Most recent articles by:

Deep Shah

Deep is the Co-founder at Codezeros Technology. His strong business acumen and industry knowledge in the Blockchain industry make him one of the strongest pillars at Codezeros. He comes with a rich technological and business understanding to lead. His deep understanding of Blockchain technology integration is a key component of our success at Codezeros. He also contributes to the overall vision of the company's growth and development.

GitLab AI Gateway critical flaw enables remote code execution

GitLab disclosed a critical vulnerability, CVE-2026-90970, in its AI Gateway with a CVSS score of 9.9.The flaw could allow a logged-in user with Duo...

Android 17 Blocks Malware via Accessibility Service Lockdown

Google restricts Android’s accessibility services to verified apps when Advanced Protection is enabled, closing a major attack pathway.Malicious apps have abused the AccessibilityService API...

WordPress SC Malware: 8 Persistence Methods, Blockchain C2

Security researchers have uncovered a WordPress malware codenamed SC that uses the Ethereum blockchain for command-and-control communication, making removal extremely difficult.The backdoor is a...

OpenSSL DTLS bug leaks heap memory, crashes apps

OpenSSL's CVE-2026-84782 DTLS flaw can leak heap memory across a connection or crash programs.Fixes are public for OpenSSL 4.0.3, 3.6.5, 3.5.9, and 3.4.8; older...

New Spectre-v2 CPU Variant ‘BTR’ Hits JIT Engines

Academics disclosed a new Spectre-v2 CPU vulnerability variant, Branch Target Reuse (BTR), affecting JIT engines across multiple CPU vendors.The attack exploits the interplay between...

MCP Python SDK OAuth flaw lets attackers steal credentials

High-severity OAuth credential theft flaw found in MCP Python SDK versions 1.9.1–1.29.1 and 2.0.0–2.1.1.Attacker-controlled MCP server can trick client into sending client secret, authorization...

Storm-3168: AI-Orchestrated Azure Attacks Hit Service Principals

Microsoft's Storm-3168 used AI orchestration and compromised service principals to launch a destructive ransomware attack on Azure, demanding Bitcoin payment.The attack deleted storage accounts,...

ShinyHunters renew Oracle PeopleSoft attacks via WAF bypass

Google warns of renewed mass exploitation of CVE-2026-35273 in Oracle PeopleSoft by ShinyHunters-linked group UNC6240Attackers bypass WAF rules using URL-encoded paths, deploying web shells...

Must read