnerabilities across core SAP products, including four critical-severity flaws that demand immediate enterprise attention. SAP strongly urges all customers to visit the SAP…

  • Multiple VMware Stored XSS Vulnerabilities Allow Attackers to Inject Malicious Scripts

    Multiple VMware Stored XSS Vulnerabilities Allow Attackers to Inject Malicious Scripts Broadcom has disclosed three stored cross-site scripting (XSS) vulnerabilities affecting VMware Cloud Foundation Operations and several related products, warning that authenticated attackers could inject malicious scripts to perform administrative actions within the environment. Tracked as CVE-2026-41722, CVE-2026-41723, and CVE-2026-41724, the flaws were addressed in…

  • CISA Warns of SolarWinds Serv-U Vulnerability Exploited in Attacks

    CISA Warns of SolarWinds Serv-U Vulnerability Exploited in Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical SolarWinds Serv-U vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, warning that threat actors are actively exploiting the flaw in the wild. Tracked as CVE-2026-28318, the vulnerability affects SolarWinds Serv-U file transfer software and…

  • Critical Hugging Face Transformers Vulnerability Enables Remote Code Execution Attacks

    Critical Hugging Face Transformers Vulnerability Enables Remote Code Execution Attacks A newly disclosed critical vulnerability in the HuggingFace Transformers library, tracked as CVE-2026-4372, allows attackers to achieve remote code execution (RCE) through malicious model configuration files. The flaw exposes a significant supply chain risk in one of the most widely used machine learning frameworks, impacting…

  • New Google Gemini Vulnerability Exploited via Prompt Injections from WhatsApp, Slack, and SMS

    New Google Gemini Vulnerability Exploited via Prompt Injections from WhatsApp, Slack, and SMS A new class of indirect prompt injection (IPI) attacks targets Google Gemini’s voice assistant, allowing attackers to silently hijack the AI through malicious payloads delivered via everyday messaging apps, including WhatsApp, Slack, Signal, SMS, Instagram, and Messenger. The research, led by Or…

  • Smashing Security podcast #470: This AI security flaw might be impossible to fix

    Smashing Security podcast #470: This AI security flaw might be impossible to fix A website called “UK visa portal” has been quietly collecting passport scans, selfies, and personal data from thousands of travellers who thought they were applying through official channels. They weren’t. And when a journalist tried to warn the company, it was lawyers…

  • HTTP/2 Bomb — Remote DoS Exploit Hits nginx, Apache, IIS, Envoy, and Cloudflare Pingora

    HTTP/2 Bomb — Remote DoS Exploit Hits nginx, Apache, IIS, Envoy, and Cloudflare Pingora A newly disclosed remote denial-of-service exploit dubbed “HTTP/2 Bomb” targets the default HTTP/2 configurations of the world’s most widely deployed web servers, nginx, Apache httpd, Microsoft IIS, Envoy, and Cloudflare Pingora, enabling a single attacker on a home internet connection to…

  • 1-Click GitHub Token Vulnerability Lets Attackers Steal Users’ OAuth Tokens

    1-Click GitHub Token Vulnerability Lets Attackers Steal Users’ OAuth Tokens A critical security vulnerability in Visual Studio Code’s webview implementation allows attackers to steal GitHub OAuth tokens, including read/write access to private repositories, simply by tricking a victim into clicking a single malicious link. The bug was publicly disclosed on June 2, 2026, by security…

  • Police arrest man following hack of Ajax football club

    Police arrest man following hack of Ajax football club Dutch police have arrested a 35-year-old man suspected of hacking into the computer systems of Amsterdam football giant Ajax, after the personal data of hundreds of thousands of supporters was put at risk. Read more in my article on the Hot for Security blog. Graham Cluley…

