A Storm-2945 campaign layers device code phishing onto hijacked hotel Wi-Fi to bypass MFA on Microsoft 365 accounts. Here’s how it works and how to shut…
Tag: Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses
Check Point SmartConsole Authentication Bypass Is Under Active Attack, and a PoC Is Now Public
CVE-2026-16232 lets an unauthenticated attacker seize full admin control of Check Point’s management console. Check Point confirms in-the-wild attacks,…
A Skipped Cookie Check Let Flatpak Apps Escape PipeWire’s Sandbox Entirely
CVE-2026-5674 chains a broken PulseAudio auth check, default module loading, and an unrestricted dlopen() into a full PipeWire sandbox escape from inside…
Sweet Security Brings Autonomous Protection to the AI Enterprise with New Blocking Capabilities
Las Vegas, USA, 29th July 2026, CyberNewswire Sweet Security Brings Autonomous Protection to the AI Enterprise with New Blocking Capabilities on Latest…
Why Your Business Needs a Secure Messaging Platform
Business communication has shifted almost entirely to digital channels, creating unprecedented efficiency but also exposing… Why Your Business Needs a…
Public Exploit Lands for vBulletin’s Pre-Auth RCE, CVE-2026-61511
A public proof-of-concept for the vBulletin RCE vulnerability CVE-2026-61511 is now live. Here’s how the eval() injection works and who still needs to…
Public Exploit Lands for vBulletin’s Pre-Auth RCE, CVE-2026-61511
A public proof-of-concept for the vBulletin RCE vulnerability CVE-2026-61511 is now live. Here’s how the eval() injection works and who still needs to…
How the Bing Images RCE Flaws Actually Worked, and How to Check Your Own Pipeline
A three-line SVG gave XBOW SYSTEM access on Bing's servers through a default ImageMagick setting. Here's the exploit chain and a checklist for anyone running a similar image pipeline. How the Bing Images RCE Flaws Actually Worked, and How to…
ENCFORGE Ransomware Targets AI Models After Langflow RCE Exploit
An AI-driven threat actor called JADEPUFFER built ransomware that hunts AI model files specifically, entering through a known Langflow RCE and pivoting via an exposed Docker socket. ENCFORGE Ransomware Targets AI Models After Langflow RCE Exploit on Latest Hacking News…
Azure DevOps MCP Flaw: How to Lock Down Your AI Review Agent Before Microsoft Patches It
A practical checklist for the Azure DevOps MCP flaw that lets hidden PR comments hijack AI coding agents, plus the configuration changes to make right now. Azure DevOps MCP Flaw: How to Lock Down Your AI Review Agent Before Microsoft…
Chaos Ransomware’s msaRAT Hides Its C2 Inside Your Own Browser
Cisco Talos has detailed msaRAT, a Rust-based RAT used by the Chaos ransomware crew that drives a headless Chrome or Edge session over CDP to smuggle C2 traffic through Cloudflare and Twilio infrastructure. Chaos Ransomware’s msaRAT Hides Its C2 Inside…
How the Fastjson RCE Vulnerability Actually Works, and How to Check You’re Exposed
A practical checklist for the Fastjson RCE vulnerability (CVE-2026-16723): how the exploit chain works, four questions to answer this week, and how to mitigate it before a patch exists. How the Fastjson RCE Vulnerability Actually Works, and How to Check…
Shark Vacuum Vulnerability Lets Attackers Hijack Cameras Across an Entire AWS Region
A researcher found that anyone with physical access to one Shark robot vacuum can extract its AWS IoT certificate and use it to take over other Shark vacuums region-wide, with no patch yet available. Shark Vacuum Vulnerability Lets Attackers Hijack…
Cursor’s Unpatched Zero-Day Lets a Fake git.exe Hijack Any Windows Developer
A Cursor zero-day vulnerability lets a planted git.exe run automatically when a Windows developer opens a repository. Mindgard disclosed it after seven months of silence from Cursor. Cursor’s Unpatched Zero-Day Lets a Fake git.exe Hijack Any Windows Developer on Latest…
CVE-2026-14266: Inside the 7-Zip Heap Overflow Hiding in XZ Archives Since 2021
A heap-based buffer overflow in 7-Zip's XZ decoder, patched in version 26.02, let a crafted archive run code on extraction and had gone unnoticed for five years. CVE-2026-14266: Inside the 7-Zip Heap Overflow Hiding in XZ Archives Since 2021 on…
wp2shell: WordPress Patches a Pre-Auth RCE That Needed No Plugins
WordPress 6.9.5 and 7.0.2 fix wp2shell, a core REST API bug chaining route confusion and SQL injection into unauthenticated remote code execution. wp2shell: WordPress Patches a Pre-Auth RCE That Needed No Plugins on Latest Hacking News | Cyber Security News,…
The Ill Bloom Vulnerability: How to Check If Your Wallet Is Exposed
A weak random-number generator behind the Ill Bloom vulnerability has let attackers drain over $5 million from crypto wallets. Here's how to check exposure and fix it. The Ill Bloom Vulnerability: How to Check If Your Wallet Is Exposed on…
11 Old Signed UEFI Shims Just Broke Secure Boot on Millions of PCs
ESET found 11 Microsoft-signed UEFI shims, some over a decade old, that let attackers bypass Secure Boot without a single new exploit. 11 Old Signed UEFI Shims Just Broke Secure Boot on Millions of PCs on Latest Hacking News |…
Two Joomla Extensions Hit by Zero-Day File Upload Attacks Before Patches Landed
CISA added CVE-2026-48939 and CVE-2026-56291 to its Known Exploited Vulnerabilities catalog after automated attackers exploited file upload flaws in iCagenda and Balbooa Forms weeks before either bug had a CVE number. Two Joomla Extensions Hit by Zero-Day File Upload Attacks…
How the GodDamn Ransomware Driver Bypasses Your EDR
GodDamn ransomware’s PoisonX driver is a textbook EDR bypass driver: a Microsoft-signed kernel driver that kills security tools instead of exploiting them. How the GodDamn Ransomware Driver Bypasses Your EDR on Latest Hacking News | Cyber Security News, Hacking Tools…