Category: Vulnerabilities
Progress Tells ShareFile Storage Zone Controller Customers to Shut Down Servers Now
Progress Software has disabled cloud access to on-premises ShareFile Storage Zone Controllers and is urging customers to manually power down affected Windows…
Dutch Police Suspect Local Hackers Behind Odido Vishing Breach
Dutch National Police say they have found strong indications that Dutch-speaking hackers used a vishing call to Odido's customer service to trigger…
npm 12 Disables Install Scripts by Default to Cut Supply Chain Risk
GitHub has shipped npm 12 with install scripts turned off by default and has deprecated granular access tokens that could bypass two-factor…
Injective Labs npm SDK Backdoored to Steal Crypto Wallet Keys
Attackers compromised a contributor's GitHub account to publish a malicious version of the @injectivelabs/sdk-ts package, silently harvesting private keys and seed phrases…
Chrome 150 Patches 27 Vulnerabilities, Including Two Critical Flaws
Google's Chrome 150 update addresses 27 security vulnerabilities, with two critical use-after-free bugs in the Ozone and Views components leading the list.…
CISA Orders Federal Agencies to Patch Actively Exploited Langflow Auth Bypass
CISA has added a Langflow authorization bypass flaw to its KEV catalog and given federal civilian agencies until Friday to apply patches,…
Critical Gitea Auth Bypass Flaw Under Active Exploitation
A critical vulnerability in Gitea's Docker images allows attackers to impersonate any user with a single HTTP header. Exploitation began just 13…
Januscape: 16-Year-Old Linux KVM Flaw Enables VM Escape on Intel and AMD
A use-after-free bug in the Linux kernel's KVM shadow MMU lets an attacker with guest root access execute code on the host,…
Hidden Backdoor in Tenda Router Firmware Grants Admin Access
A hardcoded secondary authentication mechanism in multiple Tenda router firmware versions allows any attacker who knows the backdoor password to gain full…
BeyondTrust Patches Critical Auth Bypass Flaws in RS and PRA Software
BeyondTrust has disclosed two critical authentication bypass vulnerabilities in its Remote Support and Privileged Remote Access products, urging self-hosted customers to apply…
PoC Exploit Released for Linux ‘Bad Epoll’ Root Privilege Escalation Bug
A public proof-of-concept exploit now targets a race-condition use-after-free flaw in the Linux kernel's epoll subsystem, enabling unprivileged local attackers to gain…
Exploit Attempts Hit Gitea Docker Flaw CVE-2026-20896 Within Two Weeks of Patch
Threat actors are actively probing a critical Gitea Docker vulnerability that allows unauthenticated clients to gain elevated access by spoofing a trusted…