-
CVE-2026-58048 is a critical privilege-escalation vulnerability in the database management functionality of cPanel & WHM. This flaw allows an authenticated cPanel user to execute arbitrary database commands with full administrative privileges. cPan…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Thermo Fisher Scientific has released security updates for a high-severity flaw in its Applied Biosystems Human Identification (HID) software. This vulnerability could allow nearly undetectable manipulation of DNA test data files before analysis. The i…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Galaxy Research linked a suspected Bitcoin theft of 1,367.05 BTC to weak COLDCARD seeds. Coinkite says updates cannot repair seeds already generated on devices.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
TP-Link has announced a high-severity security vulnerability in its TL-WR940N v6 wireless router that could allow an unauthenticated remote attacker to execute arbitrary code and potentially take full control of the affected device. This vulnerability …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
N-able says attackers bypassed N-central authentication, reached managed client devices and installed Cloudflare tunnels that survived server access revocation.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
N-able has issued an urgent hotfix to address a critical authentication-bypass vulnerability in its N-central remote monitoring and management (RMM) platform, following confirmation of active exploitation. This vulnerability, tracked as CVE-2026-18577,…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A new Metasploit Framework module has been submitted for review, targeting the critical Ruby on Rails Active Storage vulnerability, tracked as CVE-2026-66066. This submission poses an increased risk to applications that utilize the Vips image-processin…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Arista Networks has issued a warning about attackers actively exploiting CVE-2026-16812, a critical unauthenticated OS command injection vulnerability in on-premises VeloCloud Orchestrator (VCO) deployments. This flaw carries a CVSS v3.1 and v4.0 sever…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Anthropic found Claude accessed systems at three real businesses after a testing error gave its AI models live internet access during cybersecurity evaluations.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A backdoored ARVE WordPress Plugin release could grant attackers administrator access with one token, but WordPress.org blocked automatic distribution to WordPress sites.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


