Public Exploit Code Raises Urgency Around Critical Atlassian File-Read Flaw
A proof-of-concept exploit is now public for CVE-2026-21589, a critical, unauthenticated file-read flaw affecting Jira, Confluence, Bitbucket, and other self-managed Atlassian Data Center products. In certain Crowd-connected setups...
Fake Cloudflare Verification Pages Used to Push LUNEXSTEALER Malware on 100+ Hacked Sites
Ukraine's CERT-UA is tracking a campaign, dubbed UAC-0277, that has compromised more than 100 legitimate websites to show visitors a convincing but fake Cloudflare verification screen. Clicking through...
Breach at Discord Bot Provider Double Counter Exposes Data on Millions of Users
An intrusion into Double Counter, a third-party company behind a popular Discord moderation bot, let an attacker pull tens of millions of user records and briefly hijack the...
Pwn2Own Ireland 2026: Researchers Cash In on 32 Zero-Days Across Samsung, Oracle, and AI Platforms
On the opening day of Pwn2Own Ireland 2026, competing research teams chained together 32 previously unknown vulnerabilities across flagship phones, AI services, and smart-home gear, collecting $388,500 in...
South Korean Church Breaches Expose More Than One Million Congregant Records
Attackers penetrated two major South Korean churches through a web shell, leaked credentials and broken authorization controls, exposing records tied to more than one million congregants. The intrusions...
CyberXero Uses AI Agent Swarms to Scale WordPress Intrusions and Target Ukrainian Energy
A Russian-speaking initial-access broker known as CyberXero used dozens of AI agents alongside PentAGI and Cobalt Strike to automate web attacks and conduct targeted reconnaissance. Exposed operator files...
Attackers Hijack Three Country-Code Registries to Obtain Rogue HTTPS Certificates
Attackers compromised the .gh, .sl and .as domain registries and exploited DNS control to obtain unauthorized HTTPS certificates for Google and other organizations. Chrome blocked known certificates, but...
SonicWall Fixes Maximum-Severity SMA1000 Flaw Allowing Pre-Login Internal Requests
SonicWall has patched four SMA1000 vulnerabilities, led by a CVSS 10 pre-authentication SSRF flaw that can turn an exposed appliance into a proxy for internal requests. Organizations must...