Apache HTTP Server 2.4.69 Fixes 20 Flaws Across CGI, WebDAV and Proxy Modules
Apache HTTP Server 2.4.69 addresses 20 vulnerabilities that can cause code execution, memory corruption, crashes, data exposure or authentication problems under particular configurations. Administrators should upgrade, but risk-based...
Antino Backdoor Hides Its Entire Command Channel Inside Microsoft 365
A China-linked espionage campaign has deployed a Rust backdoor whose native command-and-control workflow runs through Outlook and OneDrive. Cisco Talos found roughly 350 compromised endpoints across eight countries,...
Warlock Ransomware Turns SharePoint Servers Into Gateways to Essential Services
A China-linked operator is exploiting on-premises SharePoint flaws to deploy Warlock ransomware across water, telecom, government and education organizations. Recent intrusions show how web shells, stolen machine keys,...
Actively Exploited FortiMail Zero-Day Lets Attackers Write Files Without Login
Fortinet says attackers are exploiting a critical FortiMail flaw that permits unauthenticated file writes through crafted web requests. With patches still pending for several branches at disclosure, administrators...
Star Blizzard’s RedFlick Phishing Chain Targets More Than 100 Organizations
A Russia-linked operation is using attachment-free opening messages before sending encrypted archives that deploy the CosmicPulse backdoor. More than 100 organizations, particularly those involved with Ukraine-related policy and...
CopyEscape Flaw Turns Docker File Copies Into a Route to Host Root
A flaw in Docker’s archive extraction path can let a hostile container write beyond the destination chosen for a file copy. On Linux systems where the command runs...
How a Single Poisoned Package Can Hand Attackers the Keys to Your Cloud
A new Qualys analysis ties together a string of 2025–2026 software supply chain campaigns — from the Shai-Hulud worm to malicious Ruby gems and Go modules — showing...
Cloudflare’s New Certificate Design Aims to Make Quantum-Safe HTTPS Actually Practical
Cloudflare is building a certificate authority around a new 'Merkle Tree Certificate' format designed to deliver post-quantum website authentication without bloating every TLS handshake. Early tests show a...