§Source · Cybersecurity News
Cybersecurity News
Every dispatch we have aggregated from Cybersecurity News.
All dispatches
Loading
§Source · Cybersecurity News
Every dispatch we have aggregated from Cybersecurity News.
All dispatchesA stored XSS flaw in Open WebUI allows 1-click remote code execution when uploading a profile image. Patch status and mitigations required to protect AI workspaces.
Short halt on issuance due to a cross-signed root issue; service restored after hours with mitigations.
Three critical disclosures in Microsoft 365 Copilot and Copilot Chat were remediated; end-user action not required per advisories.
ScarCruft trojanized a gaming platform to deploy backdoors on Windows and Android. Review supply chain and application trust.
Critical unauthenticated RCE in Weaver E-cology is being actively abused in the wild. Organizations should patch affected builds and monitor for payloads.
Exim fixes address memory corruption, crash and data leakage risks across widely used mail servers.
Technical PoC publicly released for CVE-2026-41940; vast exploitation activity observed in wild, enabling pre-authentication access and server compromise.
April 2026 Windows 11 update breaks third-party backup software; assess vendor patches and rollback options to avoid data loss.
A maximum severity remote code execution flaw in the Gemini CLI and related GitHub Actions could allow attackers to run code on host systems. Apply patches immediately.
RCE in GitHub's internal git infra could allow full server compromise; authenticated access required.
Critical pre-auth SQL injection in LiteLLM openly exploited in the wild, exposing cloud credentials.
Two actively exploited SimpleHelp remote-support flaws pose direct access risks to networks.
New Windows RPC flaw PhantomRPC enables LPE with multiple exploitation paths; disclosed at Black Hat Asia 2026.
Legacy FTP exposure persists; organizations urged to decommission or secure gateways.
Unauthenticated command execution demonstrated; patch recommended and mitigations outlined.
Get these articles delivered to your inbox.
Subscribe free