Chrome’s Latest Patch Closes 12 Security Holes, Nine of Them Rated High Severity
Google has shipped a new Stable Chrome release fixing 12 vulnerabilities, nine of them high severity, touching core components like V8, ANGLE, and the GPU stack. Several of...
Unauthenticated Attackers Are Actively Exploiting a ServiceNow Sandbox-Escape Flaw
A critical ServiceNow vulnerability that lets unauthenticated attackers break out of the platform's scripting sandbox is now being exploited in the wild. ServiceNow has shipped patches, but self-hosted...
New Windows ‘Bind Link’ Trick Lets Attackers Fool EDR, AMSI, and AppLocker Without Touching a File
Bitdefender researchers have detailed how Windows 'bind links' — a legitimate feature behind containers and Sandbox — can be abused by an attacker with local admin rights to...
HOLLOWGRAPH Malware Turns Microsoft 365 Calendars Into a Covert Spy Channel
Group-IB has uncovered HOLLOWGRAPH, a stealthy malware component that hides its command-and-control traffic inside Microsoft 365 calendar invites dated decades in the future. The tool shows technical overlap...
Gig Economy Platform Paidwork Leaks Banking and Personal Data of 23 Million Users
A data breach at gig-economy platform Paidwork has exposed banking details, payout histories, and personal information for more than 23 million users, with the stolen dataset publicly leaked...
Qilin Ransomware Affiliates Exploit Palo Alto Firewall Bypass to Skip Straight Past Perimeter Defenses
A critical PAN-OS authentication bypass, CVE-2026-0257, is being actively exploited by Qilin ransomware affiliates to gain direct VPN access to corporate networks. Arctic Wolf Labs traced multiple June...
Decade-Old NGINX Bug Finally Exposed: A Single Regex Quirk Enables Remote Code Execution
A remote code execution flaw that has quietly lived inside nginx's script engine since 2011 has finally come to light, tracked as CVE-2026-42533. Researchers say a single malicious...
wp2shell: The WordPress Core Bug That Lets Anyone Take Over 500 Million Sites Without Logging In
A newly disclosed WordPress Core vulnerability, nicknamed wp2shell, chains a REST API batch-route flaw into full unauthenticated remote code execution. No plugins, no login, and no special configuration...