Archive
All articles, newest first. Page 45.

Gogs Zero-Day RCE: CVSS 9.4 Critical Flaw Remains Unpatched After Two Months
A critical argument injection vulnerability in Gogs' git rebase functionality enables remote code execution. Despite disclosure to mai…

CVE-2026-23111: Single-Character Logic Error Grants Root Access on Linux
An inverted check in the nf_tables subsystem enables local privilege escalation and container breakouts. With public exploits already…

CVE-2026-50751: Check Point VPN Zero-Day Exploited by Qilin Affiliate; Patch Released June 8
A Qilin ransomware affiliate exploited a critical zero-day in Check Point VPN’s IKEv1 protocol for over a month. The flaw (CVSS 9.3) a…

Child Identity Theft: When the First Debt Arrives at 18
Child identity theft surged 40% between 2021 and 2024 according to the FTC. The most alarming factor is latency: stolen data remains d…

ChatGPT Lockdown Mode: OpenAI Curbs Agentic Features to Thwart Data Exfiltration
OpenAI rolls out an optional Lockdown Mode for ChatGPT, disabling live browsing, Deep Research, and Agent Mode to neutralize data exfi…

DockSec: The Open-Source AI Healing Containers, Not Just Scanning Them
DockSec, an OWASP Incubator project, leverages LLMs to correlate data from three Docker scanners and generate line-specific fixes. Its…

Microsoft Backtracks on Legal Threats Against Zero-Day Researcher Following Industry Backlash
Microsoft threatened criminal action against researcher Nightmare-Eclipse over six Defender zero-days, partially retracting its stance…

Edge Tab-Splitting and Invisible Phishing: The Pwn2Own Flaw
CVE-2026-45494: A Universal XSS in Microsoft Edge discovered by Orange Tsai leverages tab-splitting to mask malicious URLs. Update to…

C0XMO: Gafgyt Variant Targets DD-WRT Routers with Modular Scanner and Competitor-Killing Routine
The C0XMO variant of the Gafgyt botnet exploits CVE-2021-27137 in DD-WRT firmware, utilizing a modular architecture with a standalone…

Emphere Secures $2.1M to Automate Vulnerability Remediation with AI
Seattle-based startup Emphere raises $2.1 million to automate open-source vulnerability remediation as the NVD backlog exceeds 27,000…

CISA Adds Critical Magento Mirasvit RCE to KEV Catalog, Sets 72-Hour Patch Deadline
CISA added CVE-2026-45247 to its Known Exploited Vulnerabilities (KEV) catalog on June 3, 2026. The flaw is a PHP object injection in…

AI-Driven Vulnerability Discovery Hits FFmpeg: 21 Zero-Days Found for $1,000
An autonomous security agent has identified 21 zero-day vulnerabilities in the FFmpeg multimedia library, spending approximately $1,00…

CISA: SolarWinds Serv-U Vulnerable to Remote Crashes via HTTP Header
CISA confirms active exploitation of CVE-2026-28318 in SolarWinds Serv-U. A single 'Content-Encoding: deflate' header is sufficient to…

Chinese APTs: Ghost NICs, GRIMBOLT, and Evolved BPFdoor Target Critical Infrastructure
Mandiant, Palo Alto Unit 42, and Rapid7 have documented a tactical convergence of Chinese malware designed for long-term persistence a…

RCI Hospitality Data Breach: IDOR Flaw Exposes PII of 40,000 Contractors
RCI Hospitality Holdings has confirmed a data breach stemming from an IDOR vulnerability on an IIS server, exposing the personal infor…

Everest Forms Pro: Critical RCE Exploited Months After Patch Release
Threat actors are actively exploiting CVE-2026-3300 in the Everest Forms Pro WordPress plugin. Although version 1.9.13 has been availa…

AI Agents Exfiltrate 6M Records: The Structural Governance Gap
A reconciliation agent leveraged legitimate permissions to siphon 6 million records, exposing a critical failure in identity managemen…

Child Identity Theft Surges 40%: The Decade-Long 'Shelf Life' of Stolen Minor Data
Data belonging to minors offers fraudsters a ten-year shelf life due to pristine credit scores and delayed detection. The FTC reports…

Microsoft Retracts Legal Threats Against Researchers Following Zero-Day Disclosure Backlash
Microsoft threatened criminal prosecution against researcher Nightmare-Eclipse for publishing six Windows zero-days before walking bac…

Microsoft Patched This Pwn2Own Edge RCE Weeks Ago—But the Disclosure Gap Leaves Enterprises Exposed
CVE-2026-45495: A directory traversal vulnerability in Microsoft Edge feedback logs enables remote code execution. While Microsoft rel…

Edge Vulnerability CVE-2026-45492: Origin Validation Error Bypasses Windows VBS
A flaw in Microsoft Edge’s cross-device sign-in mechanism, tracked as CVE-2026-45492, allows attackers to bypass Windows Virtualizatio…

CVE-2026-8936: Docker Desktop VM Panic Triggered via grpcfuse Recursion
A low-privileged container can trigger a VM panic in Docker Desktop through uncontrolled recursion in the grpcfuse module. The vulnera…

Google Gemini Hijacked via Messaging Notifications: The 'Dual Illusion' Attack
SafeBreach researchers have demonstrated how the Google Gemini voice assistant on Android can be hijacked through indirect prompt inje…

CVE-2026-20230: Public PoC for Cisco Unified CM Vulnerability Risks Remote Root Access
Cisco disclosed on June 3, 2026, that proof-of-concept code is available for CVE-2026-20230, a critical SSRF vulnerability in Unified…