Tag: update
-
CVE-2026-58048: cPanel Bug Enables Full Database Administrator Access
A critical cPanel flaw (CVE-2026-58048) lets authenticated users execute SQL as root. Users should update to fixed versions immediately. If you run a shared hosting box, this one’s worth reading before your morning coffee gets cold. cPanel just patched a flaw, tracked as CVE-2026-58048 (CVSS score of 9.4), that let an ordinary authenticated hosting customer,…
-
Critical Adobe Campaign Flaws Let Unauthenticated Attackers Execute Arbitrary Code
Adobe has released an urgent security update for Adobe Campaign Classic, addressing multiple critical vulnerabilities that could allow remote attackers to execute arbitrary code on vulnerable servers without authentication. The update is documented in bulletin APSB26-120, published on August 3, 2026, and carries Adobe’s highest Priority 111 rating. The company urges organizations that use affected…
-
The U.S. Cyber Strategy Has a Scaling Problem and AI Is Exposing It
AI can discover and weaponize software vulnerabilities faster than organizations can patch them, making exploit mitigation and runtime protection essential to cybersecurity. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/the-u-s-cyber-strategy-has-a-scaling-problem-and-ai-is-exposing-it/
-
CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild.The vulnerability, tracked as CVE-2026-18577 (CVSS score: 8.2), is a case of incomplete patching for CVE-2026-18556 (CVSS score: 8.2) that allows First seen…
-
cPanel Database Privilege Escalation Flaw Enables Full Administrative Access
CVE-2026-58048 is a critical privilege-escalation vulnerability in the database management functionality of cPanel & WHM. This flaw allows an authenticated cPanel user to execute arbitrary database commands with full administrative privileges. cPanel Database Privilege Escalation Flaw All supported versions of cPanel & WHM before the recently released security updates are affected. As WebPros states, an…
-
ChocoShell Steals Microsoft 365 Tokens and Browser Sessions From Travelers
ChocoShell is a PowerShell-based infostealer used in Microsoft’s newly disclosed “CaptiveCrunch” campaign to steal Microsoft 365 tokens, browser sessions, and Wi”‘Fi credentials from travelers connecting to compromised hospitality networks worldwide. The operation, dubbed “CaptiveCrunch,” poisons DNS and HTTP flows on guest networks so that travelers attempting to reach legitimate Microsoft 365 or update endpoints are…
-
Thermo Fisher DNA Analysis Software Flaw Lets Attackers Secretly Alter Test Data
Thermo Fisher Scientific has released security updates for a high-severity flaw in its Applied Biosystems Human Identification (HID) software. This vulnerability could allow nearly undetectable manipulation of DNA test data files before analysis. The issue, tracked as CVE-2026-17583, carries a CVSS v4 score of 8.2 and affects .fsa and .hid file outputs used in forensic…
-
Attackers Exploit N-able Patch Bypass Flaw on RMM Servers
Over the weekend, the vendor discovered another vector of authentication bypass CVE-2026-18577 that gives attackers administrator access. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/attackers-exploit-n-able-patch-bypass-flaw
-
Google Tests Twice-Weekly Chrome Security Updates as AI Finds More Vulnerabilities
Google is testing twice-weekly Chrome security updates as AI tools uncover more vulnerabilities and the company works to shrink the browser’s patch gap. The post Google Tests Twice-Weekly Chrome Security Updates as AI Finds More Vulnerabilities appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-google-chrome-twice-weekly-security-updates/
-
COLDCARD Seed Generation Flaw Linked to Nearly $89 Million Bitcoin Theft
Galaxy Research linked a suspected Bitcoin theft of 1,367.05 BTC to weak COLDCARD seeds. Coinkite says updates cannot repair seeds already generated on devices. First seen on hackread.com Jump to article: hackread.com/coldcard-seed-generation-flaw-bitcoin-theft/
-
N-Able Flaw Exposes MSPs to Worst Case Scenario
Remote Management and Monitoring Tools Widely Used by Managed Security Providers. Remote management and monitoring software developer N-Able published a second hotfix to patch a vulnerability in all versions of its N-central software being actively exploited by attackers. Many managed security providers use its software to remotely administer customers’ systems. First seen on govinfosecurity.com Jump…
-
Midnight Blizzard Targets Travelers via Captive Portals
Russian actor Storm-2945 hijacked hotel captive portals to push fake updates and steal tokens First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/captivecrunch-midnight-blizzard/
-
30 days with Claude Mythos Preview: How Tenable adapted our security program, and why yours is next
Tags: ai, api, attack, business, control, cybersecurity, data, data-breach, endpoint, exploit, flaw, injection, LLM, remote-code-execution, risk, service, threat, tool, update, vulnerabilityTenable spent 30 days running frontier AI models against our own code. It didn’t just find bugs, it proved they’re real, with reproducible exploits. That fundamentally changes code security from ranking potential code defects to a much higher signal focused on the findings that matter. Read on to learn how it reshaped our security team’s…
