Panel fixed three flaws, including one that lets any logged-in cPanel account run code as root and another that can modify ...
Next.js ImageResponse flaw can lead to server code execution when attacker-controlled values reach generated SVG.
ShinyHunters claims it breached the FBI and stole employee data; the bureau says it is investigating activity affecting ...
Microsoft disrupted EvilTokens after it was linked to more than 12,000 compromised inboxes across over 10,000 organizations.
WordPress fixes a critical unauthenticated path traversal flaw that can load local PHP files and, on some servers, enable ...
XRanges for AI scores autonomous security agents on coverage, boundary violations, exploited flaws, and target integrity.
Anthropic and OpenAI report fewer boundary circumvention and unauthorized actions in safety tests of their latest AI models.
A Linux AF_UNIX use-after-free can escape containers for host root; exploit code targets Ubuntu 26.04, which remains unpatched.
UTA0565 exploited a Chrome-Windows zero-day chain through fake websites to deploy CLEANGULP malware against Asian government entities.
Unauthenticated attackers are exploiting CVE-2026-94127 in F5 BIG-IP APM to run code on systems acting as OAuth authorization servers.
Check Point fixed a Management Server flaw exploited in targeted July attacks that can run scripts without login.
BigDiskBuster can block Microsoft Defender updates by filling disk space, leaving detection content stale; no patch or advisory exists.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results