New PamStealer Variant Poses as a Crypto Wallet App to Raid Mac Keychains
Jamf Threat Labs has identified a third-generation PamStealer campaign distributed through a fake multichain crypto-wallet installer called Wavel. The malware has been rewritten in Swift and now relies...
Extradited Ryuk Ransomware Conspirator Sentenced to Federal Prison in Oregon Case
Karen Vardanyan, an Armenian national extradited from Ukraine, has been sentenced to 24 months in federal prison and ordered to pay more than $1.2 million in restitution for...
GitLab’s Email-to-Issue Feature Can Be Hijacked to Commit Code as Any User
Researchers at Aikido Security found that GitLab’s incoming-email work-item feature relies on a long-lived, non-expiring token that, if exposed, lets an attacker submit merge requests and land commits...
Apache Patches a Dozen Tomcat Flaws Spanning WebSockets, HTTP/2, and TLS Checks
Apache has released Tomcat 11.0.26 to close twelve security holes across WebSocket, HTTP/2, AJP, authentication, and certificate-validation code, including a message-smuggling bug and a header mix-up introduced by...
cPanel Security Update Closes Root Escalation and Cross-Tenant Data Access Flaws
cPanel has fixed three flaws that break tenant isolation, including a root-level privilege escalation and cross-account access to calendars, contacts, and WordPress databases. Hosting providers need both current...
AWS Integration Lambda Could Turn Limited IAM Access Into Privileged Cloud Actions
CVE-2026-94384 allowed callers of an Amazon Connect Salesforce setup function to make AWS requests with the Lambda execution role's privileges. AWS has fixed the issue in AmazonConnectSalesforceLambda 5.26...
IBM Payment Platform Flaws Expose Financial Workflows to Code Execution and Fraud
IBM has patched a broad set of flaws in Financial Transaction Manager for Red Hat OpenShift, including unauthenticated code-execution bugs and authorization failures affecting payment actions. Customers on...
Critical Next.js SVG Flaw Opens Server-Side Image Routes to Remote Code Execution
A critical flaw in the Node.js implementation of Next.js ImageResponse can turn attacker-controlled SVG data into server-side code execution. Applications using affected releases should move to Next.js 16.3.6...