At a glance Malware family Shai-Hulud variant (“Mini Shai-Hulud”) Threat actor Unattributed; linked to the Shai-Hulud lineage...
News
TL;DR HashiCorp patched three bugs in its Terraform MCP Server. The worst Terraform MCP Server flaw, CVE-2026-16498,...
TL;DR The Apache Software Foundation fixed 38 Apache Traffic Server vulnerabilities. The patches landed in versions 9.2.15...
TL;DR Researchers at Calif.io published full technical details and working proof-of-concept exploit code for CVE-2026-50343, tracked as...
TL;DR A new Linux kernel vulnerability, tracked as CVE-2026-53264, lets a local user run arbitrary code and...
TL;DR A researcher has published full details and a working proof-of-concept for a macOS privilege escalation bug....
At a glance Actor DPRK-linked group (Sapphire Sleet, Stardust Chollima, BlueNoroff, UNC1069) Activity NPM supply chain compromise...
TL;DR Gitea 1.27.1 patches a critical Gitea vulnerability, CVE-2026-59774, rated CVSS 9.8. An unauthenticated attacker can read...
At a glance Actor STAC4749 (unattributed threat cluster) Activity Teams vishing, remote access, ransomware Targets Dozens of...
At a glance Malware family Dysphoria (jackskid/fbot-derived IoT botnet) Threat actor Unattributed; run as a commercial DDoS-for-hire...
Google has announced that its agentic AI assistant, Gemini Spark, is now deeply integrated with the Chrome...
For years, the Apple ecosystem has proudly showcased its Handoff and Universal Clipboard features. These tools allow...
Google Chrome utilizes Google Search as its default search engine while embedding a prominent search box on...
TL;DR Veeam patched four flaws in Veeam Service Provider Console. Two are critical. One is an unauthenticated...
Generative AI technology has expanded rapidly. Consequently, deceptive images, fake news, and synthetic voices flood the internet....
TL;DR Adobe published a Priority 1 security update for Adobe Campaign Classic. The patch resolves seven severe...
TL;DR Four new Apache NiFi vulnerabilities affect installations running versions prior to 2.11.0. These flaws allow attackers...
TL;DR: cPanel patched a cPanel root SQL execution flaw tracked as CVE-2026-58048, rated CVSS 9.4. A second,...
TL;DR: Attackers are actively exploiting a N-central account takeover flaw tracked as CVE-2026-18577. N-able says an incomplete...
TL;DR: Check Point patched a Check Point authentication bypass affecting its Security Management and Multi-Domain Security Management...
TL;DR Researchers at LAVA found 36,872 exposed BMCs on the public internet. Most leaked password-derived hashes before...
TL;DR SICK InspectorP6xx machine-vision sensors have a critical remote-access flaw. Tracked as CVE-2026-11841, it scores a CVSS...