Decade-Old NGINX Bug Finally Exposed: A Single Regex Quirk Enables Remote Code Execution
A remote code execution flaw that has quietly lived inside nginx's script engine since 2011 has finally come to light, tracked as CVE-2026-42533. Researchers say a single malicious...
wp2shell: The WordPress Core Bug That Lets Anyone Take Over 500 Million Sites Without Logging In
A newly disclosed WordPress Core vulnerability, nicknamed wp2shell, chains a REST API batch-route flaw into full unauthenticated remote code execution. No plugins, no login, and no special configuration...
This Week’s Threat Landscape: Patch Tuesday’s 570 Fixes, an Active Directory Zero-Day, and AI Tools Under Fire
A packed week in cybersecurity saw Microsoft ship roughly 570 patches including two actively exploited zero-days, a WordPress RCE bug threatening hundreds of millions of sites, and a...
HollowByte: How 11 Bytes Can Quietly Starve an OpenSSL Server to Death
A newly disclosed OpenSSL weakness, dubbed HollowByte, lets an unauthenticated attacker trigger a slow, memory-fragmenting denial-of-service condition using a payload as small as 11 bytes. Because it was...
Spirals Ransomware: From First Foothold to Full Encryption in Under 24 Hours
A newly identified ransomware strain called Spirals encrypted an entire IT services company's network in South Asia within a single day, using an IIS web shell, tunneling tools,...
Hugging Face Breach Reveals a New Front: AI Agents Attacking, AI Agents Defending
Hugging Face has confirmed a production infrastructure intrusion driven by an autonomous AI agent, exploiting two flaws in its dataset processing pipeline. The company's own AI-based forensic analysis...
Citrix Patches Privilege Escalation Flaw That Hands Standard Users Full SYSTEM Control
Cloud Software Group has disclosed two vulnerabilities in Citrix Secure Access and Endpoint Analysis clients for Windows, including a high-severity flaw (CVSS 8.5) that lets a low-privileged local...
Inside NadMesh: The Shodan-Powered Botnet Hunting Exposed AI Servers
Researchers at XLab have identified NadMesh, a Go-based botnet that uses Shodan to hunt down exposed AI and MCP infrastructure before hijacking it with more than 20 exploitation...