A critical authentication bypass vulnerability, CVE-2026-41940, affecting cPanel, WHM, and WP Squared is being actively exploited in the wild. Proof-of-concept exploit code has recently been made...
Google has fixed a critical vulnerability in its Gemini CLI npm package and GitHub Actions workflow that could enable arbitrary code execution by attackers.
A newly disclosed Linux local privilege escalation vulnerability, CVE-2026-31431, allows unprivileged users to gain root access by writing controlled bytes into system file caches.
The VECT 2.0 ransomware contains a critical flaw that results in the permanent destruction of large files rather than their encryption, according to recent security research.
The Brazilian cybercrime group LofyGang has resurfaced after three years with a new malware campaign targeting Minecraft users. The campaign employs LofyStealer malware disguised as a...
A severe command injection vulnerability in GitHub.com and GitHub Enterprise Server can allow remote code execution by an authenticated user with push access through a single...
Xu Zewei, alleged member of the Silk Typhoon group, was extradited from Italy to the U.S. for cyberattacks targeting American organizations during the COVID-19 pandemic.
Advancements in AI are rapidly reducing the exploit window organizations have to patch vulnerabilities, prompting a shift towards network detection and response strategies.
Security researchers identified 73 counterfeit Visual Studio Code extensions on the Open VSX repository linked to the GlassWorm information-stealing malware campaign.
The pro-Ukrainian hacktivist group PhantomCore has been actively exploiting multiple vulnerabilities in TrueConf video conferencing servers targeting Russian networks since September 2025.