PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

A Critical Vulnerability in PostgreSQL Has Been Patched After 12 Years PostgreSQL, a popular open-source database management system, has just released patches for a long-standing vulnerability that allows attackers to execute malicious code on systems using its replication feature. The flaw, discovered in 2014 but not previously addressed, is particularly concerning due to the sensitive … Read more

Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

Millions of Email Users Targeted in Sophisticated Phishing Campaign Using Invisible Unicode A massive phishing campaign has been underway, sending out millions of emails that have managed to evade traditional spam filters. The attackers’ cunning trick? They’re using invisible Unicode characters to conceal their malicious links and attachments. At the heart of this operation is … Read more

Microsoft says some users can’t open the Teams desktop client

Microsoft’s Microsoft Teams desktop client has been plagued by a known issue that prevents some users from opening it on their Windows systems. The company acknowledged the problem on Thursday and advised affected customers to work around it by using the web or mobile platforms until a fix is released. The issue, tracked as TM1466820, … Read more

Critical Citrix NetScaler auth bypass now leveraged in attacks

Critical Citrix NetScaler Flaw Exploited in Real-World Attacks, Experts Warn Citrix’s NetScaler appliance has been compromised by attackers exploiting a critical vulnerability that allows unprivileged threat actors to bypass authentication remotely. This flaw, tracked as CVE-2026-19490, was first disclosed in mid-August and has now been confirmed to be exploited in the wild. The vulnerability affects … Read more

New Ted Backdoor Hides Inside Victims’ Own HAProxy Builds to Intercept Web Traffic

A devastating new backdoor, dubbed “Ted”, has been discovered lurking within HAProxy builds, potentially leaving thousands of organizations vulnerable to interception and data theft. This stealthy malware is embedded deep within a victim’s own infrastructure, making it a ticking time bomb waiting to unleash chaos on unsuspecting networks. HAProxy is an open-source load balancer used … Read more

PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

A 12-Year-Old Flaw in PostgreSQL Replication System Leaves Thousands Vulnerable to Remote Code Execution Thousands of organizations using PostgreSQL, a popular open-source relational database management system, have been left vulnerable to remote code execution attacks due to a 12-year-old flaw in its replication system. The vulnerability, identified as CVE-2023-4651, was patched by the PostgreSQL developers … Read more

Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

Cyber attackers have unleashed a sophisticated phishing campaign that exploits Unicode characters, sending millions of emails that evade even the most robust email filters. This insidious tactic has far-reaching implications for businesses and individuals alike, underscoring the need for heightened vigilance in today’s digital landscape. The attackers’ scheme leverages invisible Unicode characters to craft emails … Read more

Catch Raises $5 Million for AI Executive Assistant With Guardrails

Catch Raises $5 Million for AI Executive Assistant With Built-In Security Features A startup called Catch has secured $5 million in funding to further develop its artificial intelligence-powered executive assistant. This AI agent, also called Catch, is designed to perform tasks like scheduling meetings and booking travel, but with a key difference: it’s built with … Read more

Google warns of new Chrome zero-day flaw exploited in attacks

Google has issued an emergency update for its Chrome browser to address a critical security vulnerability that has been actively exploited by attackers. The issue, identified as CVE-2026-85046, is a type confusion bug in the V8 engine, which compiles and executes JavaScript code used by websites. This flaw allows hackers to corrupt memory and potentially … Read more