-
IBM has disclosed several security vulnerabilities in its WebSphere Application Server that put enterprise environments at risk of cross-site scripting (XSS) and path-traversal attacks. These vulnerabilities could allow attackers to compromise administ…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly disclosed high-severity vulnerability in PHP, tracked as CVE-2026-12184, poses a significant risk to web applications by allowing a remotely triggerable denial-of-service (DoS) condition. This vulnerability can cause entire PHP-FPM process pool…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A single RedLine Stealer command-and-control (C2) indicator has revealed a focused spear-phishing campaign targeting the South Korean maritime industry, exposing a cluster of attacker-owned domains and mail infrastructure used to distribute credential-…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Malicious AI agent skills can be packaged to steal credentials, exfiltrate source code, and install backdoors while still bypassing many current skill-auditing systems. The paper finds that static scanners are especially weak against payload-preserving…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A targeted campaign that delivers the Ousaban banking Trojan to users in Spain and Portugal using sophisticated server-side geofencing and multi-stage delivery. The adversary begins with a socially engineered phishing PDF that impersonates a corrupted …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
ModSecurity, a widely used open-source web application firewall (WAF), has multiple security vulnerabilities that allow attackers to bypass detection with specially crafted HTTP requests. These vulnerabilities, identified as CVE-2026-52761 and CVE-2026…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-46242 and dubbed “Bad Epoll,” exposes a critical race-condition use-after-free (UAF) flaw in the epoll subsystem that allows unprivileged users to escalate privileges to root across Linu…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
SSH attackers are increasingly abusing single non-interactive exec commands over SSH to bypass traditional honeypot analysis, effectively turning post-authentication activity into short, automated probes rather than interactive shell sessions that dece…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A new macOS stealer, tracked as Gaslight and attributed to North Korean operators, demonstrates a worrying evolution in malware design: deliberate prompt-injection to mislead AI-driven security tools. Gaslight arrives as a standalone Mach-O executable …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly disclosed set of vulnerabilities in the widely used FatFs file system library is raising significant concerns across the embedded systems ecosystem. Researchers are warning that specially crafted USB drives and SD card images can trigger memory…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


