loader image
GitLab Issues Critical Patch for XSS, DoS Flaws

GitLab has issued a critical patch to address high-severity vulnerabilities impacting its self-managed instances. The update, available for both Community Edition (CE) and Enterprise Edition (EE), comprises versions 18.11.3, 18.10.6, and 18.9.7. These patches fix serious security flaws, including a cross-site scripting (XSS) vulnerability and an unauthenticated denial-of-service (DoS) flaw, which could potentially be exploited […]

OPNsense Flaw Enables Root RCE

The cybersecurity community is on high alert following the disclosure of critical security vulnerabilities within OPNsense firewalls. These vulnerabilities, identified as CVE-2026-44194 and CVE-2026-45158, allow attackers to execute remote code with root privileges. The OPNsense flaw enables root access, posing significant risks to these widely used open-source firewall systems. The exposure of full technical details […]

18-Year-Old NGINX Flaw Allows Unauthenticated RCE

An 18-year-old NGINX flaw has emerged as a significant cybersecurity threat. Depthfirst recently identified a critical vulnerability in both NGINX Plus and NGINX Open, which could have severe implications for server security. This flaw is a heap buffer overflow issue within the ngx_http_rewrite_module, tagged as CVE-2026-42945, with a CVSS v4 score of 9.2. Such a […]

Microsoft BitLocker Bypassed by YellowKey 0-Day

A newly surfaced security threat poses a significant risk to Microsoft users, as unpatched zero-day vulnerabilities allow the Microsoft BitLocker encryption to be bypassed. Dubbed “YellowKey,” this critical flaw grants attackers full access to locked system drives used in Windows 11, Server 2022, and Server 2025. Highlighted alongside is “GreenPlasma,” a vulnerability that exploits the […]

TrickMo Variant Hijacks Phones to Steal Wallets

A new TrickMo variant hijacks phones, posing a serious threat to Android users by targeting banking, wallet, and authenticator apps. Identified by analysts at ThreatFabric, this variant elevates the malware’s capabilities through improved stealth tactics. Once users install the deceptive malware via fake TikTok apps, it gains extensive control by exploiting accessibility permissions. TrickMo intercepts […]

M23-Held Rubaya Landslides Kill Hundreds

In the M23-held Rubaya landslides, which have occurred since early 2026, hundreds of lives have been lost along the Democratic Republic of Congo’s coltan-rich Rubaya mines. The mines, a crucial source for smartphone and e-vehicle components, operate under perilous conditions. Despite global attention, access remains restricted due to control by the Rwandan-backed M23 group. Bellingcat […]

EU Most Wanted Nabs Hungarian Child Abuser

The EU Most Wanted platform played a crucial role in the capture of a 37-year-old Hungarian man, convicted of child abuse, who was hiding in Spain. Officials arrested him on May 7 in Tenerife, just three days after his details appeared on the list. This platform, backed by Europol and the European Network of Fugitive […]

Canvas Faces Extortion Over 8,800 Schools

Canvas faces extortion threats from a group affiliated with The Com, which is demanding ransom from Instructure to prevent a widespread data breach. The attackers have reportedly accessed sensitive data from over 8,800 school systems, increasing pressure on Instructure as the extortion deadline approaches. If the company fails to comply, the data could be leaked, […]

Instagram Removes DM Encryption; Export Your Chats

Instagram removes DM encryption starting May 8, 2026, allowing Meta to access messages on its popular platform. This change affects users who previously opted for encrypted direct messages, fundamentally altering message privacy. While Meta claims low usage and complex maintenance as reasons, some observers note the decision aligns with the U.S. Take It Down Act’s […]

Android Zero-Click ADB Exploit Goes Public

A recently uncovered android zero-click adb exploit exposes a significant vulnerability within Android’s developer tools, allowing attackers to gain unauthorized access to mobile devices via Wi-Fi without user interaction. The flaw, identified as CVE-2026-0073, permits an astonishingly stealthy breach, bypassing authentication mechanisms crucial for device security. Eight hours ago, researchers released a proof of concept […]

JDownloader Site Breach Plants Python RAT

The jdownloader site breach has unleashed a sophisticated cyberattack compromising millions. In May 2026, cybercriminals infiltrated JDownloader’s website, replacing legitimate download links with malicious files embedded with a Python-based remote access trojan (RAT). For two days, unsuspecting users who downloaded the installer faced significant risk, opening backdoors into their systems. Despite no tampering with the […]

Phishing Campaign Hits 500+ Organizations

A sophisticated phishing campaign has targeted over 500 organizations across diverse sectors such as aviation, critical infrastructure, energy, logistics, public administration, and technology. This persistent cyber threat, which has unfolded over several years, highlights the growing complexities that businesses must navigate in maintaining cyber vigilance. Cybersecurity experts express concerns about the adaptive techniques employed in […]