Max severity Adobe ColdFusion flaw now exploited in attacks

A Critical Adobe ColdFusion Flaw is Being Exploited by Attackers, Urgent Action Required A maximum-severity vulnerability in Adobe’s ColdFusion platform has been actively exploited by attackers just hours after being publicly disclosed. The flaw, tracked as CVE-2026-48282, affects multiple versions of the platform and allows malicious actors to gain remote code execution on unpatched systems … Read more

Software Is Now Written at the Speed of Thought. Security Isn’t.

Software Creation Speeds Up, But Security Lags Behind A revolution is underway in software development. Generative artificial intelligence and Vibe Coding are making it possible for developers to create applications at an unprecedented pace – almost as fast as they think them up. However, this accelerated creation process has left a gaping hole in security: … Read more

Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure

Threat actors are already probing a critical flaw in Gitea, an open-source platform for managing Git repositories, just 13 days after its disclosure. The vulnerability, identified as CVE-2026-20896, affects Docker containers and allows attackers to escalate privileges on compromised systems. Gitea is used by thousands of organizations worldwide to host and manage their software development … Read more

Max severity Adobe ColdFusion flaw now exploited in attacks

A critical vulnerability in Adobe ColdFusion, a popular web application development platform, is being actively exploited by attackers just two days after Adobe released patches to address the issue. The vulnerability, tracked as CVE-2026-48282, affects multiple versions of ColdFusion and allows hackers to gain remote code execution on unpatched systems without requiring any user interaction. … Read more

Software Is Now Written at the Speed of Thought. Security Isn’t.

As Software Creation Approaches the Speed of Thought, Security Lags Behind The latest innovation in software development has revolutionized the way applications are created. Generative artificial intelligence (AI) and Vibe Coding have made it possible for anyone, anywhere to build functional solutions at an unprecedented pace. However, this rapid progress has raised a pressing concern: … Read more

Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT

CyberNews.work Exclusive: China-Nexus Hackers Utilize Fake Tax Filing Utility to Deploy DcRAT Malware A sophisticated hacking operation, suspected to be linked to Chinese actors, has been uncovered using a fake Indian tax filing utility as a vector to deploy the highly potent DcRAT malware. The malicious software, which can evade detection by traditional security systems … Read more

How to Evaluate an AI SOC Platform in 2026: 6 Capabilities That Separate Leaders from Bolt-On AI solutions

As AI-powered threat detection and mitigation solutions become increasingly prevalent, organizations are facing a daunting challenge: evaluating the effectiveness of these advanced security platforms. A recent report highlights six key capabilities that set leaders apart from mere “bolt-on” AI solutions, but what does this mean for the average company struggling to stay ahead of evolving … Read more

⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More

A new threat is emerging on the cybersecurity landscape, one that leverages artificial intelligence (AI) models to discover previously unknown software vulnerabilities. These vulnerabilities can be exploited by attackers to gain unauthorized access to systems and data, making them a major concern for organizations worldwide. The AI-powered vulnerability discovery process typically involves training machine learning … Read more

Proof-of-Concept Exploit Released for Linux ‘Bad Epoll’ Root Access Vulnerability

A critical vulnerability in Linux’s Epoll feature has been made public, allowing attackers to gain root access on vulnerable systems. The “Bad Epoll” flaw, discovered by Jaeyoung Chung of Seoul National University’s Computer Security Lab, can be exploited using a proof-of-concept (PoC) code released by the researcher. The vulnerability affects Linux distributions based on kernel … Read more

North Korean Hackers Target Open Source Developers in Supply Chain Attacks

North Korean Hackers Target Open Source Developers in Supply Chain Attacks A sophisticated campaign by North Korean hackers has been targeting open source software developers with a backdoor and an information stealer, compromising repositories on GitHub and other package registries to inject malicious code into popular projects. The operation, dubbed “PolinRider,” is part of a … Read more