Zapscape Flaw Lets a Rogue Cloud Virtual Machine Seize Root on Its Host Server
A Linux kernel vulnerability nicknamed Zapscape and tracked as CVE-2026-64561 allows a malicious KVM guest running nested virtualization to escape its virtual machine entirely and take root control...
New WordPress Flaw Turns a Failed Login Attempt Into Full Server Takeover
A newly disclosed WordPress vulnerability, dubbed XSS2Shell and tracked as CVE-2026-64638, chains a decade-old parsing quirk in the login page into full remote code execution, putting an estimated...
18-Year-Old Linux Kernel Bug Lets Attackers Seize Full Root and Break Out of Containers
A newly disclosed use-after-free vulnerability nicknamed SCTPhantom, tracked as CVE-2026-64564, traces back to Linux kernel code written in 2007 and lets a local attacker escalate to full root...
Researchers Find Matching RCE Flaws in Claude Code, Gemini CLI and Codex Coding Agents
Security researcher Elad Meged has uncovered a strikingly similar vulnerability pattern across AI coding agents from Anthropic, Google, and OpenAI, all traceable to how each vendor's surrounding 'harness'...
Thousands of Exposed Rockwell PLCs Leave US Water Utilities Open After Multi-State Attack Wave
A wave of attacks against U.S. water and wastewater utilities has renewed scrutiny of how many industrial controllers sit exposed to the open internet. Forescout researchers count over...
Cisco Rushes Fixes for Near-Maximum-Severity Flaws in Catalyst SD-WAN
Cisco has patched five vulnerabilities in Catalyst SD-WAN Software, three of them scoring 9.9 out of 10 on the CVSS scale. There is no evidence of active exploitation...
One Click, Total Takeover: The RCE Bug That Hid Inside Cursor, VS Code, and Google Antigravity
Security researchers at AISLE uncovered a one-click remote code execution flaw shared by Cursor, Microsoft VS Code, and Google Antigravity, all three built on the same underlying codebase....
Six Ways to Break Flowise: New RCE Chain Puts AI Workflow Servers at Risk
Security researchers at Elttam disclosed six separate remote code execution flaws in the Flowise AI workflow platform, spanning CSV processing, sandboxed JavaScript, and database configuration. Several of the...