  • Critical Notepad++ Vulnerabilities Allow Attackers to Execute Arbitrary Code

    Critical Notepad++ Vulnerabilities Allow Attackers to Execute Arbitrary Code Notepad++, one of the most widely used open-source text editors for Windows, has released an urgent security update addressing three vulnerabilities, including two arbitrary code execution flaws that could allow attackers to silently run malicious programs on a victim’s machine. The Notepad++ development team released version…

  • CISA Warns of Drupal Core SQL Injection Vulnerability Exploited in Attacks

    CISA Warns of Drupal Core SQL Injection Vulnerability Exploited in Attacks CISA has issued an urgent alert regarding a critical SQL injection vulnerability in Drupal Core, tracked as CVE-2026-9082, which is now being actively exploited in real-world attacks. The flaw, classified under CWE-89, affects Drupal’s database abstraction API and could allow attackers to execute malicious…

  • Google Publishes Exploit Code for Unfixed Chromium Bug Exposing Millions of Users

    Google Publishes Exploit Code for Unfixed Chromium Bug Exposing Millions of Users Google has publicly released proof-of-concept (PoC) exploit code for a critical, still-unpatched vulnerability in the Chromium codebase, potentially exposing millions of users across Chrome, Microsoft Edge, and other Chromium-based browsers to stealthy botnet-style abuse. The vulnerability, originally reported in late 2022 by independent…

  • Defenders fall behind, as AI rewrites the rules of a data breach

    Defenders fall behind, as AI rewrites the rules of a data breach For almost 20 years, stolen credentials have been the most common route for attackers into organizations, according to the Verizon Data Breach Investigations Report (DBIR). But that’s no longer the case. Read more in my article on the Fortra blog. Graham Cluley Go…

  • New Microsoft Defender 0‑Days Actively Exploited in the Wild

    New Microsoft Defender 0‑Days Actively Exploited in the Wild Two newly disclosed Microsoft Defender vulnerabilities are being actively exploited in the wild, enabling local attackers to elevate privileges to SYSTEM and potentially disrupt endpoint protection across Windows environments. The bugs, tracked as CVE‑2026‑41091 (Elevation of Privilege) and CVE‑2026‑45498 (Denial of Service), were published on May…

  • Smashing Security podcast #468: High-speed train hacks and homicidal lawnmowers

    Smashing Security podcast #468: High-speed train hacks and homicidal lawnmowers A 23-year-old radio enthusiast spent £300 on a piece of kit from the internet, and used it to bring four packed high-speed trains to a screeching halt. His defence in court? Possibly the most creative excuse we’ve heard all year. Meanwhile, owners of $4,000 robot…

  • First Public macOS Kernel Exploit on Apple M5 Prepared Using Mythos Preview in Five Days

    First Public macOS Kernel Exploit on Apple M5 Prepared Using Mythos Preview in Five Days Apple’s M5 silicon has reportedly been exploited for the first time in a public macOS kernel memory corruption attack, successfully bypassing the company’s notable hardware-level memory protection. Researchers from Calif, Bruce Dang, Dion Blazakis, and Josh Maine, developed a working…

  • Malicious JPEG Images Could Trigger PHP Memory Safety Vulnerabilities

    Malicious JPEG Images Could Trigger PHP Memory Safety Vulnerabilities Two critical memory-safety vulnerabilities in PHP’s image-processing functions could allow attackers to leak sensitive heap memory or to execute denial-of-service attacks via specially crafted JPEG files. The flaws, discovered in PHP’s ext/standard extension by Positive Technologies researcher Nikita Sveshnikov, affect the widely-used getimagesize and iptcembed functions…

  • Critical Linux Kernel Flaw ‘ssh-keysign-pwn’ Exposes SSH Keys and Shadow Passwords

    Critical Linux Kernel Flaw ‘ssh-keysign-pwn’ Exposes SSH Keys and Shadow Passwords A newly disclosed Linux kernel vulnerability is raising serious concerns across the security community, as it allows attackers to access highly sensitive data, including SSH private keys and password hashes, on affected systems. Tracked as CVE-2026-46333, the flaw has been nicknamed “ssh-keysign-pwn” and impacts a wide range…

