-
MapLibre GL JS users are advised to upgrade their software following the disclosure of an XSS vulnerability, identified as CVE-2026-85061 and documented in GitHub advisory GHSA-jrc7-96c5-q579. This vulnerability affects maplibre-gl versions 6.4.0 and e…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
GoldFactory has expanded the evasion capabilities of its Gigabud Android banking trojan by deploying Vwork, a weaponized fork of the open-source Shelter application. The companion tool abuses Android Work Profile isolation to clone banking apps into a …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Microsoft disclosed CVE-2026-69449, an Important-severity vulnerability in Windows BitLocker. This issue is classified as a heap-based buffer overflow (CWE-122) and may allow remote code execution (RCE). Microsoft released details about this vulnerabil…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researchers have revealed a recently patched flaw in ChatGPT’s isolation system that could have allowed attackers to access data from a victim’s connected Gmail account and send it to a separate ChatGPT account through a hidden cro…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat actors are increasingly operationalizing agentic artificial intelligence to compress cyberattack timelines, automating reconnaissance, vulnerability research, exploit development and credential theft with far less hands-on-keyboard activity. How…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat actors are actively exploiting a critical vulnerability in FortiGate to deploy PivotC2, a Node. js-based remote access trojan (RAT) designed for persistent post-exploitation of FortiOS appliances. Researchers at SOCRadar’s Threat Research Unit (…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly published proof-of-concept (PoC) called ShieldCrash reveals an unpatched vulnerability in Microsoft Defender that allows a local attacker to gain arbitrary file-read access in the SYSTEM context. This disclosure, attributed to the researcher kn…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
U.S. intelligence and cybersecurity agencies have accused six China-based AI companies including DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun and Z.AI of extracting billions of tokens from leading American AI systems through industrial-scale knowle…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
cPanel has disclosed CVE-2026-67401, a SQL injection vulnerability in its EmailTrack functionality. This flaw allows an authenticated account holder to create arbitrary files on a server, which can ultimately enable them to execute code with root privi…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Fortinet FortiSandbox Vulnerability Allows Unauthenticated Attackers to Access Sensitive Information

Fortinet has disclosed a critical vulnerability involving improper access control in the FortiSandbox web interfaces. This issue could allow an unauthenticated remote attacker to access sensitive information by sending specially crafted HTTP requests. …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶

