loader image
GhostLock 15‑Year Flaw Lets Users Root Linux

The ghostlock 15-year flaw discovered by Nebula Security researchers affects numerous Linux distributions, posing a significant security risk. This longstanding vulnerability, known as CVE-2026-43499, permits any logged-in user to gain full root control on any unpatched machine. Remarkably, the flaw, which originated over a decade ago, has been included by default in nearly all mainstream […]

CISA Deploys Anthropic Mythos to Hunt Code Flaws

CISA deploys Anthropic Mythos AI to scan federal code repositories for vulnerabilities, aiming to detect flaws before hackers and foreign intelligence services can exploit them. According to informed sources, these efforts have already identified numerous vulnerabilities, though specifics about scope and severity remain undisclosed. Managed by CISA’s Attack Surface Evaluation team, this initiative uses the […]

Keyfactor Secures $1 Billion for AI, Post-Quantum

Keyfactor secures a $1 billion investment to enhance its cryptographic security solutions for AI and post-quantum environments. This significant financial boost positions the company to address the proliferation of “identity sprawl,” a growing concern as machine identities multiply uncontrollably, often surpassing human identities in organizations. With enterprises seeking more unified security strategies, Keyfactor is striving […]

Palencia Man Arrested in NoName057(16) Probe

Authorities have arrested a man in Palencia suspected of collaborating with pro-Russia hacking groups, including CARR, Z-Pentest, and NoName057(16). Investigators allege the Palencia man arrested assisted a Ukrainian hacker in fleeing to Russia. This arrest highlights the increasing scrutiny on cyber activists believed to have ties with geopolitical conflicts involving Russia and Ukraine. The man’s […]

Linux KVM Flaw Lets Guest Corrupt Host Kernel

A newly uncovered flaw, known as CVE-2026-53359 or “Januscape,” has exposed a critical vulnerability in the Linux Kernel-based Virtual Machine (KVM). This linux kvm flaw, unnoticed for 16 years, allows a malicious guest to corrupt host kernel memory by exploiting KVM’s x86 shadow memory management logic. Affecting both Intel and AMD systems, the issue lies […]

Ex-MEP Kouloglou Infected Twice by Pegasus

Ex-MEP Kouloglou was infected twice with Pegasus spyware while involved in examining its misuse within the European Parliament, according to researchers. Stelios Kouloglou, who participated in the committee probing commercial spyware abuses, experienced the breaches during his tenure. Security researchers have confirmed these infections, shedding light on the controversial application of Pegasus, developed by Israel’s […]

DHS Confirms Hackers Breached HSIN

The Department of Homeland Security confirmed hackers breached the Homeland Security Information Network (HSIN), a critical platform for information-sharing among federal, state, local, and private-sector entities. This cyberattack has triggered an investigation to assess the extent of the breach and its potential impact on sensitive data. HSIN plays a pivotal role in fostering collaboration across […]

EvilTokens Kit Fuels Complete Email Fraud

The Eviltokens kit represents a significant threat, revolutionizing the landscape of device-code phishing. This kit creates a ‘complete business email compromise (BEC) operations environment,’ according to a Talos researcher. Cybercriminals utilize this tool to exploit vulnerabilities, streamline attacks, and increase their potential reward. By focusing on device-code phishing, the kit takes advantage of a critical […]

Oracle E-Business Flaw Under Attack, 950 Exposed

A critical vulnerability in Oracle E-Business Suite, identified as CVE-2026-46817, is currently under active attack, with approximately 950 systems exposed. Defused Cyber researchers reported that this flaw, affecting Oracle Payments versions 12.2.3 through 12.2.15, allows attackers to take over systems without authentication via HTTP. Although Oracle addressed this issue in its latest Critical Patch Update, […]

CISA Adds SharePoint RCE to KEV After Exploits

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently added a new vulnerability affecting Microsoft SharePoint Server to its Known Exploited Vulnerabilities catalog. Identified as CVE-2026-45659, this high-severity flaw carries a CVSS score of 8.8. The issue allows remote code execution due to the deserialization of untrusted data, posing significant security risks for users. CISA […]

Adobe ColdFusion Flaws Allow Remote Code Execution

Adobe has issued a crucial security update to address significant vulnerabilities in ColdFusion 2025 and 2023. These Adobe ColdFusion flaws, rated Priority 1, pose a risk for arbitrary code execution and privilege escalation. Affected versions include ColdFusion 2025 Update 9 and earlier, and ColdFusion 2023 Update 20 and earlier. The company strongly advises users to […]

Microsoft Pulls Forward Post-Quantum to 2029

Microsoft pulls forward its post-quantum cryptography timeline, setting a new target for 2029. This acceleration stems from recent advancements in quantum computing, which pose a growing threat to traditional encryption methods. Microsoft Azure’s Chief Technology Officer, Mark Russinovich, emphasized that these developments have altered the risk landscape. The tech giant is underscoring the urgency to […]