Four severe vulnerabilities deeply embedded within the Linux kernel, lurking undetected for 10 to 21 years, finally have functional public exploits. Consequently, these critical flaws allow attackers to achieve root privilege escalation. These vulnerabilities...
The prominent cybersecurity firm CrowdSec recently acknowledged a significant data breach. Attackers successfully exfiltrated source code from approximately 170 private GitHub repositories. A malicious actor initially duplicated this proprietary code on May 22, 2026....
An attempt to download a film through a familiar torrent tracker could infect a computer even without the tracker itself being hacked. Attackers compromised iTorrents.org, a popular repository of torrent files, and made the...
Extortion has suddenly turned against the extortionists themselves. ShinyHunters gained access to the Tor site of the Clop group and replaced its content with a page of its own. BleepingComputer confirmed that the attackers...
A single link in an attacker’s hands can make WordPress install a theme without a button being pressed, provided an already-authenticated administrator opens it. On September 17, WordPress released version 7.1.1, which closes a...
Firefox recently received one of its most substantial security packages in recent history. Within the Firefox 156 release, Mozilla decisively remediated an astonishing 73 vulnerabilities. This formidable list encompassed dozens of vectors allowing for...
Although a patch for the critical VMware vCenter vulnerability has existed since late July, the situation escalated into a significantly more perilous phase over the subsequent six weeks. The Cybersecurity and Infrastructure Security Agency...
Adversaries have ingeniously manipulated Google Docs to perform a function utterly unexpected from a cloud-based word processor: they transformed a standard document into an interactive malware installation vector. Following the conclusion of the prestigious...
The boundary separating an individual client account from the entire server infrastructure within LiteSpeed Web Server Enterprise has proven alarmingly fragile. Recently, cPanel issued a stark warning regarding a critical privilege escalation vulnerability. Within...
The Revolut data-leak saga has proven considerably wider than the initial account. A hacker under the pseudonym IAmNotAVillain claims that the attackers maintained access to the systems of several Italian law-enforcement divisions for about...
Apple has mounted the largest vulnerability purge in its entire history: a single September cycle brought more than 260 unique CVEs and sent nearly the whole of the company’s ecosystem scrambling to update. On...
A staggering misconfiguration within an attacker’s own offensive infrastructure fortuitously exposed nearly the entire exploitation chain orchestrated against a prominent Thai internet service provider. Hunt.io analysts discovered an unprotected, openly accessible server maintained by...
A routine export of Telegram correspondence could inadvertently transform a saved chat history into a covert instrument for message theft. Security researchers uncovered a pernicious vulnerability residing within Telegram Desktop. This critical flaw permitted...
An entirely ordinary Android application, devoid of any requested permissions, can now seize absolute control over contemporary flagship smartphones. Calif researcher Lucas Maar brilliantly demonstrated a devastating attack vector targeting devices from Samsung, Xiaomi,...
In a matter of mere days, a publicly disclosed exploit targeting Gitea rapidly metamorphosed into an industrialized instrument for source code theft. The Red Heron threat group ruthlessly automated the discovery of vulnerable servers,...