Sitemap
All pages on Hacker Posts.
Home
Newsroom
- Estée Lauder confirms Oracle EBS zero-day breach in Cl0p campaign
- Arctic Wolf ties CVE-2026-0257 GlobalProtect bypass to Qilin ransomware
- ServiceNow CVE-2026-6875: pre-auth sandbox escape RCE now exploited
- Windows VMSwitch CVE-2026-57092: CVSS 9.9 guest-to-host escape in Hyper-V
- Zimbra 10.1.20 patches critical command injection plus three CVEs
- FortiSandbox: CVE-2026-25089 and CVE-2026-39808 land in KEV, exploited
- AD FS zero-day CVE-2026-56155: Microsoft DART finds DKM ACL bug already exploited
- WordPress patches wp2shell pre-auth RCE in 7.0.2 and 6.9.5
- Zoom Workplace on Windows: CVE-2026-53412 lets a network attacker take an account
- LegacyHive drops Windows profsvc zero-day PoC after Patch Tuesday
- SonicWall SMA1000 zero-days chained: CISA adds CVE-2026-15409 and 15410 to KEV
- CISA adds SharePoint CVE-2026-56164 to KEV, chained with two prior bugs
- SonicWall SMA1000 CVE-2026-15409/15410 chained in the wild, KEV
- SAP patches NetWeaver ABAP memory corruption (CVE-2026-44747, CVSS 9.9)
- EU + UK ship first joint cyber sanctions on Russia — FSB Centre 16 and Turla named
- Zimbra 10.1.19 patches Classic Web Client stored XSS, TAG-reported
- Two more Joomla extensions hit CISA KEV: iCagenda and Balbooa Forms
- GhostLock (CVE-2026-43499): 15-year rtmutex UAF gives root on every Linux distro
- Tenda routers ship a hidden backdoor password — CVE-2026-11405 unpatched
- Ubiquiti UniFi Connect CVE-2026-50746 (10.0): SAB-066 lands 25 flaws
- Two Joomla page-builder RCEs hit CISA KEV, remediation due today
- Gitea CVE-2026-20896: Docker image trusts X-WEBAUTH-USER from anywhere
- Microsoft patches Defender RoguePlanet LPE CVE-2026-50656
- Januscape (CVE-2026-53359): 16-year-old KVM UAF escapes VMs on Intel and AMD
- Langflow CVE-2026-55255 IDOR added to CISA KEV, patch to 1.9.2
- Adobe ColdFusion CVE-2026-48282 hits honeypots within hours of writeup
- Cisco Catalyst Center CVE-2026-20191: unauth arbitrary file read
- Cursor DuneSlide: two critical sandbox escapes in the AI IDE (CVE-2026-50548 / -50549)
- JetBrains Hub ships 2026.1.13757 patching two critical auth-bypass CVEs
- Bad Epoll CVE-2026-46242: Linux epoll race lifts any user to root
- runZero drops seven FatFs CVEs; only CVE-2026-6684 fixed in R0.16
- Oracle EBS Payments CVE-2026-46817 exploited before any public PoC existed
- Citrix CTX696604: six NetScaler CVEs, CVE-2026-8451 leaks memory
- CISA adds SharePoint CVE-2026-45659 to KEV, FCEB deadline July 4
- Adobe ships APSB26-68 out of band: 11 ColdFusion CVEs, six at CVSS 10
- Progress LoadMaster CVE-2026-8037: pre-auth root RCE, PoC-ready diff
- OpenAM 16.1.1 patches 10+ CVEs as wodzen coordinated disclosure rolls out
- CISA adds SimpleHelp CVE-2026-48558 to KEV after OIDC bypass exploited
- FBI: Russian intel now phishes Signal Backup Recovery Keys
- Linux pedit COW CVE-2026-46331: page-cache LPE PoC drops in 24h
- macOS.Gaslight: DPRK Rust implant attacks LLM-based malware triage
- Ubiquiti UniFi OS: three chained CVSS 10.0 flaws hit CISA KEV (CVE-2026-34908/34909/34910)
- Linux DirtyClone CVE-2026-43503: working LPE PoC from JFrog
- Lantronix EDS5000 CVE-2025-67038 in CISA KEV — patch deadline is today
- PTC Windchill CVE-2026-12569 in CISA KEV — federal patch deadline June 28
- Cisco Unified CM CVE-2026-20230 now drops webshells via Tor
- Symantec ties new Mistic backdoor to ransomware broker KongTuke
- DifyTap: four cross-tenant flaws hit Dify, one still unpatched
- Squidbleed: 29-year-old Squid FTP gateway leaks heap memory (CVE-2026-47729)