-
Critical N-able N-central Vulnerability Under Active Exploitation as Hotfix Lands
N-able has confirmed that a critical vulnerability in N-central, its flagship remote monitoring and management (RMM) platform, is being actively exploited in the wild, prompting an emergency hotfix and urgent calls for managed service providers (MSPs) to patch immediately. The flaw, disclosed by N-able on 12 August, affects all currently supported versions of N-central, including…
-
AI is now both the weapon and the target in cyberattacks
AI generates 2.5 signals for every human-triggered signal CrowdStrike has to assess. Meanwhile, attackers are using AI to weaponize vulnerabilities faster than companies can patch them. First seen on cyberscoop.com Jump to article: cyberscoop.com/crowdstrike-annual-threat-hunting-report-2026/
-
HackerOne Mandates ID Verification Before Bug Bounty Report Submissions
HackerOne has rolled out a significant policy change requiring all hackers to complete identity verification before submitting reports to Bug Bounty Programs (BBPs). The update, effective immediately, aims to strengthen platform integrity and meet regulatory compliance requirements for reward payments. Under the new policy, hackers must verify their identity before becoming eligible for any bounty…
-
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution.The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system.It has been described as a case of incorrect authorization that could result in…
-
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report.Researchers track the operation as CaptiveCrunch and attribute it to Storm-2945. It assesses Storm-2945 to be an operational sub-cluster of Midnight…
-
Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical
Google Chrome 151 patches 370 security flaws, including seven Critical vulnerabilities. Users on Windows, macOS, and Linux should update now. The post Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-google-chrome-151-370-vulnerabilities/
-
Google AI Supercharges Chrome Security, Fixing 1,072 Bugs
Google says AI found and helped fix 1,072 Chrome security bugs in two releases, dramatically accelerating vulnerability detection and patching Google’s Chrome Security team published a detailed account of how AI models have transformed their vulnerability management pipeline, and the headline figure is difficult to dismiss: in the last two Chrome releases alone, the team…
-
Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined
Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined.Both versions were released last month. In its latest patch for Chrome 151, released Wednesday, the tech giant resolved 370 flaws, out of…
-
Mindestens ein weiteres Opfer – Autonomer KI-Agent dringt in Hugging-Face-Systeme ein
First seen on security-insider.de Jump to article: www.security-insider.de/openai-verantwortung-ki-angriff-hugging-face-a-987ee29bad8f77ce0efbe12c4c975053/
-
Security regression testing and abuse case testing for technical teams
Security regression testing and abuse case testing for technical teams Security testing is often treated as a point-in-time activity. A team runs a penetration test, fixes the findings, and moves on. That approach helps, but it does not stop the same weakness from returning in the next release, refactor, dependency update, or feature change. For……
-
CVE-2026-20316 Zero-Day Actively Exploited, Cisco Releases Fix
Cisco has released security updates for an actively exploited zero-day vulnerability, CVE-2026-20316, affecting Cisco Secure FMC (Secure Firewall Management Center) software. The flaw, disclosed on July 29, 2026, allows a remote, unauthenticated attacker to log in to vulnerable systems using a built-in low-privilege account and access sensitive data. First seen on thecyberexpress.com Jump to article:…
-
ClickFix Campaign Uses EtherHiding to Hide Malware and Exposes DPRK Wallet Trail
ClickFix-style fake macOS updates are now being weaponized with EtherHiding-backed command”‘and”‘control and a DPRK-linked crypto laundering network, turning a routine search click into a full-stack theft operation spanning browser, endpoint, blockchain, and exchange infrastructure. Instead of traditional web C2, the implant resolves its live command”‘and”‘control endpoints from Ethereum smart contracts, a takedown”‘resistant pattern known as…
-
PHP Patches 3 Security Flaws Enabling SQL Injection, Memory Corruption and DoS Attacks
PHP maintainers have released security updates to address three vulnerabilities affecting the PostgreSQL, BCMath, and Phar extensions. These vulnerabilities could potentially lead to SQL injection attacks, out-of-bounds memory writes, and denial-of-service attacks in vulnerable applications. The issues impact several actively maintained PHP release branches and have been resolved in versions PHP 8.2.338.2, 8.3.338.3, 8.4.248.4, and…
-
Companies push AI, sysadmins keep it on a short leash
In 2024, sysadmins expected AI to automate patch management optimization, vulnerability prioritization, infrastructure monitoring, and incident response within two years. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/31/action1-sysadmins-ai-expectations-report/
-
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign.The defining aspect of the attack is that bogus macOS software…

