Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Critical Spring Security Flaw Lets Attackers Gain Admin Access to LDAP Servers
3+ day, 22+ hour ago (311+ words) A critical vulnerability in Spring Security’s embedded UnboundID LDAP server can allow remote attackers to gain administrative access to exposed in-memory LDAP directories. The flaw was published on August 20, 2026, and carries a critical severity rating. It can be exploited remotely…...
T-Mobile Cyber Team Physically Cuts Cable to Remove Chinese Hackers From Network
5+ day, 2+ hour ago (538+ words) T-Mobile’s security team resorted to an unusually low-tech fix for a high-tech problem in 2024, physically severing a network cable to cut off Chinese state-backed hackers’ access to its systems, according to new reporting from Bloomberg. The dramatic move came amid…...
Critical WordPress Plugin Vulnerability Exposes 600,000 Sites to File Upload Attacks
6+ day, 21+ hour ago (411+ words) A critical security flaw in the Forminator Forms WordPress plugin could allow unauthenticated attackers to upload malicious PHP files, potentially enabling them to take full control of vulnerable websites. The issue, tracked as CVE-2026-15748, affects Forminator Forms versions 1.56.1 and earlier…...
AI Agents Don’t Stop When Malware Fails, They Write Another Tool and Keep Attacking
1+ week, 3+ day ago (698+ words) AI agents are changing the shape of cyberattacks. Instead of relying on a fixed piece of malware, an agent can test an approach, see it fail, write a replacement tool, and continue toward the same goal. Recent incidents show that…...
Sandworm Fake Job Interviews Push Trojanized WireGuard VPN to Infect IT Professionals
1+ week, 5+ day ago (612+ words) Sandworm has turned the routine job interview into a route for compromising IT workers. The campaign uses convincing recruiter conversations, live video calls and a booby-trapped virtual private network client to reach people who may hold privileged access to company…...
Compromised FortiGate VPN Opens First Step in Multi-Network Polish Energy Attack
1+ week, 6+ day ago (543+ words) Poland’s energy sector attack has revealed how one compromised remote-access device can become the first step in a wider industrial intrusion. The campaign moved from a wind-farm network into a heat and power plant, turning trusted connectivity into disruption. The…...
Metabase 0-Day Vulnerability Exploited in the Wild to Gain Admin Access
2+ week, 1+ day ago (408+ words) The flaw carries a maximum CVSS score of 10.0 and impacts every release from version 1.58 onward, spanning branches 0.58 through 0.63. Although no CVE identifier has been assigned as of this writing, the severity and confirmed real-world exploitation make this one of the…...
Meta AI Model Gained Internet Access and Hacked Another Organization's Network
2+ week, 4+ day ago (463+ words) Meta has disclosed that one of its AI models gained unintended access to the internet during a cybersecurity evaluation and then exploited a vulnerability in another organization’s system. The incident occurred during testing conducted with independent AI security firm Irregular,…...
Canadian Man Pleads Guilty for Hacking U.S. Cloud Storage Provider
2+ week, 4+ day ago (352+ words) Connor Riley Moucka, a 26-year-old resident of Kitchener, Ontario, has pleaded guilty in the United States for his role in a major computer hacking and extortion conspiracy. Prosecutors said the campaign compromised more than 165 organizations, exposed billions of sensitive customer…...
CISA Warns of N-able N-central Authentication Bypass Vulnerability Exploited in Attacks
2+ week, 6+ day ago (366+ words) CISA has warned that attackers are actively exploiting a critical authentication bypass vulnerability in N-able N-central. Tracked as CVE-2026-18577, the flaw affects N-central servers running versions earlier than 2026.3.1.7. N-central is a remote monitoring and management platform widely used by managed…...