A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company said on September 22. A second bug in...
Autonomous security agents are getting good at finding bugs. Nobody has a good way to measure how good. Point one at a realistic target and what comes back is a report the agent wrote about...
Anthropic and OpenAI on Tuesday announced new models, with both artificial intelligence (AI) companies noting that they are continuing to invest in improving alignment to combat risky behavior....
A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22. The...
Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only...
A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected...
Authorization bypass through User-Controlled key vulnerability (CVE-2026-92419) has been found in WEBCON BPS software.
Regulator wants to know whether parent Aylo did its homework before reopening the door to UK iPhone users
Meta says it issued a fix for the Muse zero-day vulnerability that would have let attackers do “whatever” they wanted on a victim’s Mac, highlighting the inherent dangers of AI helpers.
A new security vulnerability in Next.js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said. The...
CERT Polska uncovered a toll fraud operation targeting Polish users through deceptive Meta advertisements and malicious applications distributed via Google Play. We preserved 1235 ads, linked 852...
New paper: “Self-Jailbreaking: Language Models Can Reason Themselves Out of Safety Alignment After Benign Reasoning Training.” Abstract: We discover a novel and surprising phenomenon of...
The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency....
Pro-Iran hackers who have claimed to have hit Western companies including eBay, Spotify, X, Bluesky, Airbnb, Target and more with DDoS attacks since the start of the Iran war recently have focused...
SPONSORED EXPLAINER: Merging security into the network makes enterprise protection more agile
The National Capital Commission (NCC) says it has confirmed a privacy breach involving its website. The breach happened on Aug. 28, the NCC said. “An unauthorized party accessed information...
The Securities Board of Nepal (SEBON) has launched a high-level probe into the suspension of share trading after a ransomware attack disrupted the Data Hub server, affecting 72 out of Nepal’s 92...
An Armenian citizen extradited from Ukraine was sentenced Tuesday to two years in federal prison for his role in a ransomware scheme that targeted companies in the United States, including one in...
Quest Apartments has advised customers affected by a data breach in August to replace their passports and driver's licences after its investigation revealed additional information had been leaked....
What HappenedOn 25 August 2026, Manchester Airports Group (MAG), the operator of Manchester Airport, London Stansted Airport, and East Midlands Airport, reported they recently suffered data...