  • VMware Fusion Vulnerability Let Attackers Escalate Privilege to Root

    VMware Fusion Vulnerability Let Attackers Escalate Privilege to Root A high-severity privilege escalation vulnerability has been discovered in VMware Fusion, Broadcom’s popular macOS virtualization software, allowing local attackers to gain root-level access on affected systems. Tracked as CVE-2026-41702, the flaw was privately reported to Broadcom and patched on May 14, 2026, under security advisory VMSA-2026-0003.…

  • Critical Microsoft Exchange Server Vulnerability Actively Exploited in Attacks

    Critical Microsoft Exchange Server Vulnerability Actively Exploited in Attacks Microsoft issued an urgent security alert regarding a newly discovered vulnerability in Exchange Server that is currently being exploited in the wild. Tracked as CVE-2026-42897, this critical spoofing flaw carries a high CVSS 3.1 severity score of 8.1 and directly impacts on-premises email infrastructure. Threat actors…

  • PoC Exploit Released for Android Zero-Click Vulnerability that Enables Remote Shell Access

    PoC Exploit Released for Android Zero-Click Vulnerability that Enables Remote Shell Access In a chilling blow to mobile security, Google’s May 2026 Android Security Bulletin has unmasked a catastrophic zero-click vulnerability lurking within the core Android System. The CVE-2026-0073 flaw in Android’s adbd daemon lets nearby threat actors remotely gain full shell access without victim…

  • New cPanel and WHM Flaws Enable Code Execution, DoS Attacks

    New cPanel and WHM Flaws Enable Code Execution, DoS Attacks cPanel has disclosed three critical security vulnerabilities tracked as CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203 affecting its widely deployed cPanel & WHM web hosting control panel and WP Squared (WP2) platform. The flaws, patched on May 8, 2026, expose servers to arbitrary file reads, Perl code injection,…

  • Critical Microsoft 365 Copilot Vulnerabilities Expose sensitive Information

    Critical Microsoft 365 Copilot Vulnerabilities Expose sensitive Information Microsoft has disclosed and fully remediated three critical information disclosure vulnerabilities affecting Microsoft 365 Copilot and Copilot Chat in Microsoft Edge, all released on May 7, 2026, requiring no action from end users or administrators. Microsoft’s Security Response Center published advisories for CVE-2026-26129, CVE-2026-26164, and CVE-2026-33111 as…

  • Mozilla Patches 423 Firefox 0-Day Vulnerabilities with Claude Mythos and Other AI Models

    Mozilla Patches 423 Firefox 0-Day Vulnerabilities with Claude Mythos and Other AI Models Mozilla has fixed a total of 423 Firefox security bugs in April 2026 alone, a figure nearly 20 times higher than its monthly average of about 21 bugs throughout 2025, driven by a groundbreaking agentic AI pipeline built around Anthropic’s Claude Mythos…

  • Dirty Frag Linux Vulnerability Let Attackers Gain Root Privileges – PoC Released

    Dirty Frag Linux Vulnerability Let Attackers Gain Root Privileges – PoC Released Dirty Frag is a newly disclosed, CVE-pending Linux kernel local privilege escalation (LPE) vulnerability that chains two separate page-cache write flaws, the xfrm-ESP Page-Cache Write and the RxRPC Page-Cache Write, to achieve root access on virtually all major Linux distributions, with a public exploit…

  • Multiple Critical Vulnerabilities Patched in Next.js and React Server Components

    Multiple Critical Vulnerabilities Patched in Next.js and React Server Components Vercel has released an extensive set of security advisories for Next.js, addressing more than a dozen vulnerabilities, including denial-of-service, middleware bypass, server-side request forgery, and cross-site scripting. The flaws affect Next.js versions 13.x through 16.x using the App Router, as well as React Server Components…

  • Smashing Security podcast #466: Meta sees everything, Copy Fail, and a deepfake gets hired

