Cybersecurity

Critical WordPress RCE bug actively exploited within hours

Threat actors are actively exploiting a critical WordPress vulnerability, CVE-2026-87902, just hours after its public disclosure.The unauthenticated remote code execution (RCE) flaw carries a...

MikroTik SSH flaws chained for full router takeover

A chain of two SSH vulnerabilities—CVE-2026-67279 and CVE-2026-86060—allows unauthenticated attackers to gain full administrative control over exposed MikroTik RouterOS devices.Active exploitation began before patches...

MemTensor npm, PyPI packages push credential-stealing malware

Compromised MemTensor packages on npm and PyPI delivered the Go-based sckit implant across Windows, Linux, and macOS.Attackers stole publish tokens from MemTensor’s GitHub Actions...

Next.js Critical Flaw in ImageResponse Allows Server RCE

A critical vulnerability (CVE-2026-94545, CVSS 9.5) in Next.js versions 16.2.0 through 16.3.5 allows remote code execution via the ImageResponse feature when running on the...

Critical AI Gateway Bug Allows Unauthenticated RCE

A critical unauthenticated remote code execution vulnerability (CVE-2026-90898, CVSS 9.8) affects all versions of the open-source AI gateway Bifrost before 2.1.0.A second flaw (CVE-2026-86242,...

Critical VeloCloud Orchestrator flaw actively exploited

Arista disclosed a critical flaw (CVE-2026-93952) in on-premises VeloCloud Orchestrator (VCO) actively exploited as of September 22.The vulnerability, with a CVSS 3.1 score of...

Mac Malware Hijacks Meta Muse, Security Researcher Warns

Security researcher Patrick Wardle disclosed a vulnerability in Meta's new Muse AI assistant for Mac that allows malware to hijack dictation and steal account...

North Korea’s Contagious Interview hack steals $10.7M in crypto

North Korean threat actors compromised 30,000 devices across 100+ countries and stole from over 7,000 cryptocurrency wallets, netting at least $10.71 million.The Contagious Interview...

Latest news

SEC proposes easing crypto custody rules for advisers

The SEC proposed easing custodian rules for investment advisers to hold client crypto assets.Advisers can self-custody assets if no...

Burry: Temporary GPU Shortages Mask Rapid Depreciation

Michael Burry warns that NVIDIA's GPU residual value claims rely on discounted cash flow models, not actual secondary market...

NEAR Intents halted after $3.8M hack

NEAR Intents halted services after a $3.8 million exploit of its Omni deposit and withdrawal infrastructure.The protocol patched the...