-
Red Hat has disclosed a privilege-escalation vulnerability in Red Hat Advanced Cluster Management for Kubernetes (ACM) that could allow a low-privileged user to gain full cluster-admin control of an affected hub cluster. This vulnerability is tracked a…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical command injection vulnerability in Progress LoadMaster, tracked as CVE-2026-8037, to its Known Exploited Vulnerabilities (KEV) catalog after confirming evidence of ac…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
RovoBlast is a recently disclosed vulnerability affecting Atlassian’s Rovo AI assistant that allows attackers to expose sensitive enterprise data through a single malicious link. According to Varonis Threat Labs, the vulnerability exploits Rovo&#…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A supply chain compromise affecting multiple BdThemes WordPress plugins has allowed attackers to hijack administrator sessions, create unauthorized admin accounts, and deploy persistent web shells, without modifying the plugin source code or requiring …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researcher Drinor Selmanaj has disclosed a path traversal vulnerability (CVE-2026-20685) in Apple’s Private Cloud Compute (PCC) that allows a privileged network attacker to write attacker-controlled files as root during node boot. This f…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A malicious pull request has the potential to turn Claude Code’s project-scoped Model Context Protocol (MCP) configuration into a trigger for code execution, which could expose developer secrets before a reviewer has a chance to evaluate the code. Anth…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security research presented at Black Hat 2026 has identified 12 vulnerabilities across four enterprise Java platforms, including two critical pre-authentication remote code execution (RCE) chains affecting Bonita BPM and Apache OFBiz. Researchers Lidor…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Critical vulnerabilities in the open-source Paperclip AI-agent orchestration platform could allow attackers to execute commands remotely on exposed servers or on a developer’s local machine. These flaws arise from broken authorization boundaries across…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical vulnerability in Jenkins, tracked as CVE-2026-70426, may allow attackers to execute arbitrary code on Jenkins controllers by bypassing deserialization protections within the platform’s Remoting library. This flaw, identified as SECURITY-3911…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A proof-of-concept (PoC) has been released for a use-after-free vulnerability affecting the Linux kernel’s software bridge implementation found in `net/bridge`. This vulnerability occurs within the Spanning Tree Protocol (STP) timer lifecycle. It…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


