Malicious JPEG Images Could Trigger PHP Memory Safety Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 16, 2026 Two critical memory-safety vulnerabilities in PHP’s image-processing functions could allow attackers to leak sensitive heap memory or to execute denial-of-service attacks via specially crafted JPEG files. The flaws, discovered in PHP’s ext/standard extension by Positive Technologies researcher …

Linux Kernel Vulnerability “ssh-keysign-pwn” Lets Attackers Read SSH Keys and Shadow Passwords

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly disclosed Linux kernel vulnerability is raising serious concerns across the security community, as it allows attackers to access highly sensitive data, including SSH private keys and password hashes, on affected systems. Tracked as CVE-2026-46333, the flaw has been nicknamed “ssh-keysign-pwn” and …

Google Project Zero Discloses Zero-Click Exploit Chain for Pixel 10 Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 16, 2026 A newly disclosed zero-click exploit chain targeting Google Pixel 10 devices has raised fresh concerns about Android’s low-level security. Google Project Zero researchers demonstrated how attackers could silently compromise a device and escalate privileges to root without …

Android 16 VPN Bypass Lets Malicious Apps Reveal Users Real IP Address

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 16, 2026 A newly disclosed flaw in Android 16 is raising serious privacy concerns after researchers revealed that malicious apps can bypass VPN protections and expose a user’s real IP address even when strict security settings are enabled. The …

Gunra Ransomware Expands RaaS Operations After Shifting From Conti-Based Locker

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 15, 2026 Gunra ransomware has quickly grown from a new threat into a serious global problem, hitting dozens of organizations in less than a year. The group behind it is not just encrypting data, but also running a business-like …

OpenClaw Chain Vulnerabilities Expose 245,000 Public AI Agent Servers to Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 15, 2026 A chain of four critical vulnerabilities discovered in OpenClaw, one of the fastest-growing open-source platforms for autonomous AI agents, has left an estimated 245,000 publicly accessible server instances exposed to remote exploitation, credential theft, and persistent backdoor …

Shai-Hulud Worm Steals npm, GitHub, AWS, and Kubernetes Secrets From Developers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 15, 2026 A dangerous new piece of malware called Shai-Hulud has emerged as one of the most alarming supply chain threats of 2026. It is a self-propagating worm that quietly tunnels through developer environments, stealing credentials from npm, GitHub, …

Microsoft Edge, Windows 11 and LiteLLM Hacked in Pwn2Own Berlin 2026

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 15, 2026 Pwn2Own Berlin 2026 opened with a surge of zero-day exploits targeting modern browsers, operating systems, and emerging AI platforms. On Day One alone, security researchers successfully hacked Microsoft Edge, Windows 11, and LiteLLM, earning a total of …

Tycoon 2FA Operators Adopt OAuth Device Code Phishing to Bypass MFA

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals behind the Tycoon 2FA phishing kit have added a powerful new weapon to their playbook. By combining their well-known phishing infrastructure with OAuth Device Code abuse, they can now steal access to Microsoft 365 accounts without ever capturing a …

PraisonAI Vulnerability Exploited Within Hours of Public Disclosure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 15, 2026 As artificial intelligence frameworks become central to enterprise operations, a critical flaw in a popular AI platform has exposed organizations to serious security risks from threat actors. Within hours of public disclosure, a severe vulnerability in PraisonAI’s …