-
A recently disclosed privilege-related vulnerability in the Common UNIX Printing System (CUPS) on macOS could allow an unprivileged local user to create attacker-controlled files in arbitrary locations outside the protection of System Integrity Protect…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Adobe has released an urgent security update for Adobe Campaign Classic, addressing multiple critical vulnerabilities that could allow remote attackers to execute arbitrary code on vulnerable servers without authentication. The update is documented in …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A large-scale malware campaign targeting developers and AI users has been uncovered ,revealing how attackers are weaponizing fake AI tools and cloned GitHub repositories to distribute infostealers and exfiltrate sensitive data. The latest evolution sho…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Apache NiFi has issued security advisories for four vulnerabilities affecting its web API. These include an authorization bypass that could allow unauthorized deletion of Parameter Context assets, and a high-severity issue that results in excessive mem…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The published Part 2 of a two-part technical analysis exposing BINDCLOAK, a previously undocumented modular backdoor deployed against government entities in the Middle East by an East Asia-linked threat actor tracked as OctLurk. The disclosure follows …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Check Point has disclosed a high-severity authentication bypass vulnerability that could allow unauthenticated attackers to execute arbitrary commands on vulnerable Security Management Servers and Multi-Domain Security Management Servers (MDS). This vu…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
CVE-2026-58048 is a critical privilege-escalation vulnerability in the database management functionality of cPanel & WHM. This flaw allows an authenticated cPanel user to execute arbitrary database commands with full administrative privileges. cPan…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
ChocoShell is a PowerShell-based infostealer used in Microsoft’s newly disclosed “CaptiveCrunch” campaign to steal Microsoft 365 tokens, browser sessions, and Wi‑Fi credentials from travelers connecting to compromised hospitality networks worldwide. Th…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
NullReceiver is a lean, stealth-focused evolution of DPRK’s blockchain C2 tradecraft that hides a reusable attacker wallet behind ordinary-looking Ethereum transfers, while still exposing just enough bytes to resolve a live command server. Two trojaniz…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Telegram Messenger was temporarily removed from Apple’s App Store in several countries late Monday, preventing new users from downloading the messaging platform and blocking reinstalls for users who had previously deleted the app. This global d…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