    Smashing Security podcast #466: Meta sees everything, Copy Fail, and a deepfake gets hired Meta’s smart glasses promise privacy “designed for you” – but everything they record was being beamed off to workers in Nairobi to label by hand. When those workers blew the whistle, Meta sacked all 1,108 of them. Meanwhile, the IT press…

  • Critical Palo Alto Firewalls Vulnerability Exploited in the Wild to Gain Root Access

    Critical Palo Alto Firewalls Vulnerability Exploited in the Wild to Gain Root Access Palo Alto Networks has disclosed a critical buffer overflow vulnerability in PAN-OS software, tracked as CVE-2026-0300, that is already being actively exploited in the wild. The flaw carries a CVSS 4.0 score of 9.3 (CRITICAL) and allows unauthenticated attackers to execute arbitrary…

  • Microsoft Edge Stores All Saved Passwords in Cleartext Process Memory at Launch

    Microsoft Edge Stores All Saved Passwords in Cleartext Process Memory at Launch A security researcher has discovered that Microsoft Edge decrypts every stored password into process memory the moment the browser launches and keeps them there as cleartext, regardless of whether the user ever visits those sites. The finding, disclosed on April 29 by PaloAltoNtwks…

  • Critical Apache HTTP Server Flaw Exposes Millions of Servers to RCE Attacks

    Critical Apache HTTP Server Flaw Exposes Millions of Servers to RCE Attacks The Apache Software Foundation has released a critical security update for Apache HTTP Server, patching five vulnerabilities, including a dangerous double-free flaw capable of enabling Remote Code Execution (RCE) in version 2.4.67, released on May 4, 2026. All users running version 2.4.66 or…

  • cPanelSniper – PoC Exploit Disclosed for cPanel Vulnerability, 44,000 Servers Compromised

    cPanelSniper – PoC Exploit Disclosed for cPanel Vulnerability, 44,000 Servers Compromised A weaponized proof-of-concept (PoC) exploit framework dubbed “cPanelSniper” has been publicly released for CVE-2026-41940, a maximum-severity authentication bypass in cPanel & WHM that has already led to the compromise of tens of thousands of servers worldwide with attack activity traced as far back as…

  • Alleged Silk Typhoon hacker extradited to the United States to face charges

    Alleged Silk Typhoon hacker extradited to the United States to face charges A man accused of working as a hacker for China’s Ministry of State Security has been extradited to the USA from Italy, and faces – if found guilty – the prospect of decades behind bars. Read more in my article on the Hot…

  • Critical Pack2TheRoot Vulnerability Let Attackers Gain Root Access or Compromise the System

    Critical Pack2TheRoot Vulnerability Let Attackers Gain Root Access or Compromise the System A high-severity privilege escalation vulnerability, dubbed Pack2TheRoot (CVE-2026-41651, CVSS 3.1: 8.8), has been publicly disclosed by Deutsche Telekom’s Red Team, affecting multiple major Linux distributions in their default installations. The flaw allows any local unprivileged user to silently install or remove system packages,…

  • Smashing Security podcast #464: Rockstar got hacked. The data was junk. The secrets it revealed were not

    Smashing Security podcast #464: Rockstar got hacked. The data was junk. The secrets it revealed were not A company that ran anonymous tip lines for 35,000 American schools – handling reports of bullying, weapons, and self-harm – boasted on its website that it had suffered zero security breaches in over 20 years. A hacker called…

  • Critical Atlassian Bamboo Data Center and Server Flaw Enables Command Injection Attacks

    Critical Atlassian Bamboo Data Center and Server Flaw Enables Command Injection Attacks Atlassian has disclosed two significant security vulnerabilities affecting its Bamboo Data Center and Server product, including a critical OS command injection flaw and a high-severity denial-of-service issue tied to a third-party dependency. Organizations running affected versions are strongly urged to apply patches immediately.…

  • CrowdStrike LogScale Vulnerability Allows Remote Attackers to Read Arbitrary Files from Server

