Vercel Confirms KVM Zero-Day Behind Claimed Guest-to-Host Root Escape
Vercel has confirmed a KVM zero-day reported through its Sandbox bounty program after a researcher claimed a full guest-to-host escape. Technical details, affected versions and remediation guidance remain...
Debian’s Massive 1,313-CVE Kernel Update: What Administrators Actually Need to Know
Debian's DSA-6528-1 advisory bundles fixes for 1,313 CVEs into a single kernel update for Trixie, addressing privilege escalation, denial-of-service, and information-leak risks. The headline number is less alarming...
Root-Level cPanel/WHM Flaw Puts Every Hosted Account on a Server at Risk
cPanel has patched a critical flaw (CVE-2026-93698) in the Multilang adminbin component that allows arbitrary command execution as root, alongside two stored XSS bugs in WHM's SSL Hosts...
Leaked Control Panel Exposes 50,000 Stolen Credentials Harvested From WordPress Backups
Researchers at LevelBlue uncovered TIKTOUK, a credential-harvesting toolkit that scans for exposed WordPress backups, configuration files, and JavaScript secrets. A leaked operator panel contained roughly 50,000 real credentials...
Inside the Supply Chain Playbook Turning Trusted Software Updates Into Credential Thieves
A new ReversingLabs report ties together the S1ngularity, Shai-Hulud, and TeamPCP/Trivy supply chain incidents, showing how stolen maintainer tokens and compromised CI pipelines let attackers push credential-stealing code...
Red Hat Satellite Authorization Flaw Can Expose Root Passwords and Enable Code Execution
Red Hat has patched a CVSS 9.1 authorization flaw in Satellite's Foreman component that lets low-privileged users view protected host data, potentially including root passwords. Unsafe Safemode configurations...
Attackers Abuse SQL Server as a Covert Command and Exfiltration Channel
Investigators found attackers using Microsoft SQL Server functionality to execute Windows commands and return stolen files through query output. An exposed staging server also leaked the intruders' toolkit...
Dell Storage Module Flaws Expose Kubernetes Environments to Admin Takeover
Dell has fixed multiple critical flaws in its Container Storage Modules, including two CVSS 10 vulnerabilities reachable without authentication. Attacks could expose array credentials, bypass tenant controls and...