Cybersecurity
Cybersecurity collects analysis on vulnerabilities, exploits, patch management, ransomware, supply chain, AI security and threat intelligence. These articles help IT professionals, developers and security analysts follow operational threats, vendor updates and technical trends.

Weaponized OAuth: Government and Public Sector Targeted in Malicious Redirection Campaign
Microsoft researchers have identified active campaigns abusing OAuth redirection to steer government and public sector entities toward…

Critical Apache HTTP/2 Double-Free Flaw Enables RCE and Unauthenticated DoS
CVE-2026-23918 in Apache 2.4.66 allows for unauthenticated Denial-of-Service via a single TCP connection and potential RCE on Debian a…

Weaver E-cology 10.0 N-Day RCE: Unauthenticated Exploitation via Debug API (CVE-2026-22679)
CVE-2026-22679 enables unauthenticated RCE in Weaver E-cology 10.0 via the Dubbo debug endpoint. In-the-wild attacks began March 17, 2…

One Million AI Services Exposed Online: Massive Risks from Misconfigurations and Hardcoded Credentials
A security scan of over 2 million hosts has uncovered 1 million exposed AI services, many of which lack basic authentication or featur…

NVIDIA Confirms GeForce NOW Data Breach via Armenian Partner
NVIDIA has confirmed that a regional partner in the GeForce NOW Alliance suffered a breach exposing user personal data. While central…

cPanel Issues Critical Patches as Zero-Day Exploitation Targets WHM with Mirai and Ransomware
cPanel has released security updates for three new WHM vulnerabilities while confirming that a critical authentication bypass (CVE-202…

Trellix Confirms Source Code Breach as RansomHouse Claims Attack on Internal Infrastructure
Cybersecurity giant Trellix has confirmed unauthorized access to its source code repository following an extortion claim by RansomHous…

Zara Data Breach: 197,000 Emails Exposed via Compromised Anodot Tokens
Threat actor ShinyHunters has published a 140 GB Zara dataset allegedly obtained via compromised Anodot authentication tokens. Have I…

TCLBanker Weaponizes WhatsApp and Outlook to Target 59 Financial Platforms
TCLBanker targets 59 financial institutions—spanning banks, fintech, and crypto—using autonomous worm modules to propagate through Wha…

ShinyHunters Defaces Canvas LMS, Threatening Leak of 275 Million Records
The ShinyHunters group hijacked the Canvas login page on May 7, 2026, threatening to leak data from 275 million users and causing wide…

Ivanti EPMM Zero-Days Under Attack: CISA Mandates Unprecedented 3-Day Patch Deadline
Two unauthenticated RCE zero-days in Ivanti Endpoint Manager Mobile (EPMM) have prompted CISA to issue a rare 72-hour remediation mand…

Critical Palo Alto Zero-Day Grants Root RCE; Patches Delayed Until May 13
CVE-2026-0300 enables unauthenticated root RCE on Palo Alto firewalls. While CISA has ordered federal agencies to apply mitigations wi…