    CrowdStrike LogScale Vulnerability Allows Remote Attackers to Read Arbitrary Files from Server CrowdStrike has issued an urgent security advisory for a critical unauthenticated path-traversal vulnerability (CVE-2026-40050) affecting its LogScale platform, warning that a remote attacker could exploit the flaw to read arbitrary files directly from the server’s filesystem without authentication. The vulnerability resides in a…

  • Claude Code, Gemini CLI, and GitHub Copilot Vulnerable to Prompt Injection via GitHub Comments

    Claude Code, Gemini CLI, and GitHub Copilot Vulnerable to Prompt Injection via GitHub Comments A critical cross-vendor vulnerability class dubbed “Comment and Control” is a new category of prompt injection attacks that weaponizes GitHub pull request titles, issue bodies, and issue comments to hijack AI coding agents and steal API keys and access tokens directly from CI/CD…

  • Smashing Security podcast #463: This AI company leaked its own code. It’s also built something terrifying

    Smashing Security podcast #463: This AI company leaked its own code. It’s also built something terrifying A hacking group claims to have broken into the flood defence system protecting Venice’s Piazza San Marco – and is offering to sell access to whoever wants it. The asking price? A frankly insulting $600. Meanwhile, Anthropic accidentally leaked…

  • Google Unveils Device-Bound Chrome Sessions in Anti-Cookie-Theft Move

    Google Unveils Device-Bound Chrome Sessions in Anti-Cookie-Theft Move Google officially announced the public rollout of Device Bound Session Credentials (DBSC) for Windows users on Chrome 146. According to the Google Account Security and Chrome teams, this major security update aims to eliminate session hijacking, a primary method for attackers to compromise user accounts. The feature…

  • Juniper Networks Default Password Vulnerability Let Attacker Take Full Control of the Device

    Juniper Networks Default Password Vulnerability Let Attacker Take Full Control of the Device A critical security alert warns of a severe default password vulnerability affecting Support Insights Virtual Lightweight Collector (vLWC) appliances. This flaw enables unauthenticated network-based attackers to gain full administrative control of exposed network devices easily. Formally tracked as CVE-2026-33784, this vulnerability has…

  • Critical Claude Code Flaw Silently Bypasses Developer-Configured Security Rules

    Critical Claude Code Flaw Silently Bypasses Developer-Configured Security Rules A high-severity security bypass vulnerability in Anthropic’s Claude Code AI coding agent allows malicious actors to silently evade user-configured deny rules through a simple command-padding technique, exposing hundreds of thousands of developers to credential theft and supply chain compromise. According to Adversa, the flaw was traced…

  • Smashing Security podcast #461: This man hid $400 million in a fishing rod. Then it vanished

    Smashing Security podcast #461: This man hid $400 million in a fishing rod. Then it vanished A cannabis-growing, beekeeping, gyrocopter-flying Irishman invested his drug money in Bitcoin back in 2011 – and now sits on a fortune worth $400 million. There’s just one small problem: the access codes were tucked inside his fishing rod case,…

  • New Windows Error Reporting Vulnerability Lets Attackers Escalate to Gain SYSTEM Access

    New Windows Error Reporting Vulnerability Lets Attackers Escalate to Gain SYSTEM Access A newly analyzed local privilege escalation vulnerability in the Windows Error Reporting (WER) service allows attackers to easily gain full SYSTEM access. The flaw, tracked as CVE-2026-20817, was considered so structurally dangerous that Microsoft completely removed the vulnerable feature rather than attempting a…

  • Oracle Issues Urgent Security Update for Critical RCE Flaw in Identity Manager and Web Services Manager

    Oracle Issues Urgent Security Update for Critical RCE Flaw in Identity Manager and Web Services Manager Oracle has issued an out-of-band Security Alert addressing a critical remote code execution (RCE) vulnerability, CVE-2026-21992, affecting two widely deployed Fusion Middleware components, Oracle Identity Manager and Oracle Web Services Manager. The vulnerability carries a CVSS 3.1 base score…

