Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now!

6 days ago

7-Zip fixed a vulnerability that could let attackers run code by tricking users into opening malicious XZ-compressed archive files. 7-Zip…

CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers

6 days ago

F5 fixes critical nginx flaw CVE-2026-42533 that can crash servers and, in some cases, allow remote code execution through crafted…

AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign

6 days ago

Hugging Face says an autonomous AI agent breached part of its production infrastructure and accessed internal data and service credentials.…

Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances

6 days ago

Unknown hackers exploited two SonicWall SMA 1000 zero-days to gain root access on VPN appliances before patches became available. Volexity…

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 106

6 days ago

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware…

Security Affairs newsletter Round 586 by Pierluigi Paganini – INTERNATIONAL EDITION

6 days ago

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs…

Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits

7 days ago

Public exploits are now available for two critical WordPress flaws that attackers can chain to gain remote code execution without…

OpenSSL Fixes HollowByte Memory Exhaustion Bug

1 week ago

Okta disclosed HollowByte, an 11-byte OpenSSL flaw that lets remote attackers exhaust server memory and trigger denial-of-service attacks. Okta's Red…

Daxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer’s Network

1 week ago

Researchers found China's Daxin rootkit and a new Stupig backdoor on a Taiwan firm's network, suggesting a stealthy intrusion dating…

U.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog

1 week ago

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog.…

This website uses cookies.