Next.js Ships Emergency Fixes for Nine Flaws, Including High-Severity SSRF and Auth Bypass Bugs
Vercel has patched nine security vulnerabilities in Next.js, the widely used React framework, covering server-side request forgery, a middleware authentication bypass, denial-of-service conditions, and data-exposure issues. Four of...
Chaos Ransomware’s New msaRAT Tool Hijacks Chrome and Edge as a Stealth Command Channel
Cisco Talos has identified msaRAT, a Rust-based tool tied to the Chaos ransomware group that quietly launches Chrome or Edge in headless mode and turns the browser into...
Sloppy Server Configuration Unmasks JadeProx Espionage Campaign and Its TriBack Malware Loader
Researchers at Group-IB stumbled onto an active espionage operation, now tracked as JadeProx, after its operators left a staging server's directory listing wide open. The exposed files revealed...
Alleged 160-Million-Record Decathlon Customer Database Surfaces on Cybercrime Forum
A threat actor is advertising what they claim is a Decathlon customer database of roughly 160 million records on an underground forum, seeking cryptocurrency payment. Decathlon has not...
ASUS Rushes Out Router Patch After Discovery of Unauthenticated Remote Command Execution Flaw
ASUS has issued firmware updates for a high-severity vulnerability, tracked as CVE-2026-13385, that could let remote attackers run arbitrary commands on widely deployed router models without authentication. Security...
RefluXFS: A Nine-Year-Old Race Condition in Linux’s XFS Filesystem Opens a Silent Road to Root
Qualys researchers have disclosed RefluXFS (CVE-2026-64600), a race condition in the Linux kernel's XFS copy-on-write path that lets a local, unprivileged user seize root access while leaving no...
HermeticReader: How a Bug in Adobe’s PDF Browser Extension Could Expose WhatsApp Chats to Any Website
Researchers at Guardio Labs disclosed a flaw in the Adobe Acrobat Chrome extension, installed on roughly 329 million browsers, that let a malicious website silently read a victim's...
Iran’s Cyber Playbook Shifts From Loud Attacks to Patient, Long-Term Access
A new SentinelOne assessment finds Iran-linked hacking groups increasingly favor quiet, persistent access over destructive attacks, planting footholds in cloud accounts, IT suppliers, and industrial systems that could...