Japan’s Digital Agency has confirmed a significant data breach affecting the Government Solution Service (GSS), a shared IT platform used across multiple ministries and government bodies, after attackers exploited a …
Homebrew 7.0.0 Adds Built-In Vulnerability Scanner and Stronger Package Sandboxing
Homebrew has released version 7.0.0, introducing a native vulnerability scanner, a Homebrew-specific advisory database, stronger sandboxing, and faster package installation workflows. The release also ends support for macOS Catalina 10.15 …
cPanel LiteSpeed Web Server Vulnerability Allows Shared Server Users to Gain Root-Level Access
cPanel has issued an urgent security advisory warning that a critical vulnerability in LiteSpeed Web Server Enterprise could allow a low-privileged shared-hosting user to gain root-level access to an affected …
Google’s New Search Redirects Make It Harder to Check Where Links Lead Before Clicking
Google is changing how some search-result links behave. Certain results now pass through an encoded Google redirect rather than opening the listed site, making a browser’s link preview less useful …
New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Phishing is arriving via trusted email systems. Instead of using obvious malicious addresses, attackers send ordinary account alerts, invoices and renewal notices that lead victims into web-based traps. The approach …
Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Attackers are actively exploiting a critical flaw in a WooCommerce extension to seize control of WordPress sites without a username or password. The issue affects Wholesale Lead Capture and turns …
Critical WordPress Plugin Flaws Put Over 600,000 Websites at Risk of Takeover
Two critical vulnerabilities in The Events Calendar WordPress plugin could allow unauthenticated attackers to take over vulnerable websites. The flaws affect more than 600,000 active installations. They can lead to …
Hackers Actively Exploiting Gitea n-day RCE Vulnerability in the Wild to Hijack Instances
Hackers are actively exploiting a critical Gitea remote code execution vulnerability, tracked as CVE-2026-60004, to compromise internet-facing source-code management servers. Researchers found that a Chinese-speaking threat actor, named Red Heron, …
New DDRop Attack Breaks Intel TDX and AMD SEV-SNP With $159 DDR5 Device
Confidential cloud systems are designed to keep a customer’s data hidden even from the server operator. DDRop shows that this promise can fail when an attacker can tamper with the …
Telegram Desktop Flaw Lets Attackers Steal Chat Messages Through Poisoned HTML Exports
A high-severity Telegram Desktop vulnerability let attackers hide JavaScript in bot-created inline keyboard buttons and steal chat content when victims exported conversations as HTML files. Telegram fixed the issue in …
