ZCyberNews
中文

Articles

460 articles

Signal Adds In-App Warnings to Block Russian-Linked Phishing AttacksHIGH
Tools & Techniques

Signal Adds In-App Warnings to Block Russian-Linked Phishing Attacks

Signal introduced new in-app confirmations and warnings to counter phishing attacks linked to Russian state hackers who abused the Linked Device feature to hijack high-profile...

3 min readRussian state-sponsored hackers
Adobe Patches 52 Flaws Across 10 Products, Two Critical in ConnectCRITICAL
Vulnerabilities

Adobe Patches 52 Flaws Across 10 Products, Two Critical in Connect

Adobe's May 2026 patch batch fixes 52 CVEs across 10 products; Adobe Connect gets two critical bugs (CVE-2026-34659, 9.6 CVSS for RCE; CVE-2026-34660, 9.3 CVSS for privilege...

CVE-2026-34659CVE-2026-34660
3 min read
Apple Patches Everything: 0-Days, RCS Encryption RolloutCRITICAL
Industry News

Apple Patches Everything: 0-Days, RCS Encryption Rollout

Apple released emergency patches for two zero-days exploited in the wild alongside the beta rollout of end-to-end encrypted RCS messaging for iOS and macOS.

3 min read
CosyVoice gRPC Server Insecure Deserialization Flaw CVE-2026-31251CRITICAL
Vulnerabilities

CosyVoice gRPC Server Insecure Deserialization Flaw CVE-2026-31251

CVE-2026-31251: CosyVoice gRPC server deserializes untrusted models via torch.load() without weights_only=True, enabling RCE via crafted .pt files. No patch confirmed.

CVE-2026-31251
4 min read
CVE-2026-40612: jq Stack Overflow Lets Attackers Crash JSON ProcessorHIGH
Vulnerabilities

CVE-2026-40612: jq Stack Overflow Lets Attackers Crash JSON Processor

CVE-2026-40612 in jq 1.8.1 and earlier allows attackers to trigger a stack overflow via deeply nested JSON input, crashing the tool. CVSS 7.5.

CVE-2026-40612
3 min read
Docling XXE Flaw CVE-2026-31248 Lets Attackers Trigger XML Bomb DoSHIGH
Vulnerabilities

Docling XXE Flaw CVE-2026-31248 Lets Attackers Trigger XML Bomb DoS

CVE-2026-31248: Docling METS GBS backend through 2.61.0 fails to disable entity resolution in etree.fromstring(), enabling XML Bomb attacks via crafted .tar.gz archives.

CVE-2026-31248
4 min read
EU States Export Spyware to Abusive Regimes, HRW Report Finds
Industry News

EU States Export Spyware to Abusive Regimes, HRW Report Finds

Human Rights Watch report documents EU surveillance tech sales to over two dozen nations with poor human rights records, citing Bulgaria as a top exporter.

3 min read
Exim BDAT Use-After-Free Flaw CVE-2026-45185 Enables Remote CodeCRITICAL
Vulnerabilities

Exim BDAT Use-After-Free Flaw CVE-2026-45185 Enables Remote Code

CVE-2026-45185 (Dead.Letter) is a use-after-free in Exim's BDAT handling affecting GnuTLS builds — CVSS 9.8, remote code execution risk. Patches released.

CVE-2026-45185
3 min read
Instructure Pays Ransom to ShinyHunters After Canvas BreachCRITICAL
Industry News

Instructure Pays Ransom to ShinyHunters After Canvas Breach

Instructure paid ShinyHunters after two Canvas intrusions stole data from 9,000 institutions. Congress launched an investigation into the ed-tech vendor's incident response.

3 min readShinyHunters
Instructure Pays ShinyHunters to Halt 3.65TB Canvas Data LeakHIGH
Industry News

Instructure Pays ShinyHunters to Halt 3.65TB Canvas Data Leak

ShinyHunters agreed to delete 3.65TB of stolen Canvas data after Instructure paid an undisclosed ransom. The breach affects thousands of schools and universities worldwide.

3 min readShinyHunters
Ivanti Patches Flaws in Secure Access Client, EPM, Xtraction, VTMHIGH
Industry News

Ivanti Patches Flaws in Secure Access Client, EPM, Xtraction, VTM

Ivanti disclosed vulnerabilities in Secure Access Client, Endpoint Manager, Xtraction, and Virtual Traffic Manager. No evidence of exploitation.

3 min read
Škoda Discloses Customer Data Breach After Online Shop HackHIGH
Industry News

Škoda Discloses Customer Data Breach After Online Shop Hack

Škoda Auto disclosed a data breach after attackers exploited a vulnerability in its e-commerce portal, stealing customer names, addresses, and password hashes.

3 min read
← PrevPage 9 of 39Next →