19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

A wave of malicious Chrome and Edge extensions has been discovered, exposing millions of users to the risk of wallet-stealing and crypto-draining attacks. The extensions, which have been downloaded over 30 million times, were found to contain code that exploits vulnerabilities in popular web applications, allowing hackers to drain cryptocurrency wallets and steal sensitive user … Read more

Over 8,300 Gitea servers vulnerable to code execution attacks

Over 8,300 Gitea servers remain vulnerable to code execution attacks, with nearly a third still unpatched against a critical security flaw that allows attackers to execute arbitrary shell commands with elevated privileges. This vulnerability, reported by Salesforce researcher Shai Rod and tracked as CVE-2026-60004, can be exploited even by unauthenticated visitors who register an account … Read more

AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?

As AI-powered tools accelerate vulnerability discovery, cybersecurity defenders are facing an unprecedented challenge. With thousands of new vulnerabilities being published each month, traditional methods of managing risk are struggling to keep up. The National Vulnerability Database (NVD), a critical resource for defenders, has been forced to introduce changes in response to the growing volume of … Read more

Key Reasons Why Identity Fabric Matters in 2026

As we enter the mid-point of 2026, a growing trend is emerging in the world of cybersecurity: identity exposure. A recent analysis of over 11 real-world cases has revealed that compromised identities are often the starting point for active attack paths, allowing hackers to move laterally within an organization’s network with ease. The concept of … Read more

19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

A fresh wave of malicious Chrome and Edge extensions has surfaced, putting millions of users’ sensitive financial information at risk. A total of 19 suspicious extensions, available for download from both the Google Chrome Web Store and Microsoft Edge Add-ons, have been found to contain wallet-stealing and crypto-draining code. These extensions, which claim to offer … Read more

Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

A devastating cPanel vulnerability has been discovered, allowing a single hosting customer to gain root access to an entire server. This critical flaw affects numerous web hosting providers worldwide, putting millions of websites and sensitive data at risk. The issue lies in a design oversight within cPanel’s permission system, which grants excessive privileges to users … Read more

China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

A disturbing discovery has come to light, revealing a critical security flaw in certain China-made ZBT routers. These devices, used by millions of internet users worldwide, have been found to ship with not one, but two embedded implants that grant unauthenticated attackers root access. This means that anyone, regardless of their technical expertise or intentions, … Read more

Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

A trio of critical vulnerabilities in ServiceNow, a leading IT service management platform, has left thousands of organizations vulnerable to unauthenticated attacks. The three flaws, each rated CVSS 10.0, allow attackers to execute code and manipulate SQL databases without needing credentials. This is a serious concern for companies that rely on ServiceNow to manage their … Read more