Snowflake ends service-account passwords. Now comes the hard part

A Wake-Up Call for Snowflake Customers: The Perils of Service-Account Passwords and What’s Next In a shocking case that exposed the vulnerabilities of service-account passwords, Connor Moucka and his co-conspirators used valid customer credentials to log in to over 165 Snowflake customer organizations, stealing billions of records, including the call and text records of nearly … Read more

Critical Avada WordPress theme flaw enables zero-click RCE

A critical vulnerability chain in the popular Avada theme for WordPress has been discovered, allowing an unauthenticated attacker to execute arbitrary PHP code on a server with ease. This exploit, tracked as CVE-2026-18431, received a 9.8 critical severity score and can be chained together from six separate security issues. The attack requires no interaction or … Read more

Hackers now exploit critical Gitea flaw in code injection attacks

A Critical Flaw in Gitea Leaves DevOps Platforms Vulnerable to Code Injection Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about an actively exploited critical-severity vulnerability in Gitea, a self-hosted Git service used by developers worldwide. Attackers are exploiting this flaw to inject malicious code into vulnerable servers, potentially allowing … Read more

Microsoft tests new privacy controls for Windows 11 desktop apps

Microsoft Tests New Privacy Controls for Windows 11 Desktop Apps, Giving Users Greater Transparency and Control Over App Permissions In a significant development that should interest anyone who uses their Windows 11 computer to access desktop applications, Microsoft has begun testing new privacy controls designed to let users choose which apps can access sensitive resources … Read more

Ubiquiti patches three max severity security vulnerabilities

Ubiquiti has released urgent security patches for three maximum-severity vulnerabilities that can be exploited remotely without requiring any privileges. These flaws could allow threat actors, including state-backed hacking groups and cybercriminals, to compromise Ubiquiti devices used in a wide range of applications, from video surveillance management platforms to VoIP phone systems. The first vulnerability, tracked … Read more

Snowflake ends service-account passwords. Now comes the hard part

A major cybersecurity wake-up call has been issued by Snowflake, one of the leading cloud-based data warehousing and analytics platforms, as it completes its three-phase authentication rollout, effectively ending password-based service-account logins. This move comes on the heels of a high-profile hacking case that exposed billions of records, including sensitive customer information from AT&T’s wireless … Read more

Critical Avada WordPress theme flaw enables zero-click RCE

A critical vulnerability chain has been discovered in the popular Avada theme for WordPress, allowing an attacker to execute arbitrary PHP code on a target server without even requiring valid login credentials. This zero-click Remote Code Execution (RCE) attack can be executed by chaining six security issues together, and its severity is rated 9.8 out … Read more

FBI disrupts proxy network enabling Chinese espionage operations

The FBI has dealt a significant blow to Chinese cyber espionage operations by disrupting a sophisticated proxy network used by threat actors linked to Beijing. The network, known as “quartermaster,” was designed to provide reconnaissance, proxy management, and operational routing capabilities for China’s intelligence agencies. At the heart of this operation is a group called … Read more

Hackers target Microsoft SharePoint RCE chain with PoC exploit

Hackers Exploit Chain of Microsoft SharePoint Vulnerabilities, Putting Thousands at Risk Cybersecurity experts are sounding the alarm as threat actors have begun chaining two previously disclosed vulnerabilities in Microsoft SharePoint to gain unauthorized access and execute arbitrary code on unpatched servers. The combination of flaws allows attackers to bypass authentication and perform remote code execution … Read more

New GPUThor attack defeats NVIDIA ECC protection for root access

A New Rowhammer Attack Exposes Vulnerability in NVIDIA’s GPU Security A team of researchers from the University of Toronto has uncovered a sophisticated new attack that can bypass even the most advanced security measures on NVIDIA graphics processing units (GPUs). Dubbed GPUThor, this rowhammer attack exploits vulnerabilities in ECC protection, granting attackers root-level access to … Read more