  • Cisco Firewall 0-day Vulnerability Exploited in the Wild to Deploy Interlock Ransomware

    Cisco Firewall 0-day Vulnerability Exploited in the Wild to Deploy Interlock Ransomware An active campaign by the Interlock ransomware group is exploiting a critical zero-day vulnerability (CVE-2026-20131) in Cisco Secure Firewall Management Center (FMC) Software. The vulnerability may allow an unauthenticated remote attacker to execute arbitrary Java code with root privileges on an affected device.…

  • Microsoft to Block Windows 11 and Server 2025 Automated Installation After Critical RCE Vulnerability

    Microsoft to Block Windows 11 and Server 2025 Automated Installation After Critical RCE Vulnerability Microsoft has announced a two-phase plan to disable the hands-free deployment feature in Windows Deployment Services (WDS) following the discovery of a critical remote code execution (RCE) vulnerability tracked as CVE-2026-0386. The flaw, rooted in improper access control, allows an unauthenticated…

  • Microsoft Releases Out-of-Band Patch For Critical RRAS RCE Vulnerabilities in Windows 11

    Microsoft Releases Out-of-Band Patch For Critical RRAS RCE Vulnerabilities in Windows 11 Microsoft released an out-of-band hotpatch update on March 13, 2026, addressing serious security vulnerabilities in Windows 11 versions 24H2 and 25H2. Tracked as KB5084597 and targeting OS Builds 26200.7982 and 26100.7982, this update patches three actively concerning flaws in the Windows Routing and…

  • Critical LangSmith Account Takeover Vulnerability Puts Users at Risk

    Critical LangSmith Account Takeover Vulnerability Puts Users at Risk Miggo Security researchers have identified a critical vulnerability in LangSmith, tracked as CVE-2026-25750, that exposes users to potential token theft and complete account takeover. As a central hub for debugging and monitoring large language model data, LangSmith processes billions of events daily, making this a high-stakes…

  • OpenSSH GSSAPI Vulnerability Allow an Attacker to Crash SSH Child Processes

    OpenSSH GSSAPI Vulnerability Allow an Attacker to Crash SSH Child Processes A significant vulnerability in the GSSAPI Key Exchange patch was applied by numerous Linux distributions on top of their OpenSSH packages. The flaw, tracked as CVE-2026-3497, was uncovered by security researcher Jeremy Brown. It allows an attacker to crash SSH child processes reliably and…

  • GitLab Security Update – Patch for XSS and API DoS Vulnerabilities

    GitLab Security Update – Patch for XSS and API DoS Vulnerabilities GitLab has released urgent security updates for its Community Edition (CE) and Enterprise Edition (EE) to address a wide range of vulnerabilities. The newly released versions 18.9.2, 18.8.6, and 18.7.6 fix a total of 15 security issues, including critical Cross-Site Scripting (XSS) and Denial-of-Service…

  • Microsoft SQL Server Zero-Day Vulnerability Allows Attackers to Escalate Privileges

    Microsoft SQL Server Zero-Day Vulnerability Allows Attackers to Escalate Privileges Microsoft has disclosed a critical zero-day vulnerability in SQL Server that allows authenticated attackers to escalate their privileges to the highest administrative level on affected database systems. Tracked as CVE-2026-21262, the flaw was officially released on March 10, 2026, and has already been publicly disclosed,…

  • Smashing Security podcast #457: How a cybersecurity boss framed his own employee

    Smashing Security podcast #457: How a cybersecurity boss framed his own employee When a top cybersecurity firm discovered it had a leak, you would expect the FBI to be called. Instead, the person put in charge of the investigation was the actual leaker… who promptly sent an innocent colleague into a career-ending ambush. In this…

