// 1 ZERO-DAY · 1 EXPLOIT · 1 ADVISORY IN THE LAST 24H→
CYBERSECCRITICAL

Critical cPanel Vulnerability: Urgent Patch and Hosting Access Blocks

A critical cPanel authentication vulnerability forced providers to block access. Learn about the security risks and the importance of…

Apr 29, 2026views - 208

CYBERSEC

The Gentlemen Ransomware: Over 320 Victims and Botnet of 1,570+ Companies

The Gentlemen group becomes the second most active ransomware of 2026. Over 320 victims and a ready botnet: here is the model attracti…

Apr 29, 2026views - 239

CYBERSEC

Scattered Spider: 'Bouquet' Arrested in Helsinki Under US Charges

A 19-year-old dual US-Estonian citizen known as 'Bouquet' has been arrested in Helsinki on US charges related to the Scattered Spider…

Apr 29, 2026views - 236

CYBERSECCVE

CVE-2026-3854: Critical RCE Vulnerability on GitHub Discovered by AI

CVE-2026-3854 puts GitHub Enterprise Server at risk. Discovered via AI, it allowed RCE. Technical details and patch discrepancies insi…

Apr 28, 2026views - 254

CYBERSECCVE

CVE-2026-25874: Unpatched Critical RCE Found in Hugging Face LeRobot

A critical CVSS 9.3 flaw hits Hugging Face's LeRobot. Learn about the RCE risks and the month-long patch delay following initial discl…

Apr 28, 2026views - 281

CYBERSEC

Paragon Spyware: A Year of Silence on the Italian Investigation

Paragon Solutions has not responded to the Italian judiciary on Graphite spyware used against journalists. Here is why the case remain…

Apr 28, 2026views - 264

CYBERSEC

Entra ID Vulnerability: Patch for Agent ID Privilege Escalation

Microsoft fixed a vulnerability in Entra ID's Agent ID Administrator role. The bug allowed high-privilege service principal takeover.…

Apr 28, 2026views - 264

CYBERSEC

Chinese Hacker Extradited to the US: The Xu Zewei Case

Xu Zewei, an alleged Hafnium member arrested in Milan, was extradited to the US. Accused of stealing COVID research, the case sparks a…

Apr 27, 2026views - 180

CYBERSEC

GlassWorm v2: 73 Fake VS Code Extensions Discovered on Open VSX

A cluster of 73 malicious extensions linked to GlassWorm v2 discovered on Open VSX. Attackers use sleeper packages to evade security c…

Apr 27, 2026views - 221

CYBERSEC

IRSF Fraud via Fake CAPTCHAs: Analysis of the Campaign Active Since 2020

Over 120 campaigns use Keitaro TDS to distribute IRSF scams via fake CAPTCHAs. 17 countries hit, costs up to $30 per victim. Here are…

Apr 27, 2026views - 226

CYBERSECEXPLOIT

April 2026 CISA KEV: 12 Vulnerabilities in a Week, Ransomware Alert

CISA added 12 exploited vulnerabilities to the KEV catalog from April 20-24, 2026. SimpleHelp, D-Link, and Samsung are among the affec…

Apr 25, 2026views - 286

CYBERSECCRITICAL

Pack2TheRoot: Critical Linux Passwordless Root Vulnerability

Pack2TheRoot (CVE-2026-41651) affects Linux PackageKit for 12 years. CVSS 8.8, local passwordless root access. Patches available: here…

Apr 24, 2026views - 237