19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

A fresh wave of malicious Chrome and Edge extensions has surfaced, putting millions of users’ sensitive financial information at risk. A total of 19 suspicious extensions, available for download from both the Google Chrome Web Store and Microsoft Edge Add-ons, have been found to contain wallet-stealing and crypto-draining code. These extensions, which claim to offer … Read more

Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

A devastating cPanel vulnerability has been discovered, allowing a single hosting customer to gain root access to an entire server. This critical flaw affects numerous web hosting providers worldwide, putting millions of websites and sensitive data at risk. The issue lies in a design oversight within cPanel’s permission system, which grants excessive privileges to users … Read more

China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

A disturbing discovery has come to light, revealing a critical security flaw in certain China-made ZBT routers. These devices, used by millions of internet users worldwide, have been found to ship with not one, but two embedded implants that grant unauthenticated attackers root access. This means that anyone, regardless of their technical expertise or intentions, … Read more

Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

A trio of critical vulnerabilities in ServiceNow, a leading IT service management platform, has left thousands of organizations vulnerable to unauthenticated attacks. The three flaws, each rated CVSS 10.0, allow attackers to execute code and manipulate SQL databases without needing credentials. This is a serious concern for companies that rely on ServiceNow to manage their … Read more

Key Reasons Why Identity Fabric Matters in 2026

As the threat landscape continues to evolve, a critical vulnerability has come to light, exposing millions of users worldwide to identity-based attacks. The concept of “Identity Fabric” – a complex web of interconnected identities across multiple domains and systems – has become a ticking time bomb, waiting to unleash devastating consequences. At its core, Identity … Read more

Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth

A Critical Vulnerability in Unitree G1 EDU Robots Allows Root Access and Bluetooth Hijacking, Exposing Users to Serious Risks Two critical flaws have been discovered in the Unitree G1 EDU humanoid robot, a popular educational platform used by students and educators worldwide. The vulnerabilities allow for root remote code execution (RCE) and can be exploited … Read more

APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations

A sophisticated backdoor, linked to a notorious Russian hacking group, has been detected targeting European government and diplomatic organizations. The malware, known as HOOKEDGE, is part of a larger campaign that exploits vulnerabilities in Microsoft Exchange servers to gain unauthorized access to sensitive systems. What’s alarming is the ease with which hackers can use compromised … Read more

PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions

A critical zero-day vulnerability in PaperCut, a widely used print management software, has been exploited by attackers to gain unauthorized access to sensitive systems. The exploit affects all versions of the Next Generation (NG) and Managed Folder (MF) editions of PaperCut, making it a significant concern for organizations that rely on these products. PaperCut is … Read more