  • Phishing Schemes Abuse .arpa TLD and IPv6 Tunnels to Evade Detection

    Phishing Schemes Abuse .arpa TLD and IPv6 Tunnels to Evade Detection Cybersecurity researchers at Infoblox Threat Intel have uncovered a highly sophisticated phishing campaign that exploits the foundational plumbing of the internet to bypass enterprise security controls. In a novel evasion tactic, threat actors are weaponizing the .arpa top-level domain (TLD) and utilizing IPv6 tunnels to host…

  • Hackers Abuse Windows File Explorer and WebDAV for Stealthy Malware Delivery

    Hackers Abuse Windows File Explorer and WebDAV for Stealthy Malware Delivery Cybercriminals are increasingly abusing a legacy feature within Windows File Explorer to distribute malware, bypassing traditional web browser security and endpoint detection controls. According to a threat report by Kahng An of the Cofense Intelligence Team, threat actors are leveraging Web-based Distributed Authoring and…

  • Metasploit Adds New Modules Targeting Linux RC4, BeyondTrust, and Registry Persistence

    Metasploit Adds New Modules Targeting Linux RC4, BeyondTrust, and Registry Persistence The latest Metasploit update, released on February 27, 2026, brings significant firepower to security professionals and penetration testers. The release introduces seven new modules, nine feature enhancements, and critical bug fixes. Standout additions include unauthenticated remote code execution (RCE) exploits for Ollama, BeyondTrust, and…

  • Critical Claude Code Vulnerabilities Enables Remote Code Execution Attacks

    Critical Claude Code Vulnerabilities Enables Remote Code Execution Attacks A critical security flaw in Anthropic’s Claude Code demonstrates how threat actors can exploit repository configuration files to execute malicious code and steal sensitive API keys. The vulnerabilities, tracked as CVE-2025-59536 and CVE-2026-21852, highlight a significant shift in the software supply chain threat landscape as AI…

  • Critical Jenkins Vulnerability Exposes Build Environments to XSS Attacks

    Critical Jenkins Vulnerability Exposes Build Environments to XSS Attacks Security Advisory has revealed multiple vulnerabilities in Jenkins Core, including a stored Cross-Site Scripting (XSS) flaw that could expose build environments to severe security risks. The issues, identified as CVE-2026-27099 and CVE-2026-27100, were responsibly disclosed under the Jenkins Bug Bounty Program sponsored by the European Commission. The most critical of the…

  • Critical Windows Admin Center Vulnerability Allows Privilege Escalation

    Critical Windows Admin Center Vulnerability Allows Privilege Escalation A critical security update addressing a high‑severity elevation of privilege vulnerability in Windows Admin Center (WAC), identified as CVE‑2026‑26119. The flaw, rated CVSS 8.8 (Critical), stems from improper authentication (CWE‑287) that could allow an authorized attacker to gain elevated network privileges. According to Microsoft, this vulnerability affects Windows Admin Center version 2.6.4, and…

  • Apache NiFi Vulnerability Enables Authorization Bypass

    Apache NiFi Vulnerability Enables Authorization Bypass A newly disclosed high-severity vulnerability in Apache NiFi exposes systems to an authorization bypass that could allow lower-privileged users to modify restricted components. Tracked as CVE-2026-25903, the flaw impacts Apache NiFi versions 1.1.0 through 2.7.2 and has been fixed in version 2.8.0. According to the Apache NiFi security advisory, the issue arises from missing…

  • Langchain Community SSRF Bypass Vulnerability Enables Access to Internal Services

    Langchain Community SSRF Bypass Vulnerability Enables Access to Internal Services A Server‑Side Request Forgery (SSRF) vulnerability has been identified in the langchain/community package, affecting versions up to 1.1.13. The flaw, tracked as CVE‑2026‑26019, has a moderate severity rating, with a CVSS 3.1 score, due on its potential to expose sensitive cloud metadata and internal infrastructure. The vulnerability originates from the RecursiveUrlLoader class, which…

  • 25 Vulnerabilities in Cloud Password Managers Allow Unauthorized Access and Modifications

