Attackers are actively exploiting WordPress CVE-2026-87902, a critical vulnerability that could enable remote code execution. Administrators are advised to update affected versions.
Security researchers have found the third-party.com placeholder domain serving ClickFix malware lures, affecting users through fake verification pages and malicious commands.
Researchers have disclosed GPUThor, a new Rowhammer attack that bypasses ECC protections on select NVIDIA GDDR6 GPUs, enabling denial of service and host privilege escalation under specific conditions.
Security researchers have disclosed a two stage exploit chain affecting Unisoc chipsets that can achieve Android kernel access through VoLTE video calls with no vendor patch currently available.
A security researcher has released a proof of concept for ShieldBreak, a new Microsoft Defender zero day that reportedly bypasses the RoguePlanet patch and enables SYSTEM level privilege escalation.
Explore how AI agents are creating new cybersecurity risks by exploiting legitimate credentials, infrastructure, and enterprise tools, prompting organizations to rethink security, governance, and AI oversight.
A newly disclosed Linux kernel vulnerability tracked as CVE 2026 64531 allows local users to gain root privileges through Open vSwitch. Security updates are available for affected kernel versions.
Researchers have disclosed DirtyClone, a Linux kernel vulnerability tracked as CVE 2026 43503 that enables local privilege escalation by corrupting cached memory through cloned network packets.
CISA adds CVE 2026 54420 affecting LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities catalog, warning of root privilege escalation risks on shared hosting servers.
Security researchers have published public exploits for Linux kernel vulnerability CVE 2026 23111, allowing local privilege escalation to root and container escape on affected systems.
Google has released its June 2026 Android security update addressing 124 vulnerabilities, including an actively exploited high severity flaw affecting Android 14, 15, and 16 devices.
New cybersecurity research highlights how vulnerable Windows kernel mode drivers may remain exploitable without dedicated hardware, raising concerns around BYOVD attacks and endpoint security risks.
Security researchers have disclosed new Windows zero day vulnerabilities affecting BitLocker and CTFMON, exposing privilege escalation and encryption bypass risks across Windows 11 and Windows Server systems.
Dirty Frag Linux kernel vulnerability enables local privilege escalation to root across major distributions including Ubuntu, RHEL, Fedora, and CentOS, with active exploitation risk.