Critical Gitea Flaw Under Active Exploitation, Researchers Warn

Cybersecurity researchers are sounding the alarm about a critical flaw in Gitea, an open-source platform used for hosting git repositories. Threat actors have been actively exploiting this vulnerability, which allows unauthorized access to internet-accessible instances of Gitea. The issue affects all versions of Gitea prior to 1.26.3, and is tracked as CVE-2026-20896 with a CVSS … Read more

Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks

Iran-Linked Hackers Wield Sophisticated Modular Framework in Targeted Cyberattacks A highly advanced Iranian hacking group has been using a cutting-edge, modular command-and-control (C&C) framework to infiltrate and compromise organizations in Israel. Dubbed Cavern Manticore by cybersecurity researchers at Check Point, this sophisticated threat actor focuses its attacks on government entities and IT providers, raising concerns … Read more

Critical Adobe ColdFusion Vulnerability Exploited in Attacks

A Critical Adobe ColdFusion Vulnerability Has Been Exploited in Attacks, Despite Being Recently Patched Threat actors have begun exploiting a critical vulnerability in Adobe’s ColdFusion platform, despite it being patched just two weeks ago. The flaw, tracked as CVE-2026-48282, is described as a path traversal that could lead to arbitrary code execution and has been … Read more

CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws

The US government’s cybersecurity agency is leveraging a powerful artificial intelligence model to scan federal software for vulnerabilities, a move that has significant implications for national security. According to a report by Reuters, the Cybersecurity and Infrastructure Security Agency (CISA) is using Anthropic’s Mythos AI model to proactively identify and patch security flaws in government … Read more

Critical Gitea Flaw Under Active Exploitation, Researchers Warn

A Critical Gitea Flaw is Being Actively Exploited, Putting Thousands of Instances at Risk Cybersecurity researchers have sounded the alarm about a critical vulnerability in Gitea, a popular open-source platform for managing git repositories. The flaw, tracked as CVE-2026-20896, allows attackers to bypass authentication and access internet-accessible Gitea instances by simply supplying a valid username … Read more

‘GitLost’ Flaw Leaks Private Data From GitHub’s Agentic Workflows

GitHub’s Agentic Workflows Exposed by ‘GitLost’ Flaw A critical vulnerability in GitHub’s Agentic Workflows has been discovered, allowing attackers to leak private data from organizations’ code repositories without compromising accounts or exploiting software vulnerabilities. Dubbed “GitLost” by the researchers at Noma Security who found it, this flaw highlights a fundamental security challenge of agentic AI … Read more

Dialogflow CX ‘Rogue Agent’ Flaw Enabled AI Chatbot Data Theft

A Critical Flaw in Google’s Dialogflow CX Exposed AI Chatbots to Data Theft Google has recently patched a critical vulnerability in its Dialogflow CX platform that would have allowed attackers to steal sensitive data from AI-powered chatbots and agents. The flaw, dubbed “Rogue Agent,” was discovered by Varonis researchers and reported to Google in November … Read more

Big Brand Jobs Scam Targets Marketing Pros’ Google Accounts

**Job Scam Phishing Campaign Targets Marketing Pros with Google Credentials Heist** A sophisticated phishing campaign is duping marketing professionals into handing over their sensitive Google credentials by posing as job recruiters for top brands. The scammers are using legitimate platforms and techniques to evade detection, making it essential for victims to be vigilant. The campaign, … Read more