Critical ArangoDB Flaws Enable Login Bypass and Root-Level Code Execution
Two critical ArangoDB vulnerabilities can be chained to bypass authentication, manipulate database content and execute code with root privileges. Version 3.12.11 contains fixes, and exposed deployments should be...
MapLibre Sanitizer Bug Puts 2.7 Million Sites at Risk of Zero-Click Code Execution
A critical flaw in the widely used MapLibre GL JS mapping library lets attackers slip malicious event handlers past its HTML sanitizer, triggering code execution with no clicks...
N0va Phishing Kit Hijacks Real Microsoft Logins to Steal Session Tokens
A new phishing kit called N0va abuses legitimate device-code authentication flows for Microsoft, Google, and other trusted services to steal access and refresh tokens rather than passwords. The...
ChatGPT Sandbox Isolation Flaw Created a Hidden Route for Cross-Account Data Theft
Researchers found that a shared internal package service could act as a covert communication channel between isolated ChatGPT containers. The proof of concept combined hidden instructions and connected-app...
FortiGate Exploitation Campaign Plants PivotC2 Malware and Steals Network Credentials
Attackers are exploiting a critical Fortinet vulnerability to install a custom Node.js remote-access framework on exposed appliances. The campaign has reportedly compromised 178 devices and can harvest credentials,...
Microsoft’s September Patch Wave Fixes 973 Flaws and Two Exploited Zero-Days
Microsoft’s September 2026 security release addresses 973 vulnerabilities across Windows, Office, SQL Server and other enterprise products. Two privilege-escalation zero-days are already being exploited, making rapid testing and...
How a Shared ChatGPT Sandbox Turned Into a Covert Channel for Stealing Gmail Data
Check Point Research found that ChatGPT's supposedly isolated code-execution sandboxes all shared access to the same backend package repository, allowing hidden instructions to hop between completely unrelated user...
Microsoft’s September Patch Tuesday Closes 973 Holes, Including Two Zero-Days Already Under Attack
Microsoft's September 2026 security update addresses 973 vulnerabilities — one of its largest releases on record — including two Windows elevation-of-privilege flaws that attackers are actively exploiting. Several...