Most recent articles by:

Deep Shah

Deep is the Co-founder at Codezeros Technology. His strong business acumen and industry knowledge in the Blockchain industry make him one of the strongest pillars at Codezeros. He comes with a rich technological and business understanding to lead. His deep understanding of Blockchain technology integration is a key component of our success at Codezeros. He also contributes to the overall vision of the company's growth and development.

ServiceNow AI flaw exploited in wild, patch now

Threat actors are actively exploiting CVE-2026-6875, a critical sandbox escape vulnerability in the ServiceNow AI Platform.The flaw, rated 9.5 on the CVSS scale, allows...

FakeGit campaign uses 800 fake AI tools to spread SmartLoader malware

Cybersecurity researchers uncovered nearly 7,600 malicious GitHub repositories in the FakeGit campaign, with over 800 posing as AI skills or MCP servers.The repositories deliver...

7-Zip XZ flaw enables remote code execution

A critical heap-based buffer overflow vulnerability, tracked as CVE-2026-14266, was discovered in 7-Zip's XZ archive handler.An attacker could achieve remote code execution by tricking...

Hugging Face Hacked by Autonomous AI Agent System

Open-source AI platform Hugging Face was hacked by an autonomous AI agent system that gained unauthorized access to internal datasets and credentials.The attack originated...

Critical Nginx Flat Allows Unauthenticated Remote Code Execution

F5 patched a critical nginx heap buffer overflow (CVE-2026-42533) rated 9.2 on CVSS v4, affecting versions since 2011.The flaw allows remote code execution if...

Sandworm Uses ClickFix Fake CAPTCHA to Target Ukraine

Russian state-sponsored hackers from the Sandworm group are using fake CAPTCHA checks to trick Ukrainian targets into executing malware.The campaign, attributed to sub-cluster UAC-0145,...

WordPress core hit by zero-click RCE bug, patch now live

WordPress patched a pre-authentication remote code execution flaw in versions 6.9.5 and 7.0.2 on July 17, 2026.The bug, found by Adam Kues of Searchlight...

ViteVenom: 7 Malicious npm Packages Target Vite Ecosystem

Researchers at Checkmarx uncovered the ViteVenom campaign, a software supply chain attack using seven malicious npm packages targeting the Vite frontend tooling ecosystem.The attack,...

Must read