Panel patched CVE-2026-67401, which lets a hosting account with mail privileges create files anywhere and run code as root.
F5 BIG-IP malware injects a PHP web shell into memory, leaving targeted scripts unchanged on disk while commands run through ...
A Microsoft Defender patch bypass PoC demonstrates arbitrary file read as SYSTEM on the latest Windows version.
Cybersecurity companies Volexity and Proofpoint have been acknowledged for reporting CVE-2026-85880, while Romain Deperne, an ...
CISA added actively exploited N-able N-central CVE-2026-86218 to KEV, with federal agencies ordered to patch by September 11.
Slim Spider attacks Brazilian financial firms, stealing cloud credentials and crypto custody secrets while targeting Pix ...
Liquid received 3,400 bitcoin back after nearly 4,000 BTC was taken; 598.5 BTC remains unreturned and the network is still paused.
A planted ChatGPT instruction could read connected Gmail data and relay it across accounts through shared Artifactory ...
A financially motivated actor used an autonomous multi-agent framework to compromise thousands of third-party credentials in ...
A WeChat worm demo took over iPhone and Android accounts through incoming calls from existing contacts; Calif says Tencent ...
Chainguard says Factory 2.0 doubled container build manifests to over 1 billion in six months using AI-assisted ...
FreeIPA and 389 Directory Server flaws let an anonymous client create an attacker-chosen Kerberos identity in the administrators group.