The incident occurred in May, when RubyGems maintainers suspended new account registrations due to what appeared like malicious activity.
Category: EN
Shared Hosting at Risk: LiteSpeed Enterprise Bug Can Grant Root from a Single Tenant
Critical LiteSpeed Enterprise flaw lets one shared hosting account gain root, bypassing CageFS; patch now to 6.3.7 via forced update. cPanel warned that a…
Global public-private operation disrupts Sality botnet active for two decades
An international operation supported by Europol has disrupted the Sality peer-to-peer (P2P) botnet, a long-running criminal infrastructure used to…
Researchers Find OAuth Token Exposure in Twitch Extension Used by 30K
Researchers found a Twitch extension used by 30,000 Chrome users transmitting OAuth tokens, potentially exposing authenticated account access.
Uncensored AI sold on hacking forum as alternative to ChatGPT and Claude jailbreaks
A new AI subscription service called Luciferus is being marketed on a hacking forum as an alternative to jailbreaking ChatGPT or Claude, Sophos found. The…
Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Attackers are actively exploiting a critical flaw in a WooCommerce extension to seize control of WordPress sites without a username or password. The issue…
1.8M Android APKs Scanned for Hardcoded Secrets in Automated Attack
Attackers scanned 1.8 million Android APKs for hardcoded secrets, showing why developers need stronger credential management and production-build security.
Google’s New Search Redirects Make It Harder to Check Where Links Lead Before Clicking
Google is changing how some search-result links behave. Certain results now pass through an encoded Google redirect rather than opening the listed site,…
Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point
Introduction Security teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization…
New Italian unicorn Exein rides the physical AI wave
Italian startup Exein has raised a $270 million round of funding led by Headline at a $1.7 billion valuation.
Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers
Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an…
Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
Threat actors are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin that lets unauthenticated attackers upload…
Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds
With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors,…
240,000 Hit by Data Breach at Japan’s Digital Agency
Hackers exploited a vulnerability in a VPN product to steal the personal information of roughly 240,000 people.
Weekly Cybersecurity Newsletter – Top 50 Biggest Cybersecurity Stories of the Week
Microsoft Patches 973 CVEs, Claude Agents Automate Attacks, China Chains Chrome Zero-Day, Cisco FMC Exploited & More. Welcome to this week’s edition of…
HBO Max’s verified Reddit account hijacked to spread malware
Cybercriminals used HBO Max’s verified Reddit account to run 108 malicious ads that tricked people into installing information stealers.
25 Years of Mass Surveillance Is Enough
This essay was written with Cindy Cohn, and originally appeared in Lawfare . One of the many legacies of the terrorist attacks of Sept. 11 is the…
Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)
Attackers have leveraged a zero-day SQL injection vulnerability (CVE-2026-76461) to compromise Cisco Secure Email Gateway appliances, Cisco confirmed on…
WordPress Events Calendar Vulnerabilities Let Hackers Take Over 600,000 Websites
Two critical unauthenticated vulnerability chains in the widely used The Events Calendar WordPress plugin could allow attackers to execute code and fully…
Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases
The updates resolve kernel vulnerabilities that could lead to memory corruption, privilege escalation, system termination, and information leaks.
