Archive
All articles, newest first. Page 2.

MindsDB Exposed to 0-Day RCE: OpenBBtable Class Executes Python Code Without Validation
ZDI-26-707 (CVE-2026-92207, CVSS 8.8) enables remote code execution on MindsDB via Python injection in the OpenBBtable class. The vend…

CVE-2026-89026: Hard-Coded JWT Key Enables RCE on Issabel PBX
A hard-coded cryptographic key in the Issabel Framework allows unauthenticated remote code execution on PBX phone systems. The Shadows…

CrewAI Zero-Day RCE: Malicious Agents Execute Arbitrary Code via Repository
CVE-2026-92206 hits the CrewAI framework with a CVSS 8.8 score. Unsafe reflection in load_agent_from_repository enables remote code ex…

N0va Turns Phishing Into Invisible Enterprise Access
N0va targets organizations in North America and Europe by abusing legitimate OAuth flows to capture access tokens and establish persis…

A Quote in a Folder Name Opens Root on Mac: The Parallels Bug
CVE-2026-90894: The most widely used virtualization software on Mac runs a root daemon with a world-writable socket. The fix lands in…

Acronis Patches CVE-2026-87886: In-the-Wild Exploit in cPanel Plugin
Acronis has released urgent patches for CVE-2026-87886, a local privilege escalation vulnerability with a CVSS 7.8 score that is alrea…

TP-Link Tapo C200: Two Zero-Days Allow Video Feed Access for Adjacent Attackers
OPSWAT disclosed two zero-day vulnerabilities in the TP-Link Tapo C200 camera that break local authentication. An attacker with adjace…
Google Patches Actively Exploited Android Zero-Day on Pixel: 110 Flaws Fixed
Google released the September 2026 Pixel security bulletin addressing 110 vulnerabilities. CVE-2026-58704, a zero-day in the Cellular…

Active Exploits Target WooCommerce Wholesale Lead Capture Plugin: The Patch Gap
Threat actors are exploiting CVE-2026-27540 in the WordPress WooCommerce Wholesale Lead Capture plugin. A patch has existed since Febr…

Active WSO2 API Manager Exploit: JWT Bypass with Forged Admin Tokens
CVE-2026-5430, a critical vulnerability in the JWT component of WSO2 API Manager, is under active exploitation. Forged tokens with adm…

Google Workspace Attacks Now Start With OAuth, Not Email
The Google Workspace attack chain has shifted from email-first to OAuth-first. Stolen OAuth tokens survive password resets, never expi…

TED Backdoor Turns HAProxy Into a Spy: Load Balancers Are the New Blind Spot
Rapid7 researchers have uncovered TED, a Linux toolkit that compiles a persistent espionage backdoor directly into victims' HAProxy 2.…

Switzerland: Ukrainian Ransomware Developer Sentenced to 12 Years, 9 Months
A Zurich district court sentenced a 52-year-old Ukrainian developer to 12 years and 9 months in prison for creating the LockerGoga, Me…

CVE-2026-46300 Fragnesia: Linux Kernel Bug Exposed on GKE Since May
Fragnesia exploits a flaw in skb_try_coalesce() to corrupt the page cache and gain root. Disclosed May 13, with public PoC and patch i…

Ransomware Recovery in 24–48 Hours Remains Out of Reach: 4 Cases Out of 800+
Fenix24's State of Recoverability 2026, based on 500+ ransomware recoveries, shows only 0.5% of clients neared their 24–48 hour restor…

DPRK APT Infiltrates South Korean Firms via Backdoor Embedded in HAProxy Code
Rapid7 disclosed on September 3, 2026, a previously undocumented Linux toolkit—TED and curlRAT—used by North Korean APT groups for lon…

Zero-Day Time Compressed to Hours: The Patch-Exploit Model No Longer Holds
Claude Mythos has collapsed discovery-to-exploit timelines. For CISOs, the only option left is breaking the attack chain before a work…

China's Spy Chief Names Claude Mythos and GPT-5.5-Cyber as National Security Threats
Chen Yixin, head of China's Ministry of State Security, explicitly identified two U.S. commercial AI models as risks to critical infra…

Luciferus: The AI Service Killing Jailbreaks in Cybercrime
Sophos researchers have uncovered Luciferus, a subscription-based service sold on underground hacking forums that generates malware vi…

Iran's Chosen Brick Malware Targets Journalists and Dissidents on Windows
A joint advisory from the FBI, UK NCSC, and Dutch AIVD exposes Chosen Brick, a sophisticated malware that surveils dissidents, activis…

KREMLIN Banking Malware Bypasses Chrome and Edge Using Ethereum Smart Contracts
The Brazilian KREMLIN toolkit installs malicious extensions on Chrome and Edge by subverting Chromium's Secure Preferences integrity c…

Linux Kernel: usbnet Race Condition Enables Privilege Escalation via Physical USB
CVE-2025-22050 in the Linux kernel's usbnet driver allows a physically present attacker to escalate privileges. The race condition, fi…

Chrome Zero-Day Attack: APT31 Exploits Patch Gap, Google Patches in 48 Hours
China-linked UTA0560 and JungleBamboo targeted NGOs with a three-vulnerability zero-day chain across Chrome and Windows between August…

BambooToken: Malware Framework Uses MQTT for C2 on Windows and Linux
Black Lotus Labs has identified BambooToken, a malware framework active since 2023 that adopts the MQTT protocol for command and contr…