    25 Vulnerabilities in Cloud Password Managers Allow Unauthorized Access and Modifications Researchers from ETH Zurich have uncovered 25 serious vulnerabilities in three leading cloud-based password managers: Bitwarden, LastPass, and Dashlane. These flaws enable a malicious server to bypass zero-knowledge encryption claims, allowing unauthorized access, modification, and recovery of users’ stored passwords and vault data. Bitwarden,…

  • Critical BeyondTrust Vulnerability Exploited in the Wild to Gain Full Domain Control

    Critical BeyondTrust Vulnerability Exploited in the Wild to Gain Full Domain Control A critical vulnerability tracked as CVE-2026-1731 is being actively exploited in the wild, enabling attackers to gain full domain control over affected systems. Threat actors are leveraging this flaw to execute operating system commands remotely without authentication. The flaw, discovered in self-hosted BeyondTrust deployments, allows unauthenticated…

  • Threat Actors Exploit Claude Artifacts and Google Ads to Target macOS Users

    Threat Actors Exploit Claude Artifacts and Google Ads to Target macOS Users A sophisticated malware campaign targeting macOS users through Google-sponsored search results and legitimate platforms, including Anthropic’s Claude AI and Medium. The campaign has already reached over 15,000 potential victims through two distinct attack variants that exploit users’ trust in established online services. 15,000…

  • Palo Alto Networks Firewall Vulnerability Allows an Attacker to Force Firewalls into a Reboot Loop

    Palo Alto Networks Firewall Vulnerability Allows an Attacker to Force Firewalls into a Reboot Loop A critical denial-of-service (DoS) flaw in Palo Alto Networks’ PAN-OS software could let unauthenticated attackers crash firewalls into endless reboot cycles, potentially crippling enterprise networks. Dubbed CVE-2026-0229, the vulnerability lurks in the Advanced DNS Security (ADNS) feature. An attacker sends…

  • Windows Notepad Vulnerability Allows Attackers to Execute Malicious Code Remotely

    Windows Notepad Vulnerability Allows Attackers to Execute Malicious Code Remotely Microsoft has patched a critical remote code execution (RCE) flaw in the Windows Notepad app, tracked as CVE-2026-20841, which could let attackers run malicious code on victims’ machines. Disclosed on February 10, 2026, Microsoft Patch Tuesday updates, the vulnerability stems from improper neutralization of special…

  • Augustus – Open-source LLM Vulnerability Scanner With 210+ Attacks Across 28 LLM Providers

    Augustus – Open-source LLM Vulnerability Scanner With 210+ Attacks Across 28 LLM Providers Augustus is a new open-source vulnerability scanner designed to secure Large Language Models (LLMs) against an evolving landscape of adversarial threats. Built by Praetorian, Augustus aims to bridge the gap between academic research tools and production-grade security testing, offering a single-binary solution…

  • Critical FortiClientEMS Vulnerability Let Attackers Execute Malicious Code Remotely

    Critical FortiClientEMS Vulnerability Let Attackers Execute Malicious Code Remotely Fortinet has issued a critical security advisory warning administrators to immediately patch instances of FortiClientEMS, its central management solution for endpoint protection. The vulnerability, tracked as CVE-2026-21643, carries a CVSSv3 score of 9.1 and could allow unauthenticated, remote attackers to execute arbitrary code or unauthorized commands…

  • Claude Opus 4.6 Released with Improved Cybersecurity, Validating 500+ high-severity Vulnerabilities

    Claude Opus 4.6 Released with Improved Cybersecurity, Validating 500+ high-severity Vulnerabilities Anthropic’s latest AI model autonomously identifies critical flaws in decades-old codebases, raising the stakes for both defenders and attackers Anthropic released Claude Opus 4.6 on February 5, 2026, with dramatically enhanced cybersecurity capabilities that have already identified more than 500 previously unknown high-severity vulnerabilities…