Public exploits for four patched Linux kernel flaws let local users gain root; three require unprivileged user namespaces.
WordPress 7.1.1 fixes Click2Shell, which can force theme installs from crafted links and was chained with a theme flaw for code execution.
Transparent Tribe uses four newly identified malware families in attacks on government and defense entities in India and Afghanistan.
Microsoft fixes a CVSS 10.0 Azure AI Foundry flaw enabling network privilege escalation; no exploitation has been observed.
Report URI CSP alerts surfaced a ClickFix campaign on compromised e-commerce sites using Base64 loaders and a fake verification overlay.
Thirteen npm packages deliver WeaselBiscuit, a JavaScript stealer that harvests Chrome extension storage across Windows, macOS, and Linux.
CrowdStrike says PhantomRaven was likely LLM-generated and spread through malicious npm packages that collect developer credentials and CI/CD secrets.
RatHat Android malware abuses Accessibility and ADB pairing to gain shell access and retain control after uninstall.
Check Point patched CVE-2026-91843, a critical login stack overflow that can let unauthenticated attackers run code as root ...
AI abuse, exposed infrastructure, ransomware, infostealers, malware markets, and old bugs return in this week’s ThreatsDay ...
Docker Sandboxes flaws can expose host files or Unix sockets outside the workspace; both were fixed in 0.42.0, with no ...
Unbound 1.26.1 fixes a critical DNSSEC heap overflow that malicious zones can trigger, with possible remote code execution.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results