Microsoft Patches Three Critical Information Disclosure Vulnerabilities in Microsoft 365 Copilot and Edge
Microsoft has disclosed and fully remediated three critical information disclosure vulnerabilities — CVE-2026-26129, CVE-2026-26164, and CVE-2026-33111 — affecting Microsoft 365 Copilot and Copilot Chat in Microsoft Edge. All...
Three Critical cPanel and WHM Vulnerabilities Enable Code Execution, File Reads, and DoS Attacks
cPanel has disclosed three critical security vulnerabilities — CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203 — affecting its widely deployed cPanel & WHM web hosting control panel and WP Squared platform....
Pack2TheRoot: Critical Linux Privilege Escalation Flaw in PackageKit Affects 12+ Years of Releases (CVE-2026-41651)
Deutsche Telekom's Red Team has disclosed Pack2TheRoot (CVE-2026-41651), a critical local privilege escalation flaw in the PackageKit daemon affecting all major Linux distributions across 12+ years of releases,...
The Kitten Project: A New Era of Coordinated Hacktivism
The cyber-world has always been a stage for activism and protest, but the rise of hacktivism offers something different – a blend of technical expertise and political expression....
A Critical Patch for Vulnerable Next.js: New Scanner Unveils Hidden Attacks
With the rise of Serverless functions, static site generators like Next.js have become ubiquitous in web development, streamlining functionality and boosting speed. However, while these frameworks offer undeniable...
A Silent Vulnerability Exposed: How Hackers Used Hidden Commands to Steal Sensitive Data
Microsoft’s seemingly “unremarkable” November 2025 Patch Tuesday update actually contained a major security fix. But even the most meticulous patching process can sometimes be outmaneuvered by cunning threat...
HashJack: weaponizing trust in AI browser assistants
A vulnerability in the way AI browser assistants handle URL fragments opens doors for malicious attacks. For years, we’ve seen AI take center stage across various industries, revolutionizing...
A Critical Security Flaws in HashiCorp’s Provider
HashiCorp’s Vault Terraform provider, a cornerstone of secure secrets management for organizations worldwide, has been found with a critical security flaw. This vulnerability, tracked as CVE-2025-13357, affects users...