Apache NiFi users should upgrade to version 2.11.0 after the project disclosed four security vulnerabilities affecting the NiFi Web API and Parameter Context authorization controls. The flaws could enable authorization …
Critical cPanel Vulnerability Allows Execution of SQL Commands as Root User
August 4, 2026 A critical privilege-escalation flaw in cPanel & WHM has been disclosed that could allow authenticated hosting users to execute arbitrary SQL commands with full database administrative privileges. …
North Korean Hackers Are Hiding Malware Servers Inside Empty Crypto Transfers
August 4, 2026 North Korean-linked attackers are using a new way to hide the servers that control malware. The method places a command server address inside an empty Ethereum transaction, …
Check Point Authentication Bypass Flaw Enables Full Compromise of Security Management System
August 4, 2026 Check Point has released security updates for a high-severity authentication-bypass vulnerability (CVE-2026-18574) that could allow attackers to compromise vulnerable Security Management environments fully. This issue affects both …
Telegram App Reportedly Vanished from Apple’s App Store Worldwide
Telegram Messenger briefly disappeared from Apple’s App Store across multiple countries late Monday, sparking a wave of confusion and speculation on social media before the app was restored a short …
Malware Can Steal Your Google Synced Passkey Without Asking for Your Password or Fingerprint
August 3, 2026 New research reveals that malware already sitting on a compromised Windows PC can hijack Google’s synced passkeys and take over accounts without ever prompting the victim for …
DNA Test Software Vulnerability Allows Attackers to Alter Analysis Data
August 3, 2026 Thermo Fisher Scientific has disclosed a high-severity security flaw affecting several of its Applied Biosystems Human Identification (HID) software products, warning that attackers could make nearly undetectable …
Public PoC Released for Critical Rails Active Storage RCE Vulnerability
August 3, 2026 A critical vulnerability in Ruby on Rails has raised new concerns about cloud data breaches, particularly for companies that host customer platforms in Amazon Web Services (AWS). …
Hugging Face Diffusers Vulnerabilities Enable Remote Code Execution Through Malicious AI Models
A set of high-severity vulnerabilities in Hugging Face’s diffusers library that allow a malicious model repository to silently execute arbitrary code on any machine that loads it. The flaws bypass …
TP-Link TL-WR940N Vulnerability Enables Remote Code Execution Attacks
TP-Link has issued a security advisory regarding a high-severity vulnerability affecting its TL-WR940N V6 wireless router. This vulnerability, tracked as CVE-2026-12935, could allow unauthenticated attackers to trigger a denial-of-service condition …

