The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
A Cursor zero-day vulnerability lets a planted git.exe run automatically when a Windows developer opens a repository. Mindgard disclosed it after seven months …
A researcher found that anyone with physical access to one Shark robot vacuum can extract its AWS IoT certificate and use it to take over other Shark vacuums r…
WordPress 6.9.5 and 7.0.2 fix wp2shell, a core REST API bug chaining route confusion and SQL injection into unauthenticated remote code execution.wp2shell: Wor…
A heap-based buffer overflow in 7-Zip's XZ decoder, patched in version 26.02, let a crafted archive run code on extraction and had gone unnoticed for five year…
An AI-driven threat actor called JADEPUFFER built ransomware that hunts AI model files specifically, entering through a known Langflow RCE and pivoting via an …
A practical checklist for the Azure DevOps MCP flaw that lets hidden PR comments hijack AI coding agents, plus the configuration changes to make right now.Azur…
A three-line SVG gave XBOW SYSTEM access on Bing's servers through a default ImageMagick setting. Here's the exploit chain and a checklist for anyone running a…
A practical checklist for the Fastjson RCE vulnerability (CVE-2026-16723): how the exploit chain works, four questions to answer this week, and how to mitigate…
Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applica…
Two newly fixed storage bugs in Kubernetes showed more than just a problem with path traversal. They found a common security flaw in the cloud: powerful parts …
A Linux server can be fully patched, hardened, and compliant, yet still leave investigators unable to explain how an attacker got in. Without reliable Linux lo…
Most Linux teams don't struggle to find vulnerabilities anymore. They struggle to decide which ones deserve attention first. Between daily scanner results, ven…
Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, wh…
GNOME is officially shortening its standard vulnerability disclosure window from 90 days to 30 days, a change that impacts upstream maintainers, downstream Lin…
Google's DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5 Flash that's desi…
Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) …
Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) m…
A cloud tenant using nothing but ordinary GPU access can push a data center's power draw up and down fast enough to threaten the grid it runs on, with no explo…
For organizations that run a self-hosted Git platform, it’s no longer just about hosting static code repositories. Today, Git servers are responsible for deplo…
Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archi…
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted H…
ESET researchers identified 11 old and forgotten Linux UEFI shim bootloaders at versions 0.9 and below that can be used to bypass UEFI Secure Boot on any UEFI-…
Before the week gets away from you, take a look at what's landed across the Linux ecosystem. The volume of security advisories hasn't slowed, and while not eve…
Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published.The vulnerabilities are listed b…