Critical ServiceNow AI Flaws Expose Enterprise Data and Code Execution Paths
ServiceNow has patched three critical AI-platform vulnerabilities and a high-severity Now Platform sandbox escape. Self-hosted customers should urgently verify fixed releases and investigate signs of unauthorized code execution...
APT28’s New HOOKEDGE Backdoor Targets European Defense and Diplomatic Networks
The Russia-linked APT28 group is using a lightweight backdoor called HOOKEDGE against defense, government and diplomatic targets in Europe. The campaign combines malicious Word macros, scheduled tasks, hidden...
UniBLEed Flaws Put Unitree G1 Humanoid Robots at Risk of Root Takeover
Researchers demonstrated a multi-stage attack that can give a nearby adversary root-level control of Unitree G1 humanoid robots. The UniBLEed chain combines unauthenticated Bluetooth writes, a cloud authorization...
Cyber Incident Halts Small UK Power Plant for Four Days as Attribution Remains Unclear
A cyber incident reportedly stopped a small British peaking power plant for roughly four days without disrupting customers or the wider grid. Officials confirmed the event, while key...
Emergency PaperCut Fix Targets Actively Exploited Flaw Affecting Every Supported Release
PaperCut has issued emergency builds after confirming real-world attacks against PaperCut NG and MF servers. Administrators should isolate internet-facing application servers, install the appropriate update and investigate for...
Houston Healthcare Company Nutex Health Confirms Data Breach and Exfiltration
Nutex Health, a Houston-based healthcare operator, has disclosed in an SEC filing that an unknown third party accessed its network and exfiltrated data, potentially including patient and employee...
Critical Veeam ONE Flaw Lets Unauthenticated Attackers Steal Backup Credentials (CVSS 9.3)
A newly disclosed flaw in Veeam ONE, tracked as CVE-2026-65641 with a CVSS score of 9.3, lets a remote attacker with no credentials trick the monitoring service into...
Critical cPanel Domain-Parking Flaw Lets Basic Users Seize Root Control
CVE-2026-65643 allows a low-privileged cPanel user with domain-parking rights to create arbitrary files and ultimately execute code as root. Hosting providers should verify patched builds immediately and restrict...