Click2Shell Chain Turns One Malicious Link Into WordPress Server Takeover
WordPress has fixed a theme-preview weakness that can silently install an attacker-selected theme when an administrator opens a crafted link. Paired with unsafe pre-activation code in a theme,...
Critical Check Point Login Flaw Exposes Management Servers to Root Takeover
Check Point has issued an urgent fix for CVE-2026-91843, a remotely exploitable buffer overflow that can grant root privileges before authentication. Administrators should deploy and verify the LivePatch...
Chinese Hacking Crew Weaponizes Critical Gitea Flaw to Hijack Self-Hosted Git Servers Worldwide
A Chinese-speaking intrusion set tracked as Red Heron is exploiting a critical remote-code-execution bug in self-hosted Gitea instances, deploying a custom Linux implant and rootkit against victims in...
Dell ObjectScale CVSS 10 Flaw Exposes Enterprise Storage to Remote Takeover
Dell has fixed a maximum-severity ObjectScale vulnerability that could let an unauthenticated remote attacker execute code on exposed storage systems. Organizations should upgrade quickly, reduce management-plane exposure and...
Critical CSF Flaw Exposes cPanel Servers to Unauthenticated Command Execution
A critical flaw in ConfigServer Security & Firewall can let remote attackers execute commands through its optional MESSENGER service without logging in. Administrators using CSF 14.00 through 16.29...
AI Agent Swarm Exploits PaperCut Flaws Across 440 Servers Worldwide
A Russian-speaking operator used hundreds of autonomous AI agents to compromise 440 PaperCut servers across 48 countries. Although only a fraction reached domain administrator, the campaign shows how...
Critical ArangoDB Flaws Enable Login Bypass and Root-Level Code Execution
Two critical ArangoDB vulnerabilities can be chained to bypass authentication, manipulate database content and execute code with root privileges. Version 3.12.11 contains fixes, and exposed deployments should be...
Critical Ivanti Flaws Expose ITSM and Mobile Management Systems to RCE and Admin Takeover
Ivanti has disclosed ten vulnerabilities across EPMM, Neurons for ITSM and Sentry, including unauthenticated remote-code-execution flaws rated 9.8. Cloud instances have been patched, while on-premises customers and Sentry...