Cybersecurity
Curated coverage and analysis in this editorial area.

Kaltura Unpatched: RCE and File Read in mwEmbed, No Fix for Five Months
CERT/CC disclosed two critical unpatched vulnerabilities in Kaltura's mwEmbed library enabling remote code execution and arbitrary fil…

Satanic Exposes 1,033 Stripe API Keys: The Vector Isn't an Infostealer
Threat actor Satanic released data from 669 Stripe vendors with live API keys. Analysis rules out infostealer infections and points to…

First Car Head Unit Malware Discovered: Vehicles Recruited into Proxy Botnet
Kaspersky has identified the first malware with a dedicated infection chain for Android automotive head units. It exploits the privile…

Citrix NetScaler: CVE-2026-19490, Critical Authentication Bypass with CVSS 9.3
Citrix has released patches for CVE-2026-19490, a critical authentication bypass in NetScaler ADC/Gateway carrying a CVSS 9.3 score. T…

NSA and CISA Issue First Alert on AI-Driven Attacks Against Critical Siemens PLCs
Five U.S. federal agencies have released joint advisory AA26-231A confirming threat actors are using AI-generated scripts to target in…

Unisoc VoLTE Exploit Chain Opens Android Kernel via Modem — No Patch, No CVE
A two-stage exploit chain in Unisoc VoLTE modems lets an attacker with a rogue 4G network achieve full Android kernel access when the…

Lazarus Exploits Windows AFD.sys Zero-Day for SYSTEM: Third Time in Two Years
The North Korean group used CVE-2026-68820 for local privilege escalation to SYSTEM, deploying the FudModule 3.1 rootkit and Troy back…

French Cyber-Spies Used GitHub Code to Hack EncroChat
A reverse-engineering report reveals French malware targeting EncroChat was copied from GitHub. Thousands of convictions across Europe…

CVE-2026-32475: Elementor Pro ≤4.2.1 Exposed to Unauthenticated RCE
A critical CVSS 9.0 vulnerability in Elementor Pro allows unauthenticated PHP file upload. The fix sat ready for 34 days before releas…

Fabric.js JSON Parsing Turns Attack Vector: SSRF Bug Discovered
CVE-2026-19504 in Fabric.js' loadFromJSON method enables SSRF attacks for sensitive data disclosure. The fix requires implementing a U…

BlueZ: A2DP Buffer Overflow Enables Root RCE After Pairing
ZDI-26-589 discloses a stack-based buffer overflow in the BlueZ Bluetooth stack's A2DP module, allowing remote code execution as root…

CVE-2026-65775: Microsoft Patches win32kfull UAF Discovered at Pwn2Own
Microsoft fixed CVE-2026-65775, a Use-After-Free in the Windows win32kfull driver discovered by Kentaro Kawane at Pwn2Own. The flaw en…