Critical Palo Alto VPN bug now exploited by Qilin ransomware gang

Critical Palo Alto VPN Bug Exploited by Qilin Ransomware Gang, Puts Thousands at Risk A severe vulnerability in Palo Alto Networks’ GlobalProtect Virtual Private Network (VPN) software has been exploited by the notorious Qilin ransomware gang to breach victims’ networks. The flaw, known as CVE-2026-0257, was patched by Palo Alto on May 13, but it … Read more

US seizes over 1,000 websites in FIFA World Cup piracy crackdown

As the world’s eyes are fixed on the FIFA World Cup, a different kind of battle is unfolding behind the scenes. The US Justice Department has launched a massive crackdown on piracy, seizing over 1,000 websites and blocking nearly 2,000 domains used to stream World Cup matches without authorization. The operation, dubbed “Operation Offsides,” is … Read more

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

WordPress wp2shell Exploit Spreads Rampantly as Public Exploit Code Fuels Widespread Scanning A growing number of WordPress sites have fallen prey to the notorious wp2shell exploit, with a publicly available attack code amplifying the threat. The vulnerability, which stems from an out-of-date plugin and can be exploited using AI-driven scanning tools, has left many website … Read more

Microsoft shares manual fix for WSUS sync delays and timeouts

A major issue affecting Windows Server Update Services (WSUS) servers has prompted Microsoft to share manual mitigations for IT administrators. A known problem with WSUS synchronization is causing Windows Update scans to fail or time out, leaving organizations unable to deploy the latest security patches and updates. The affected platforms include both client-side (Windows 10, … Read more

Critical Palo Alto VPN bug now exploited by Qilin ransomware gang

A Critical Palo Alto VPN Bug is Being Exploited by Ransomware Gangs, Putting Thousands at Risk A critical vulnerability in Palo Alto Networks’ PAN-OS software has been exploited by the Qilin ransomware gang to breach corporate networks, putting thousands of organizations and their sensitive data at risk. The bug, known as CVE-2026-0257, was identified back … Read more

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

A Critical ServiceNow AI Platform Flaw Has Been Exploited for Unauthenticated Code Execution, Putting Thousands of Organizations at Risk A severe vulnerability has been discovered in the AI-powered platform provided by ServiceNow, a leading digital workflow company. The flaw allows attackers to execute arbitrary code on affected systems without needing authentication, which means even unauthorized … Read more

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

A new variant of ransomware, dubbed ENCFORGE, has been spotted targeting AI model files in Langflow, an open-source video editing platform used by content creators and businesses worldwide. This sophisticated malware leverages a remote code execution (RCE) vulnerability in Langflow to gain access to sensitive data, making it a significant threat to organizations that rely … Read more

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

A critical vulnerability in WordPress plugins is spreading rapidly across the web, with security researchers warning of a significant escalation in exploitation attempts. The issue, known as wp2shell, affects several popular plugins used by millions of websites, putting sensitive data at risk of exposure and exploitation. The root cause of this problem lies in a … Read more

OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability

A newly discovered vulnerability in OpenSSL, known as “HollowByte,” has left a significant number of servers and applications at risk of being crippled by a denial-of-service (DoS) attack. The bug, identified by Okta’s red team, allows an attacker to exhaust a server’s memory before any security handshake can take place. The vulnerability arises from the … Read more

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

A pair of previously unknown vulnerabilities in SonicWall’s SMA1000 secure remote access appliances has allowed hackers to compromise sensitive systems and deliver custom malware, with the issue remaining unpatched for weeks before a fix was released. Cybersecurity firm Volexity revealed that the flaws were exploited by a threat actor known as UTA0533, which used the … Read more