-
Red Hat has disclosed a privilege-escalation vulnerability in Red Hat Advanced Cluster Management for Kubernetes (ACM) that could allow a low-privileged user to gain full cluster-admin control of an affected hub cluster. This vulnerability is tracked a…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical command injection vulnerability in Progress LoadMaster, tracked as CVE-2026-8037, to its Known Exploited Vulnerabilities (KEV) catalog after confirming evidence of ac…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
GitHub has expanded its Dependabot malware alerts beyond npm, enabling the detection of malicious dependencies across various package ecosystems, including PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer. This rollout is supported by a ne…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
RovoBlast is a recently disclosed vulnerability affecting Atlassian’s Rovo AI assistant that allows attackers to expose sensitive enterprise data through a single malicious link. According to Varonis Threat Labs, the vulnerability exploits Rovo&#…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A supply chain compromise affecting multiple BdThemes WordPress plugins has allowed attackers to hijack administrator sessions, create unauthorized admin accounts, and deploy persistent web shells, without modifying the plugin source code or requiring …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researcher Drinor Selmanaj has disclosed a path traversal vulnerability (CVE-2026-20685) in Apple’s Private Cloud Compute (PCC) that allows a privileged network attacker to write attacker-controlled files as root during node boot. This f…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Metabase has reported a critical security incident involving a zero-day vulnerability that is actively being exploited. This vulnerability affects self-hosted deployments running version 1.58 and later. According to the company, an attacker exploited t…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researcher Gareth Heyes has revealed techniques for webmail attacks that exploit HTML and CSS, the technologies used to format emails, to manipulate user interfaces, leak authentication data, and in some cases, capture passwords. Webmail servi…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researcher has disclosed a technique involving Windows Hello for Business (WHFB) that could allow attackers with access to an active Windows user session to authenticate to Microsoft Entra ID services without needing the victim’s PIN, biometri…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Google has released Chrome version 151.0.7922.108/.109 for Windows and macOS, and version 151.0.7922.108 for Linux. This update delivers 41 security fixes across various components of the browser, including rendering, graphics, JavaScript, user interfa…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


