Critical Next.js Flaws Put Windows Servers and AVIF Image Processing at Risk of RCE
Two critical Next.js vulnerabilities may enable unauthenticated remote code execution through Windows path handling and AVIF image processing. Vercel fixed both issues in Next.js 15.5.24 and 16.3.3, with...
Ubiquiti Fixes 21 Critical UniFi Flaws Across Routers, Cameras and Access Systems
Ubiquiti has patched 21 critical vulnerabilities across a broad range of UniFi products, including flaws rated a maximum 10.0. The bugs enable outcomes including authentication bypass, command injection...
CISA Flags Actively Exploited Gitea Flaw That Turns Repository Access Into Server Code Execution
CISA has added CVE-2026-60004 to its Known Exploited Vulnerabilities catalog after confirming attacks against Gitea servers. The flaw can let a repository writer plant a malicious Git hook...
28,000 Public .git Folders Left AWS Keys, Stripe Tokens, and HR Files Wide Open, Researchers Find
A large-scale internet scan uncovered 28,000 publicly accessible .git directories exposing hundreds of live cloud and payment credentials, along with sensitive employee records — a reminder that scrubbing...
Google Ships Chrome 152 With Fixes for 327 Flaws, Including 10 Critical Use-After-Free Bugs
Chrome 152 lands with 327 security fixes, ten of them rated critical and mostly tied to use-after-free memory bugs across components like ANGLE, Aura, and Chromecast. None are...
Mirage2FA Phishing Kit Hijacks Microsoft 365 Sessions at 3,500+ Organizations, Sidestepping MFA Entirely
A phishing-as-a-service kit called Mirage2FA has compromised thousands of Microsoft 365 accounts by stealing live session cookies through an adversary-in-the-middle proxy, letting attackers walk past passwords and MFA...
Iran-Linked Tortoiseshell Expands Espionage With TWOSTROKE Backdoor and Reverse SSH Tunnels
Researchers have linked new Windows malware and reverse SSH infrastructure to the Iran-associated Tortoiseshell threat group. The tools masquerade as a legitimate Windows library and support covert tunneling,...
One Malicious Webpage Can Hijack Your AI Coding Agent Through an NVIDIA NemoClaw Flaw
A critical flaw in NVIDIA's NemoClaw tooling exposes a local AI inference server to the open network, letting a single malicious website hijack an AI agent via DNS...