Most recent articles by:

Deep Shah

Deep is the Co-founder at Codezeros Technology. His strong business acumen and industry knowledge in the Blockchain industry make him one of the strongest pillars at Codezeros. He comes with a rich technological and business understanding to lead. His deep understanding of Blockchain technology integration is a key component of our success at Codezeros. He also contributes to the overall vision of the company's growth and development.

ShinyHunters renew Oracle PeopleSoft attacks via WAF bypass

Google warns of renewed mass exploitation of CVE-2026-35273 in Oracle PeopleSoft by ShinyHunters-linked group UNC6240Attackers bypass WAF rules using URL-encoded paths, deploying web shells...

Bitget hacked: $351.6M stolen by North Korea

Bitget lost $351.6 million from hot and warm wallets on September 24, 2026, in an attack attributed to North Korean hackers.The exchange confirmed cold...

Placeholder domain third-party.com now serves ClickFix malware

The long-trusted documentation placeholder domain "third-partycom" has been weaponized to serve a ClickFix malware lure to Windows users.Unlike "examplecom," the domain was not IANA-reserved...

Critical WordPress RCE bug actively exploited within hours

Threat actors are actively exploiting a critical WordPress vulnerability, CVE-2026-87902, just hours after its public disclosure.The unauthenticated remote code execution (RCE) flaw carries a...

MikroTik SSH flaws chained for full router takeover

A chain of two SSH vulnerabilities—CVE-2026-67279 and CVE-2026-86060—allows unauthenticated attackers to gain full administrative control over exposed MikroTik RouterOS devices.Active exploitation began before patches...

MemTensor npm, PyPI packages push credential-stealing malware

Compromised MemTensor packages on npm and PyPI delivered the Go-based sckit implant across Windows, Linux, and macOS.Attackers stole publish tokens from MemTensor’s GitHub Actions...

Next.js Critical Flaw in ImageResponse Allows Server RCE

A critical vulnerability (CVE-2026-94545, CVSS 9.5) in Next.js versions 16.2.0 through 16.3.5 allows remote code execution via the ImageResponse feature when running on the...

Critical AI Gateway Bug Allows Unauthenticated RCE

A critical unauthenticated remote code execution vulnerability (CVE-2026-90898, CVSS 9.8) affects all versions of the open-source AI gateway Bifrost before 2.1.0.A second flaw (CVE-2026-86242,...

Must read