WordPress has released security updates for a critical unauthenticated path traversal vulnerability that can lead to local PHP file inclusion and, on…
Tag: Vulnerability
Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
Attackers exploited a previously unknown flaw in Check Point’s Security Management Server in a handful of targeted attacks on July 23, the company said.…
Check Point Management Server 0-Day Vulnerability Actively Exploited in Attacks
Check Point has warned customers that attackers are exploiting a critical zero-day vulnerability in its Security Management infrastructure. Tracked as…
Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates
A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was…
NightmareEclipse’s latest zero-day leaves Microsoft Defender stuck in the past
BigDiskBuster leaves Microsoft’s antivirus running but unable to install updates
Chaotic Eclipse Released BigDiskBuster, A PoC For Windows Defender Update DoS Zero-Day
The researcher Chaotic Eclipse released BigDiskBuster, a PoC exploit for a Windows Defender Update DoS Zero-Day vulnerability. Security researcher Chaotic…
Linux Kernel Flaw (CVE-2026-89775): ARM64 KVM Guests Gain Host Read-Write
HOC Shorts Tracked as CVE-2026-89775, a vulnerability in the Linux kernel’s KVM subsystem exposes freed host memory pages…
Chinese Hackers Exploit ZyXEL Switch Vulnerability
A Chinese threat actor has successfully exploited a vulnerability in ZyXEL network switches, compromising nearly 1,000 devices and exfiltrating sensitive…
Security Advisory – Action Required – Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616
As part of Check Point’s Frontier AI Readiness Program, we continue to release Jumbo hotfixes with security fixes and hardening improvements for our…
Linux KVM/arm64 Vulnerability Lets Attackers Escape Virtual Machines and Gain Host Access
A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-89775, could let attackers escape an ARM64 virtual machine and access the underlying…
Hackers Clone Legitimate Websites to Silently Trigger Chrome and Windows Zero-Day Exploits
Hackers are using convincing copies of trusted websites to turn an ordinary browser visit into a full Windows compromise. The campaign pairs targeted…
Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers
A Chinese threat actor has exploited the bug to exfiltrate sensitive information from nearly 1,000 ZyXEL switches.
Hackers Exploit Veeam Agent Vulnerability to Gain SYSTEM-Level Access on Windows
A newly discovered privilege escalation flaw in Veeam Agent for Microsoft Windows could allow attackers with local access to compromised endpoints to…
Meta’s Muse AI assistant has a zero-day that can turn it into a Mac backdoor
A simple terminal command can hijack Muse and use its extensive permissions to spy on Mac users and control their connected accounts.
Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)
A Chinese-speaking threat actor has exploited a vulnerability (CVE-2026-7273) in unpatched ZyXEL GS1900 Smart Managed Switches and has exfiltrated…
WordPress Patches ‘Click2Shell’ Vulnerability
The bug lets attackers automatically install and preview themes and could lead to remote code execution.
Chinese APT Clones Legitimate Websites to Deliver Chrome and Windows Zero-Day Exploits
A third Chinese threat actor has been linked to phishing campaigns that cloned trusted websites and chained Chrome and Windows zero-day exploits to deploy…
D-Link DIR-822A Router Vulnerability Scores CVSS 10.0 With Public PoC Available
D-Link has announced a critical stack-based buffer overflow vulnerability affecting the non-US DIR-822A router, identified as CVE-2026-86296. This…
Hackers Exploit WordPress CVE-2026-63030 and CVE-2026-60137 to Steal Government Data
A suspected Chinese-speaking threat actor has exploited the critical WordPress “wp2shell” vulnerability chain to compromise government and small-business…
Meta’s Muse AI Agent 0-Day Vulnerability Allows Attackers to Hijack the Tool and Inject Malware
A zero-day vulnerability in Meta’s Muse AI agent for macOS could allow malware already running under a user account to hijack the assistant, intercept…
