Cybersecurity
Cybersecurity collects analysis on vulnerabilities, exploits, patch management, ransomware, supply chain, AI security and threat intelligence. These articles help IT professionals, developers and security analysts follow operational threats, vendor updates and technical trends.

Operation STANDOFF: 44 C2 Servers Mask Traffic With GitHub Redirects
VMRay Labs has mapped a Russian-speaking criminal campaign operating at least 44 command-and-control servers hosted on TimeWeb Ltd. (A…

CVE-2026-56163: Microsoft Mitigates Critical AKS Flaw Without Customer Action
Microsoft assigned CVE-2026-56163 a maximum CVSS 10.0 score for a critical elevation-of-privilege vulnerability in Azure Kubernetes Se…

Arista VeloCloud Zero-Day: The SD-WAN Controller That Cannot Hide
CVE-2026-16812 hits on-prem Arista VeloCloud Orchestrator with a CVSS 10.0. Active exploitation requires no credentials, and no config…

Hotel Wi-Fi DNS Attacks Steal Microsoft 365 Accounts, Bypass MFA
Threat actors compromise hotel and conference center Wi-Fi captive portals to manipulate DNS and steal Microsoft 365 credentials, sess…

Certighost: Ten Days After the Patch, the Exploit Is Public and the Domain Falls
The Certighost proof-of-concept for CVE-2026-54121 lets a standard domain user impersonate a Domain Controller via AD CS. Released exa…

Heimdall Data Database Proxy: RCE Vulnerability with Root Privileges Discovered
Trend Micro's Zero Day Initiative published advisory ZDI-26-447 covering CVE-2026-12357 (CVSS 7.2). The flaw in Heimdall Data Database…

Iran APT Sabotages US PLCs: CISA Warns of Physical Risk
The US government discloses an Iranian APT compromising internet-exposed PLCs in water and energy facilities, disabling safety logic t…

CISA Mandates Three-Day Patch for Splunk Zero-Day: New BOD 26-04 Ups the Ante
CVE-2026-20253 in Splunk Enterprise carries a CVSS 9.8 and pre-authentication RCE. CISA set a three-day deadline via the new Binding O…

From Zero to Shell: The wp2shell Chain Strikes WordPress Core in Seconds
The HackerHood group has reproduced the wp2shell exploit chain against WordPress 6.9.1 in a lab setting, achieving pre-authentication…

Delta Electronics DTM Soft Exposed to User-Interaction RCE via Project Files
The industrial configuration software DTM Soft contains a deserialization flaw in project files that enables remote code execution wit…

X.Org Server: Critical Glamor Font Bug Allows Root Privilege Escalation
CVE-2026-55999 in the Glamor Font component of X.Org Server and Xwayland lets any local user with an X connection escalate to root. Pa…

GitHub Actions Unwittingly Became an ISP for Criminals
Threat actors turned GitHub Actions runners into botnet nodes for large-scale cPanel/WHM scanning and exploitation. The campaign gener…