Most recent articles by:

Deep Shah

Deep is the Co-founder at Codezeros Technology. His strong business acumen and industry knowledge in the Blockchain industry make him one of the strongest pillars at Codezeros. He comes with a rich technological and business understanding to lead. His deep understanding of Blockchain technology integration is a key component of our success at Codezeros. He also contributes to the overall vision of the company's growth and development.

CISA Adds Critical Microsoft SharePoint Flaw CVE-2026-58644 to KEV Catalog

CISA added a critical Microsoft SharePoint Server vulnerability, CVE-2026-58644, to its Known Exploited Vulnerabilities catalog.The flaw allows unauthenticated remote code execution and has been...

n8n bug lets one token claim login into wrong user account

A critical identity-binding flaw in n8n's token exchange allowed account takeover when multiple external issuers were trusted.The vulnerability (CVE-2026-59208) matched JWTs on the sub...

Daxin malware resurfaces with Stupig backdoor in Taiwan attack

The Daxin kernel-mode rootkit, dormant for over four years, has resurfaced on a compromised host at a Taiwan-based manufacturing subsidiary alongside a new backdoor...

Zoom Patches Critical Account Takeover Flaw in Windows Clients

Zoom released a critical security update for a flaw (CVE-2026-53412, CVSS 9.8) that could allow unauthenticated account takeover via network access.Three additional high-severity vulnerabilities...

AI-Assisted TuxBot v3 IoT Botnet Found Riddled With Errors

Cybersecurity researchers at Palo Alto Networks Unit 42 discovered a new IoT botnet framework called TuxBot v3 Evolution that shows signs of being developed...

AsyncAPI npm packages compromised, deliver Miasma botnet loader

Four npm packages in the @asyncapi namespace were compromised, distributing a multi-stage botnet loader called Miasma.The attack exploited the project’s own GitHub Actions release...

Attackers exploit Microsoft Entra ID OAuth spoofing blind spot

Threat actors are using OAuth client ID spoofing to silently enumerate accounts and validate credentials in Microsoft Entra ID.The technique exploits a telemetry blind...

Grok AI Uploads Full Git Repos, Not Just Code Files

xAI's Grok Build CLI was uploading entire Git repositories with full commit history to a Google Cloud Storage bucket, not just files needed for...

Must read