GitHub ‘Verified’ Commits Can Be Rewritten Into New Hashes Without Breaking Signatures

A Critical GitHub Security Flaw Exposes Verified Commits to Rewrite Attacks GitHub, one of the world’s most popular code repositories, has disclosed a security vulnerability that allows hackers to rewrite verified commits without breaking digital signatures. This flaw, discovered by researchers at the University of California, Berkeley, affects millions of developers worldwide who rely on … Read more

Ubiquiti warns of new max severity UniFi OS vulnerability

Ubiquiti Warns of New Critical Vulnerability Affecting UniFi OS Ubiquiti, a leading provider of networking and IoT solutions, has released security updates to patch seven critical vulnerabilities in its UniFi OS, including one with a maximum-severity rating that can be exploited in command injection attacks. The vulnerability, tracked as CVE-2026-50746, affects the UniFi Connect Application, … Read more

CISA orders feds to prioritize patching Langflow auth bypass flaw

Federal Agencies Ordered to Patch Critical Langflow Vulnerability Amid Ongoing Exploitation The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive for federal agencies to prioritize patching a recently discovered vulnerability in the Langflow visual framework, which is used to build AI agents. This order comes as threat actors are actively exploiting the … Read more

CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV

A major security alert has been issued by CISA, with four actively exploited vulnerabilities added to its Known Exploited Vulnerabilities (KEV) catalog. The affected software includes Adobe’s ColdFusion, Joomla’s content management system, and Langflow, a popular video editing plugin. These vulnerabilities have been identified as being used in real-world attacks, making them high-priority targets for … Read more

15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros

A Critical Linux Flaw Lurks Undetected, Exposed After 15 Years A long-dormant vulnerability in the Ghostscript library, used by most Linux distributions to convert PostScript and PDF files, has been discovered to allow attackers to gain root access on affected systems. The flaw, which has existed for over 15 years, was unearthed recently by researchers … Read more

China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware

The China-linked threat actor known as UAT-7810 has expanded its ORB network with the introduction of new malware, dubbed LONGLEASH. This latest development highlights the evolving tactics employed by sophisticated nation-state actors and underscores the importance of staying vigilant in today’s increasingly complex cybersecurity landscape. UAT-7810 is a well-documented threat actor linked to China, known … Read more

Keyfactor Scores $1 Billion+ Investment for AI, Post-Quantum Security

Keyfactor Secures $1 Billion+ Investment for AI-Powered Post-Quantum Security Solution In a major development that highlights the growing urgency around post-quantum readiness, Keyfactor has secured a staggering investment exceeding $1 billion to accelerate its global operations and advance product innovation. The company’s end-to-end platform, known as the Trust Control Plane, provides centralized visibility into cryptographic … Read more

Linux Kernel Vulnerability Allows VM Escape on Intel and AMD Systems

A newly disclosed Linux kernel vulnerability has left multi-tenant x86 public clouds vulnerable to a major security threat. Tracked as CVE-2026-53359, the flaw allows attackers to escape virtual machines (VMs) and execute code on the underlying host, posing a significant risk to cloud providers and their customers. The vulnerability, known as Januscape, affects the shadow … Read more

CISA orders feds to patch max severity ColdFusion flaw by Friday

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a stern warning to all federal government agencies in the United States: they must patch an extremely critical vulnerability in the Adobe ColdFusion web application development platform by this Friday. The flaw, identified as CVE-2026-48282, is being actively exploited by malicious actors, and CISA has … Read more

CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV

The US Cybersecurity and Infrastructure Security Agency (CISA) has added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, highlighting the continued threat posed by software weaknesses in widely used applications such as Adobe, Joomla, and Langflow. This move underscores the urgent need for organizations to prioritize vulnerability patching and risk mitigation. The … Read more