A practical checklist for the Fastjson RCE vulnerability (CVE-2026-16723): how the exploit chain works, four questions to answer this week, and how to mitigate it before a patch exists. How the Fastjson RCE Vulnerability Actually Works, and How to Check…
Category: Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Shark Vacuum Vulnerability Lets Attackers Hijack Cameras Across an Entire AWS Region
A researcher found that anyone with physical access to one Shark robot vacuum can extract its AWS IoT certificate and use it to take over other Shark vacuums region-wide, with no patch yet available. Shark Vacuum Vulnerability Lets Attackers Hijack…
Cursor’s Unpatched Zero-Day Lets a Fake git.exe Hijack Any Windows Developer
A Cursor zero-day vulnerability lets a planted git.exe run automatically when a Windows developer opens a repository. Mindgard disclosed it after seven months of silence from Cursor. Cursor’s Unpatched Zero-Day Lets a Fake git.exe Hijack Any Windows Developer on Latest…
CVE-2026-14266: Inside the 7-Zip Heap Overflow Hiding in XZ Archives Since 2021
A heap-based buffer overflow in 7-Zip's XZ decoder, patched in version 26.02, let a crafted archive run code on extraction and had gone unnoticed for five years. CVE-2026-14266: Inside the 7-Zip Heap Overflow Hiding in XZ Archives Since 2021 on…
wp2shell: WordPress Patches a Pre-Auth RCE That Needed No Plugins
WordPress 6.9.5 and 7.0.2 fix wp2shell, a core REST API bug chaining route confusion and SQL injection into unauthenticated remote code execution. wp2shell: WordPress Patches a Pre-Auth RCE That Needed No Plugins on Latest Hacking News | Cyber Security News,…
The Ill Bloom Vulnerability: How to Check If Your Wallet Is Exposed
A weak random-number generator behind the Ill Bloom vulnerability has let attackers drain over $5 million from crypto wallets. Here's how to check exposure and fix it. The Ill Bloom Vulnerability: How to Check If Your Wallet Is Exposed on…
11 Old Signed UEFI Shims Just Broke Secure Boot on Millions of PCs
ESET found 11 Microsoft-signed UEFI shims, some over a decade old, that let attackers bypass Secure Boot without a single new exploit. 11 Old Signed UEFI Shims Just Broke Secure Boot on Millions of PCs on Latest Hacking News |…
Two Joomla Extensions Hit by Zero-Day File Upload Attacks Before Patches Landed
CISA added CVE-2026-48939 and CVE-2026-56291 to its Known Exploited Vulnerabilities catalog after automated attackers exploited file upload flaws in iCagenda and Balbooa Forms weeks before either bug had a CVE number. Two Joomla Extensions Hit by Zero-Day File Upload Attacks…
How the GodDamn Ransomware Driver Bypasses Your EDR
GodDamn ransomware’s PoisonX driver is a textbook EDR bypass driver: a Microsoft-signed kernel driver that kills security tools instead of exploiting them. How the GodDamn Ransomware Driver Bypasses Your EDR on Latest Hacking News | Cyber Security News, Hacking Tools…
Kerberoasting Attack Explained Step by Step
A technical walkthrough of the kerberoasting attack: the Kerberos quirk it abuses, RC4 vs AES, and how to detect and fix it in Active Directory. Kerberoasting Attack Explained Step by Step on Latest Hacking News | Cyber Security News, Hacking…
Adobe ColdFusion Vulnerabilities Are a Design Failure, Not Bad Luck
Adobe frames the fast exploitation of its ColdFusion vulnerabilities as an attacker speed problem. The real issue is a connector that never should have trusted an unauthenticated request. Adobe ColdFusion Vulnerabilities Are a Design Failure, Not Bad Luck on Latest…
Gitea Docker Vulnerability Now Under Active Probing, CVE-2026-20896
A critical flaw in Gitea’s official Docker image let anyone impersonate an admin with one forged header. Sysdig spotted the first exploitation attempts 13 days after the fix shipped. Gitea Docker Vulnerability Now Under Active Probing, CVE-2026-20896 on Latest Hacking…
Inside Android’s New Lockscreen Rate-Limiting Rules
Google has replaced Android’s 1,800-guess lockscreen limit with a 20-attempt hard cap. Here is how the new rate limiter works and what it means for anyone testing or managing Android devices. Inside Android’s New Lockscreen Rate-Limiting Rules on Latest Hacking…
CSRF Attack Explained: Mechanics, Real Exploits, and How to Test for It
A practitioner’s breakdown of the CSRF attack: how the forged request works, two documented exploits, a manual test, and the fixes that hold up. CSRF Attack Explained: Mechanics, Real Exploits, and How to Test for It on Latest Hacking News…
Credential Stuffing: A Defender’s Guide to Detecting Automated Login Attacks
Credential stuffing tests stolen password lists against your login form until one matches. Here is how to spot the traffic pattern and layer defences that actually hold. Credential Stuffing: A Defender’s Guide to Detecting Automated Login Attacks on Latest Hacking…
“Bad Epoll” Linux Kernel Bug Lets Any User Grab Root
A newly disclosed use-after-free in the Linux kernel’s epoll code, CVE-2026-46242, lets an unprivileged user get root on affected Linux and Android systems. A fix is out, but it took two attempts. “Bad Epoll” Linux Kernel Bug Lets Any User…
What Is a Brute Force Attack? A Practical Defender’s Guide
A brute force attack automates password guessing until one works. Here’s why it still succeeds, real incidents it’s caused, and a practical checklist to stop it. What Is a Brute Force Attack? A Practical Defender’s Guide on Latest Hacking News…
Google and FBI Dismantle NetNut Residential Proxy Botnet
Google, the FBI and the IRS Criminal Investigation division disrupted NetNut, a residential proxy network built on two million hijacked devices and used by 316 threat clusters in a single week. Google and FBI Dismantle NetNut Residential Proxy Botnet on…
NetScaler Memory Overread Flaw Revives CitrixBleed Fears
Citrix has patched a pre-auth NetScaler memory overread bug, CVE-2026-8451, that echoes the 2023 CitrixBleed flaw and was found while researchers dissected an earlier Citrix bug. NetScaler Memory Overread Flaw Revives CitrixBleed Fears on Latest Hacking News | Cyber Security…
Cursor IDE Vulnerabilities Let Prompt Injection Escape the Sandbox
Two critical Cursor IDE vulnerabilities, dubbed DuneSlide, let prompt injection break the editor’s command sandbox with no click required. Both are fixed in Cursor 3.0. Cursor IDE Vulnerabilities Let Prompt Injection Escape the Sandbox on Latest Hacking News | Cyber…