- Splunk Enterprise CVE-2026-20253: KEV-listed unauthenticated RCE via PostgreSQL sidecar
- Texas Parks & Wildlife vendor breach hits 3M license holders
- Node.js ships June 18 security release — 12 CVEs across v22, v24, v26
- Gravity SMTP CVE-2026-4020: API keys leaked, 17M exploit attempts
- JetBrains pulls 15 plugins exfiltrating AI API keys, 70K installs
- SurrealDB 3.1.5 patches five flaws; lead is a HIGH file read
- FortiBleed dumps 73,932 Fortinet firewall creds; CISA orders resets
- NGINX 1.31.2 / 1.30.3 patches HTTP/3 UAF (CVE-2026-42530) and two more
- Mastra npm scope hijacked: 142 packages backdoored via easy-day-js
- Cisco SD-WAN Manager CVE-2026-20262 exploited, KEV-added
- CISA adds JCE Joomla CVE-2026-48907 to KEV — pre-auth RCE, CVSS 10
- LiteSpeed cPanel CVE-2026-54420 in KEV: symlink path to root, second LiteSpeed cPanel KEV in 3 weeks
- Chrome ships fix for V8 zero-day CVE-2026-11645, CISA adds to KEV
- CISA gives feds 3 days to patch Ivanti Sentry CVE-2026-10520
- Fortinet patches unauth command injection in FortiSandbox (CVE-2026-25089)
- Langflow CVE-2026-5027 exploited; fix shipped but unlabelled
- Everest Forms Pro CVE-2026-3300 exploited since April 13 to plant rogue admins
- Oracle PeopleSoft zero-day CVE-2026-35273 hits 100+ orgs
- Arista EOS CVE-2026-7473 added to CISA KEV — vendor says no patch coming
- Microsoft June 2026 Patch Tuesday: 3 publicly disclosed zero-days
- Veeam patches critical RCE in Backup & Replication (CVE-2026-44963)
- Check Point patches IKEv1 VPN bypass CVE-2026-50751, exploited since May
- Linux nf_tables CVE-2026-23111: full LPE chain now public via Exodus
- CISA adds SolarWinds Serv-U CVE-2026-28318 to KEV, DoS in the wild
- Anthropic patches Claude Code GitHub Action repo-takeover chain
- Cisco SD-WAN Manager CVE-2026-20245 exploited, no patch yet
- VS Code github.dev zero-day exposed full GitHub OAuth tokens in one click
- CISA adds Oracle WebLogic CVE-2024-21182 to KEV catalog
- Android Framework zero-day CVE-2025-48595 added to CISA KEV
- HTTP/2 Bomb (CVE-2026-49975) drops nginx, Apache, IIS, Envoy
- Red Hat npm packages backdoored: Miasma worm hits @redhat-cloud-services
- Windows Netlogon RCE CVE-2026-41089 now exploited in the wild
- CIFSwitch: 19-year-old Linux CIFS bug gives any local user root
- Marimo CVE-2026-39987 RCE chains into LLM-driven post-exploit
- npm supply-chain campaign: 14 typosquats target AWS, Vault, npm tokens
- Palo Alto GlobalProtect auth bypass (CVE-2026-0257) added to CISA KEV after weeks of exploitation
- FortiClient EMS bug CVE-2026-35616 now drops EKZ stealer as fake patch
- CISA links GitHub repo exfiltration to malicious Nx Console 18.95.0
- Gitea CVE-2026-27771: anyone could pull your private container images, no login
- Starlette BadHost (CVE-2026-48710): one Host header bypasses auth in FastAPI, vLLM, MCP
- KnowledgeDeliver CVE-2026-5426: Mandiant traces RCE to shared ASP.NET keys
- CISA flags Langflow CVE-2025-34291: CORS chain yields RCE
- Ghost CMS SQLi (CVE-2026-26980) hijacks 700+ sites — Harvard, Oxford, DuckDuckGo serve ClickFix
- Trend Micro Apex One CVE-2026-34926 exploited; CISA deadline June 4
- Canvas LMS breach: ShinyHunters claims 275M records; Instructure says it paid for deletion
- Drupal patches highly critical SQL injection (CVE-2026-9082) — exploited in the wild within 48h
- Laravel-Lang Composer packages hijacked — 700+ versions ship a credential stealer
- LiteSpeed cPanel plugin RCE (CVE-2026-48172, CVSS 10.0) actively exploited — any cPanel user can run code as root