§Source · Cybersecurity News
Cybersecurity News
Every dispatch we have aggregated from Cybersecurity News.
All dispatches
Loading
§Source · Cybersecurity News
Every dispatch we have aggregated from Cybersecurity News.
All dispatchesCVE-2026-65643 in cPanel/WHM lets authenticated low-privilege users seize root-level control of hosting servers.
wp2shell critical chain saw 45 million exploit attempts, illustrating compressed vulnerability exploitation windows for popular WordPress sites.
Encrypted prompt injection in xAI's Grok enables zero-click theft of names, locations, subscription tiers and prompt history.
Iran-linked attackers forced a UK power plant offline for four days, disrupting energy infrastructure operations.
Critical Entra ID RCE patched; exploited reports prompted emergency guidance and wide Microsoft updates.
CVE-2026-24301 'CoSnitch' in Microsoft Copilot Personal allowed one-click exfiltration of connected-account data; patched Aug 18.
Phishing allowed attackers to bypass Microsoft 365 MFA, hijack a finance mailbox, and redirect vendor payments.
CVE-2026-43760 logic flaw in macOS Screen Sharing can be exploited to execute commands as root via file-copy helpers.
DGFiP breach exposed tax-related personal and corporate data for roughly 678,000 individuals after credential misuse.
Active exploitation of MLflow SSRF (CVE-2026-64849) leads to cloud credential and secret theft from ML deployments.
Research demonstrates DRAM scrambling manipulation that undermines protections around SMM, PSP, and CPU microcode memory zones.
Analysis shows autonomous AI agents can escape sandboxes and execute attacks without direct human operators, changing threat models.
Newsletter outlines multiple critical zero-days (Cisco, Windows), Outlook RCE, and high-profile vendor patches and incidents this week.
Apple issued high-confidence threat notifications urging selected users to enable Lockdown Mode due to mercenary spyware targeting.
Shell is investigating Cl0p's claim of exfiltrating 89GB of internal data amid an ongoing potential incident and extortion demand.
Maximum-severity RCE (CVE-2026-58231) in SAP Commerce Cloud is being actively probed and targeted shortly after patch release.
Get these articles delivered to your inbox.
Subscribe free