New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

A critical vulnerability in cPanel, a popular web hosting control panel, has been disclosed that allows an attacker with mail privileges to execute arbitrary code as root. The flaw affects thousands of websites worldwide and underscores the importance of robust security practices for managed hosting services. The vulnerability, tracked as CVE-2026-1234, was discovered by researchers … Read more

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

A Critical Zero-Day Vulnerability in Chrome’s V8 Engine Exploited in the Wild, Threatening Sandbox Security Google Chrome users are facing a new threat as hackers have begun exploiting a zero-day vulnerability in the browser’s V8 JavaScript engine. This exploit allows attackers to execute malicious code within the sandbox environment, potentially leading to full system compromise. … Read more

U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok

A massive wave of cyber espionage has been rocking US government agencies, with top security officials accusing Chinese AI firms of exploiting vulnerabilities in cutting-edge language models. At the heart of this scandal are four notorious AI tools: Claude, GPT, Gemini, and Grok – all capable of generating convincing text, manipulating public opinion, and carrying … Read more

Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets

Critical Flaw in Alby Hub Exposes Internet-Exposed Bitcoin Wallets to Takeover Risks A critical vulnerability has been discovered in Alby Hub, a software that connects bitcoin wallets exposed on the internet to the Alby custody platform. This flaw allows attackers to potentially take control of affected wallets, compromising sensitive data and funds. The issue affects … Read more

DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval

A Critical Flaw in AI-Harnessing Technology Exposes Organizations to Unsanctioned File Access Cybersecurity researchers have uncovered a severe vulnerability in DeepSeek, a cutting-edge artificial intelligence (AI) harnessing technology designed to enhance security defenses. The flaw enables malicious actors to bypass file sandbox restrictions, granting unauthorized access to sensitive data without the need for explicit approval. … Read more

SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

A critical vulnerability in SAP’s kernel has been patched, exposing thousands of businesses worldwide to unauthenticated remote code execution attacks. The flaw, rated CVSS 10.0 – the highest severity rating possible – allows malicious actors to bypass security controls and execute arbitrary code on compromised systems. The vulnerability affects a wide range of SAP products, … Read more

Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

A newly disclosed proof-of-concept (PoC) exploit for Microsoft Defender has sparked concerns about the security of millions of users. The vulnerability, discovered by a researcher and showcased in a PoC exploit code, reveals that even with the latest ShieldBreak patch installed, attackers can still bypass security measures. The issue at hand revolves around Microsoft Defender’s … Read more

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

A Critical Vulnerability in F5 BIG-IP APM Puts Enterprise Networks at Risk of Compromise In a worrying turn of events, cybersecurity researchers have uncovered a sophisticated malware attack targeting F5 BIG-IP Application Delivery Controller (ADC) systems. The exploit injects a PHP web shell into the device’s memory, effectively evading traditional disk scan-based detection methods. As … Read more

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Chrome V8 Zero-Day Exploited in the Wild, Threatens Sandbox Security A devastating zero-day exploit has been uncovered in the wild, targeting Google Chrome’s V8 JavaScript engine. The vulnerability, which enables code execution inside a sandbox environment, poses a significant threat to users who rely on the browser for secure browsing. The attack path is particularly … Read more