Cybersecurity
Cybersecurity collects analysis on vulnerabilities, exploits, patch management, ransomware, supply chain, AI security and threat intelligence. These articles help IT professionals, developers and security analysts follow operational threats, vendor updates and technical trends.

Chrome 152 Patches 327 Vulnerabilities, Including Sandbox-Escape RCE
Google released Chrome 152.0.7977.64/.65 on August 26, 2026, with a record 327 security fixes — 10 rated critical. CVE-2026-79282, a u…

Hugging Face Kubernetes AI Agent Intrusion
Qualys mapped the stages of an autonomous AI agent's multi-day intrusion against Hugging Face's Kubernetes environment on July 9, 2026…

CareCloud Breach Balloons to 3.7 Million Victims: A Lesson in Regulatory Reporting Gaps
The CareCloud breach has surged from 350,000 to 3.75 million victims in five months, exposing how healthcare regulatory reporting can…

Kaltura Unpatched: RCE and File Read in mwEmbed, No Fix for Five Months
CERT/CC disclosed two critical unpatched vulnerabilities in Kaltura's mwEmbed library enabling remote code execution and arbitrary fil…

Satanic Exposes 1,033 Stripe API Keys: The Vector Isn't an Infostealer
Threat actor Satanic released data from 669 Stripe vendors with live API keys. Analysis rules out infostealer infections and points to…

Mirage2FA: AiTM Phishing Kit Hits 3,500 Organizations, Bypasses MFA on Microsoft 365
The Mirage2FA phishing-as-a-service kit, operated by LinX Coders, has targeted over 3,500 organizations using Adversary-in-the-Middle…

Gitea CVE-2026-60004: Real-World Victim Reports CPU Spike and Dropper
A Russian sysadmin documented an attack on their self-hosted Gitea instance via CVE-2026-60004. Hosting provider HOSTKEY flagged susta…

First Car Head Unit Malware Discovered: Vehicles Recruited into Proxy Botnet
Kaspersky has identified the first malware with a dedicated infection chain for Android automotive head units. It exploits the privile…

Citrix NetScaler: CVE-2026-19490, Critical Authentication Bypass with CVSS 9.3
Citrix has released patches for CVE-2026-19490, a critical authentication bypass in NetScaler ADC/Gateway carrying a CVSS 9.3 score. T…

NSA and CISA Issue First Alert on AI-Driven Attacks Against Critical Siemens PLCs
Five U.S. federal agencies have released joint advisory AA26-231A confirming threat actors are using AI-generated scripts to target in…

Unisoc VoLTE Exploit Chain Opens Android Kernel via Modem — No Patch, No CVE
A two-stage exploit chain in Unisoc VoLTE modems lets an attacker with a rogue 4G network achieve full Android kernel access when the…

Lazarus Exploits Windows AFD.sys Zero-Day for SYSTEM: Third Time in Two Years
The North Korean group used CVE-2026-68820 for local privilege escalation to SYSTEM, deploying the FudModule 3.1 rootkit and Troy back…