ZCyberNews
中文

Articles

460 articles

CISA Adds Actively Exploited ConnectWise, Windows Flaws to KEVHIGH
Vulnerabilities

CISA Adds Actively Exploited ConnectWise, Windows Flaws to KEV

CISA added CVE-2024-1708 (ConnectWise ScreenConnect path traversal, CVSS 8.4) and an unnamed Windows flaw to its KEV catalog based on confirmed active exploitation.

CVE-2024-1708
3 min read
cPanel & WHM Authentication Bypass CVE-2026-41940: CVSS 9.8CRITICAL
Vulnerabilities

cPanel & WHM Authentication Bypass CVE-2026-41940: CVSS 9.8

CVE-2026-41940: Unauthenticated remote attackers can bypass authentication in cPanel & WHM and WP Squared. CVSS 9.8. Patch released April 28, 2026.

CVE-2026-41940
3 min read
CVE-2026-25874: Unpatched RCE Flaw in Hugging Face LeRobotCRITICAL
Vulnerabilities

CVE-2026-25874: Unpatched RCE Flaw in Hugging Face LeRobot

CVE-2026-25874 (CVSS 9.3) in Hugging Face LeRobot enables unauthenticated RCE via unsafe deserialization.

CVE-2026-25874
2 min read
EU Accuses Meta of Breaching DSA Child Safety RulesHIGH
Industry News

EU Accuses Meta of Breaching DSA Child Safety Rules

European Commission finds Meta violated Digital Services Act by failing to protect minors under 13 on Facebook and Instagram — risks not assessed or mitigated.

2 min read
GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git PushHIGH
Vulnerabilities

GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push

CVE-2026-3854 (CVSS 8.7) lets authenticated users with push access achieve remote code execution on GitHub.com and GitHub Enterprise Server via a crafted git push command.

CVE-2026-3854
4 min read
Oracle VirtualBox Race Condition Lets Attackers Escalate PrivilegesHIGH
Vulnerabilities

Oracle VirtualBox Race Condition Lets Attackers Escalate Privileges

CVE-2026-35230: A race condition in VirtualBox's SoundBlaster 16 emulation allows local attackers with high-privileged guest access to escalate privileges. CVSS 7.5.

CVE-2026-35230
3 min read
Project Zero Dusts Off 2017 VirtualBox Escape Draft WithHIGH
Industry News

Project Zero Dusts Off 2017 VirtualBox Escape Draft With

Google Project Zero published a 2017 draft detailing CVE-2017-3558, a VirtualBox VM escape allowing host userspace compromise. No new exploit code released.

CVE-2017-3558
2 min read
SAP npm Packages Hijacked in Credential-Stealing Supply Chain AttackCRITICAL
Malware

SAP npm Packages Hijacked in Credential-Stealing Supply Chain Attack

Attackers compromised multiple SAP-related npm packages to deploy credential-stealing malware, targeting SAP BTP and cloud app credentials. Campaign dubbed mini Shai-Hulud.

3 min readmini Shai-Hulud
Swiss Police Arrest 10 Suspected Black Axe Cybercrime MembersHIGH
Industry News

Swiss Police Arrest 10 Suspected Black Axe Cybercrime Members

Swiss and German police arrested 10 suspects tied to the Nigeria-linked Black Axe network, including a regional leader overseeing Southern Europe operations.

2 min readBlack Axe
Zero-Window Era: NDR Playbooks for Post-Mythos ExploitsHIGH
Industry News

Zero-Window Era: NDR Playbooks for Post-Mythos Exploits

Claude Mythos and Project Glasswing shrink exploit windows to near-zero. The Hacker News details NDR playbooks to contain AI-driven attacks before patching is possible.

2 min readClaude Mythos
Cyber Command, NSA Chief Warns Foreign Adversaries Will Target USHIGH
Industry News

Cyber Command, NSA Chief Warns Foreign Adversaries Will Target US

Gen. Joshua Rudd told lawmakers foreign adversaries are likely to target the 2026 US midterm elections; Cyber Command is postured to safeguard the vote.

2 min read
Flowise Auth Bypass CVE-2026-41276 Lets Attackers Reset PasswordsHIGH
Vulnerabilities

Flowise Auth Bypass CVE-2026-41276 Lets Attackers Reset Passwords

CVE-2026-41276 (CVSS 8.1) in Flowise AccountService resetPassword lets unauthenticated attackers bypass authentication. ZDI advisory warns no auth required.

CVE-2026-41276
2 min read
← PrevPage 21 of 39Next →