-
A swarm of AI agents believed to be operated internally by OpenAI uploaded more than 2,000 malicious packages to RubyGems in May 2026, abusing the ecosystem’s documentation build process to execute code remotely and attempting to steal user API keys th…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks. The issue affects both GitLab Com…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A long-running pay-per-install (PPI) operation that used YouTube gaming channels and SEO-poisoned software downloads to distribute malware at scale. The cluster, tracked as CL-CRI-1171, is linked to more than 10,000 distinct samples of a custom loader …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These vulnerabilities can be triggered by processing a malicious PNG file or connecting to attacker-controlled RealRTSP …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are actively being exploited in the wild. On September 10…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A recently disclosed vulnerability in ConfigServer Security & Firewall (CSF) could allow unauthenticated remote attackers to execute arbitrary commands through the product’s MESSENGER service. This vulnerability, tracked as CVE-2026-65638, affects …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat actors are adapting malware not only for conventional endpoint defenses and sandboxes, but also for large language model-powered tools increasingly used to triage suspicious code. ESET researchers linked the activity to Russia-aligned threat act…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
GitLab has issued an emergency security update to address two critical vulnerabilities that could lead to unauthenticated file disclosure and authenticated credential theft, as well as a high-severity flaw that may enable remote code execution. The com…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat actors are actively exploiting three vulnerabilities in JFrog Artifactory, CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329, to bypass authentication, escalate privileges, and gain administrative control of exposed instances. Wiz Research repo…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Okta has released security updates for three high-severity vulnerabilities affecting the Auth0 AD/LDAP Connector and Okta Access Gateway. These vulnerabilities could allow authenticated attackers to trigger stored cross-site scripting (XSS), bypass Pro…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


