The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity Apache Tomcat flaw, tracked as CVE-2026-34486, to its Known…
Category: Cyber Security News
Multiple Veeam ONE Vulnerabilities Allows Code Execution Attacks
Veeam has released security updates for Veeam ONE 13.1 to fix multiple vulnerabilities that could allow attackers to execute code, access sensitive files,…
1-Click RCE Flaw in Cursor, VS Code, and Google Antigravity Exposes 50M Developers to Cyberattacks
A critical one-click remote code execution (RCE) vulnerability affects three of the world’s most widely used code editors: Cursor, Microsoft VS Code, and…
Mythos 5 and GPT-5.6-Sol Agents Went Beyond Their Cyber Test and Targeted the Real World
The UK’s AI Security Institute (AISI) has disclosed a serious security incident in which AI agents under evaluation broke out of their intended test scope…
How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways
Phishing is the primary initial access vector, driving 16% of breaches at an average cost of $4.8 million. Attackers now leverage Generative AI and AiTM…
Microsoft Strengthens NuGet Supply Chain Security By Reducing API Key Lifetime
Microsoft is reducing the lifetime of NuGet.org API keys to strengthen supply chain security and reduce the risk of stolen credentials being used to…
Hackers Can Weaponize Microsoft Copilot to Hijack CEO Accounts and Redirect Wire Transfers
A new proof-of-concept reveals how attackers can turn Microsoft Copilot, the AI assistant embedded in Microsoft 365, into an unwitting accomplice for…
Roblox Malware Streams Victims’ Desktops and Captures Webcam Footage
A malicious Roblox cheat campaign is turning a familiar gaming shortcut into a serious privacy threat. Players seeking an “undetected” Xeno script…
DarkSword iOS Exploit Kit Spreads Across 180 Web Properties and 27 Hosts
DarkSword has expanded from a leaked iOS exploit chain into a broad and fast-changing network of malicious web infrastructure. The campaign targets…
OWASP Subtractive Security Top 10 Project Released to Identify and Reduce Cyber Risks
The Open Worldwide Application Security Project, or OWASP, has introduced the Subtractive Security Top 10 Project, a security engineering initiative…
CISA Warns of N-able N-central Authentication Bypass Vulnerability Exploited in Attacks
CISA has warned that attackers are actively exploiting a critical authentication bypass vulnerability in N-able N-central. Tracked as CVE-2026-18577, the…
Public PoC Released for CUPS Vulnerability Allows Attackers to Gain Root Privileges
A public proof-of-concept (PoC) has been released for CVE-2026-39875, a macOS vulnerability in the Common UNIX Printing System (CUPS) that allows an…
Six Flowise RCE Flaws Let Attackers Execute Code on AI Workflow Servers
Flowise servers used to build AI agents and automated workflows are facing six newly disclosed remote code execution flaws. The weaknesses could allow…
Critical Gitea Arbitrary File Read Vulnerability Enables Remote Code Execution Attacks
A critical security flaw in Gitea, tracked as CVE-2026-59774, allows unauthenticated remote attackers to read arbitrary files from vulnerable servers and…
Russian Hacker Breaches Companies, Sells Their Access and Spies on Ukrainian Military Sites
A Russian-speaking hacker has been linked to a broad operation that breached organizations worldwide, collected credentials, and prepared access for sale…
Keyv npm Package with 127M Weekly Downloads Compromised in Shai-Hulud Attack
Attackers have compromised the GitHub account of the maintainer behind keyv, a popular key-value storage library that pulls in roughly 127 million weekly…
Critical Adobe Campaign Classic Vulnerabilities Enables Arbitrary Code Execution
Adobe has issued a critical security update for Adobe Campaign Classic, addressing multiple flaws that could enable arbitrary code execution on vulnerable…
OpenAI Reveals How Cybercriminals are Using ChatGPT to Run Scam Operation
Online scams are becoming more organized, more personal, and harder to spot. Criminal networks are now using artificial intelligence to create believable…
Critical cPanel Vulnerability Allows Execution of SQL Commands as Root User
A critical privilege-escalation flaw in cPanel & WHM has been disclosed that could allow authenticated hosting users to execute arbitrary SQL commands…
Midnight Blizzard Hijacks Hotel Wi-Fi to Infect Travelers and Steal Cloud Credentials
Travelers using hotel Wi-Fi are facing a new threat linked to Midnight Blizzard, a Russia-linked threat group known for targeted credential theft. The…
