ZCyberNews
中文

Articles

460 articles

Critical Nginx UI Vulnerability Actively Exploited for Remote Server TakeoverCRITICAL
Vulnerabilities

Critical Nginx UI Vulnerability Actively Exploited for Remote Server Takeover

Attackers are actively exploiting CVE-2026-33032, a critical flaw in the Nginx UI management tool, to execute arbitrary code and gain full control of affected web servers.

CVE-2026-33032
3 min read
Cryptography Experts Warn Quantum Risk Management Must Begin ImmediatelyHIGH
Industry News

Cryptography Experts Warn Quantum Risk Management Must Begin Immediately

Cryptography experts warn that migrating to post-quantum cryptography will take years, urging organizations to begin quantum risk management now to protect encrypted data from future 'Q-Day' harvest-now, decrypt-later attacks.

3 min read
ENISA Official Warns of Fragile Global CVE Infrastructure Amid EU RegulatoryINFORMATIONAL
Industry News

ENISA Official Warns of Fragile Global CVE Infrastructure Amid EU Regulatory

The head of ENISA's vulnerability services warns that recent CVE program funding instability exposed systemic fragility in global disclosure, as new EU regulations make coordinated disclosure a legal obligation for vendors and critical entities.

3 min read
EssentialPlugin WordPress Suite Compromised to Deploy Backdoor on Thousands ofHIGH
Malware

EssentialPlugin WordPress Suite Compromised to Deploy Backdoor on Thousands of

The EssentialPlugin suite, comprising over 30 popular WordPress plugins, has been compromised to inject a backdoor granting attackers administrative access to thousands of websites. The supply chain attack is actively being exploited.

4 min read
FISA Section 702 Reauthorization Debate Intensifies Amid Privacy and SecurityINFORMATIONAL
Industry News

FISA Section 702 Reauthorization Debate Intensifies Amid Privacy and Security

The U.S. Congress is debating the reauthorization of FISA Section 702, a surveillance authority that allows warrantless collection of foreign communications but also sweeps in American data, pitting national security claims against privacy concerns.

4 min read
Legitify Open-Source Tool Scans GitHub, GitLab for Security MisconfigurationsINFORMATIONAL
Tools & Techniques

Legitify Open-Source Tool Scans GitHub, GitLab for Security Misconfigurations

Legit Security releases Legitify, an open-source scanner that identifies security misconfigurations in GitHub and GitLab organizations, repositories, and CI/CD runners to combat software supply chain risks.

4 min read
Major Tech Giants Ignore Legally Mandated Privacy Opt-Out SignalsHIGH
Industry News

Major Tech Giants Ignore Legally Mandated Privacy Opt-Out Signals

A forensic audit finds Google, Microsoft, and Meta systematically ignore the Global Privacy Control signal, setting tracking cookies after users opt out, violating California privacy law.

3 min read
Microsoft Patches Defender Zero-Day Allowing Local Privilege EscalationHIGH
Vulnerabilities

Microsoft Patches Defender Zero-Day Allowing Local Privilege Escalation

Microsoft patches CVE-2026-33825, an 'Important' zero-day flaw in the Microsoft Defender Antimalware Platform that allows local attackers to escalate privileges to SYSTEM. The vulnerability was publicly disclosed on April 14, 2026.

CVE-2026-33825
4 min read
Microsoft Confirms Active Exploitation of SharePoint Zero-Day Spoofing FlawHIGH
Vulnerabilities

Microsoft Confirms Active Exploitation of SharePoint Zero-Day Spoofing Flaw

Microsoft warns that a critical spoofing vulnerability, CVE-2026-32201, in SharePoint Server is being actively exploited. The flaw allows attackers to bypass authentication and access sensitive data.

CVE-2026-32201
4 min read
Mirax Android RAT Evolves with Proxy Network and Data Theft CapabilitiesHIGH
Malware

Mirax Android RAT Evolves with Proxy Network and Data Theft Capabilities

The Mirax Android RAT is being offered as a Malware-as-a-Service to Russian-speaking affiliates, ensnaring devices in Europe into a residential proxy network while stealing credentials and sensitive data.

5 min read
Signed Adware Tool Disables Antivirus with SYSTEM PrivilegesHIGH
Malware

Signed Adware Tool Disables Antivirus with SYSTEM Privileges

A digitally signed adware tool, 'PC App Store', has been abused to deploy scripts that disable antivirus software with SYSTEM privileges, impacting thousands of endpoints in sectors like education and government.

3 min read
CISA Flags Six Actively Exploited Flaws in Fortinet, Microsoft, AdobeHIGH
Vulnerabilities

CISA Flags Six Actively Exploited Flaws in Fortinet, Microsoft, Adobe

CISA added six vulnerabilities in Fortinet, Microsoft, and Adobe software to its Known Exploited Vulnerabilities catalog, warning of active in-the-wild attacks requiring urgent patching.

CVE-2026-21643
3 min read
← PrevPage 35 of 39Next →