Hackers exploit critical auth bypass in Gitea Docker image

Critical Vulnerability Exploited in Gitea Docker Image, Leaving Thousands of Instances at Risk A severe security vulnerability in the official Docker image for Gitea, a popular self-hosted Git service alternative to GitHub and GitLab, has been actively exploited by hackers. The flaw, tracked as CVE-2026-20896, allows attackers to impersonate any user, including administrators, on affected … Read more

The Replicant in Your Directory: AI Agents and the Identity Security Gap

In the past few years, cybersecurity teams have been facing a growing challenge: non-human entities with access to sensitive data and systems. These “replicants” are AI agents, service accounts, OAuth applications, workload identities, and machine identities that already outnumber people in many enterprise environments. The issue isn’t new, but it’s gaining urgency as these entities … Read more

Money launderer accused of stealing seized crypto while in prison

A Shocking Case of Crypto Theft: Money Launderer Accused of Swiping Seized Funds from Prison In a stunning example of brazen audacity, a Bulgarian national has been charged with stealing over $290,000 in government-seized cryptocurrency while serving time in prison for his role in laundering millions stolen from American victims. Rossen G. Iossifov, 53, is … Read more

Hackers exploit critical auth bypass in Gitea Docker image

A critical security vulnerability has been actively exploited by hackers, allowing them to impersonate any user on a self-hosted Git service called Gitea. The issue affects deployments using the official Docker image and can be exploited even if authentication is enabled. With over 6,200 Gitea instances exposed on the public web, this flaw poses a … Read more

Progress urges ShareFile admins to shut down servers over “credible” threat

Progress Software has issued a warning to customers using its ShareFile enterprise secure file-sharing platform, urging them to immediately shut down their Storage Zone Controllers due to a “credible external security threat” targeting these on-premises servers. This move affects organizations that use a hybrid deployment model, where files are hosted locally within the company’s storage … Read more

New U-Boot flaws could enable stealthy firmware attacks

Critical Flaws in Widely Used Bootloader Could Enable Stealthy Firmware Attacks A recent discovery of six vulnerabilities in the U-Boot bootloader has raised concerns about the security of embedded Linux devices, enterprise servers, networking equipment, and IoT appliances. The flaws could allow attackers to execute malicious code during device boot, potentially compromising security protections and … Read more

Progress urges ShareFile admins to shut down servers over “credible” threat

Progress Software has urged administrators of its ShareFile secure file-sharing platform to immediately shut down their servers due to a “credible external security threat” targeting on-premises Storage Zone Controllers. The warning, sent via email to customers last night, is the latest example of a sophisticated cyberattack aimed at enterprise file transfer and sharing software. The … Read more

Police suspects Dutch hackers were involved in Odido breach

Dutch Police Suspect Local Hackers Behind Massive Odido Data Breach In a significant development in the ongoing investigation into the massive Odido data breach, Dutch police have revealed that they have found strong indications of involvement from local hackers. The breach, which was first disclosed by Odido on February 12, affected a staggering 6.2 million … Read more

New U-Boot flaws could enable stealthy firmware attacks

Widespread U-Boot Flaws Put Devices at Risk of Stealthy Firmware Attacks A recent security audit has uncovered six critical vulnerabilities in the widely used open-source bootloader, U-Boot. These flaws could allow attackers to execute malicious code during device boot, potentially enabling stealthy firmware attacks that compromise security protections and install persistent malware. U-Boot is a … Read more