ZCyberNews
中文

Articles

460 articles

Apache Patches Critical HTTP/2 Double-Free Flaw CVE-2026-23918CRITICAL
Vulnerabilities

Apache Patches Critical HTTP/2 Double-Free Flaw CVE-2026-23918

Apache HTTP Server CVE-2026-23918 (CVSS 8.8) enables DoS and potential RCE via double-free in HTTP/2 handling. Affects all mod_http2 users. Patch now.

CVE-2026-23918
3 min read
CloudZ RAT Hijacks Microsoft Phone Link to Steal SMS, OTPsHIGH
Malware

CloudZ RAT Hijacks Microsoft Phone Link to Steal SMS, OTPs

Cisco Talos: CloudZ RAT's new Pheno plugin abuses Windows Phone Link to read SMS and OTPs from local SQLite database.

2 min readCloudZ
Critical Ollama Bug CVE-2026-7482 Exposes 300K DeploymentsCRITICAL
Vulnerabilities

Critical Ollama Bug CVE-2026-7482 Exposes 300K Deployments

Cyera discloses CVE-2026-7482 (CVSS 9.3) — a heap out-of-bounds read in Ollama's GGUF model loader that leaks prompts, API keys, and secrets via three unauthenticated API calls.

CVE-2026-7482
2 min read
EOL Open Source Blind Spots Hide 400K+ Unflagged CVEsHIGH
Industry News

EOL Open Source Blind Spots Hide 400K+ Unflagged CVEs

HeroDevs analysis: 5.4M EOL package versions across npm, PyPI, Maven evade SCA scanners; ~80% of CVEs on supported versions also affect unlisted EOL releases. Free scan offered.

CVE-2026-22732
4 min read
Persistent OAuth Tokens: The Back Door Attackers ExploitHIGH
Industry News

Persistent OAuth Tokens: The Back Door Attackers Exploit

OAuth tokens with no expiration persist in Google and Microsoft tenants — attackers bypass MFA and perimeter controls.

3 min read
ShinyHunters Breaches Vimeo, Leaks 119K User RecordsHIGH
Industry News

ShinyHunters Breaches Vimeo, Leaks 119K User Records

ShinyHunters leaked a 106GB archive of Vimeo data after breaching Anodot, exposing emails and names of 119,200 users. No credentials or payment info compromised.

2 min readShinyHunters
Student Hacked Taiwan High-Speed Rail TETRA System, TriggeredHIGH
Industry News

Student Hacked Taiwan High-Speed Rail TETRA System, Triggered

A 23-year-old student used SDR gear to clone TETRA radio parameters, sending a 'General Alarm' signal that halted 4 THSR trains for 48 minutes.

3 min read
Trellix Source Code Breach Exposes Security Product InternalsHIGH
Industry News

Trellix Source Code Breach Exposes Security Product Internals

Attackers stole source code from Trellix, exposing detection logic and control locations in its security products. The breach amplifies supply chain risks for enterprise customers.

2 min read
Cisco Acquires Astrix Security for Non-Human Identity Protection
Industry News

Cisco Acquires Astrix Security for Non-Human Identity Protection

Cisco announced plans to acquire Astrix Security to address non-human identity risks in AI and machine workloads. The deal expands Cisco's identity security portfolio.

2 min read
Cyber Tax Raises Consumer Prices After Breaches, Podcast WarnsMEDIUM
Industry News

Cyber Tax Raises Consumer Prices After Breaches, Podcast Warns

Malwarebytes Lock and Code podcast: Eva Velasquez details how small business cyberattacks create a 'cyber tax' that raises prices for all consumers — no sector immune.

2 min read
Cybersecurity M&A Roundup: 33 Deals Announced in April 2026
Industry News

Cybersecurity M&A Roundup: 33 Deals Announced in April 2026

SecurityWeek reports 33 cybersecurity M&A deals in April 2026, including acquisitions by Airbus, Cyera, Fortra, Palo Alto Networks, Silverfort, and Socket.

2 min read
Infrastructure Breach: Hackers Steal Student Data from Canvas PlatformHIGH
Industry News

Infrastructure Breach: Hackers Steal Student Data from Canvas Platform

Infrastructure confirmed hackers accessed Canvas user data — names, emails, student IDs, messages — from educational institutions.

2 min read
← PrevPage 17 of 39Next →