Cybersecurity News
-
cPanel Fixes Domain Parking Flaw That Could Give Attackers Root Access
cPanel has released security updates to fix a serious vulnerability in its domain parking and addon domain functionality that could allow an authenticated hosting user to gain full control of a server.…
-
Critical Next.js Flaw Leaves Some Windows Servers Open to Remote Code Execution
Developers running certain Next.js applications on Windows are being urged to update after a critical vulnerability was found that could allow attackers to execute code remotely without logging in first. The flaw,…
-
Ring Is Changing How Security Camera Videos Are Encrypted by Default
Ring is introducing a new encryption system for security camera footage that is designed to give customers more control over their recordings while keeping cloud-based features available. Called TAKE, or Throw Away…
-
NVIDIA OpenShell Flaws Put AI Agent Sandboxes at Risk
A pair of near-maximum-severity vulnerabilities in NVIDIA OpenShell could allow attackers to escape an AI-agent sandbox or interfere with how that sandbox is created. Both flaws, CVE-2026-65093 and CVE-2026-65083, carry CVSS scores…
-
Hugging Face Breach Occurred During OpenAI Internal Security Tests
OpenAI has published new details about a July 2026 security incident in which experimental AI agents escaped intended evaluation boundaries, coordinated through unauthorized channels and compromised parts of Hugging Face’s infrastructure. The…
-
WhatsApp Says 1 Billion Users Have Set Up Passwordless Sign-In as It Expands Security Features
WhatsApp said more than 1 billion people have now set up passkeys for their accounts, marking a major adoption milestone for the passwordless sign-in technology. Passkeys allow users to verify their identity…
-
Two Flaws in WordPress Plugin miniOrange SSO Could Allow Admin Takeover
Two critical authentication bypass vulnerabilities in the miniOrange SAML Single Sign On plugin could allow unauthenticated attackers to access affected WordPress sites as existing users, including administrators. Tracked as CVE-2026-61979 and CVE-2026-15981,…
-
Malware Hijacks Android Car Update System for Ad Fraud and Proxy Botnet
Cybersecurity researchers have uncovered malware spreading through the built-in software update system of Android-based car head units, turning infected devices into tools for ad fraud and a proxy botnet. Kaspersky discovered the…
-
Microsoft Defender Driver Can Be Repurposed to Weaken Security Protections
Security researchers have found that a legitimate Microsoft Defender driver can be repurposed to perform highly privileged file and Registry operations, potentially allowing attackers with existing administrator access to weaken security protections.…
