SAP Rushes Emergency Security Updates For Critical Commerce Cloud & S/4HANA Vulnerabilities post, mei 13, 2026mei 18, 2026 German enterprise software giant SAP has released a sweeping set of security updates addressing multiple vulnerabilities across its enterprise software ecosystem, including two critical flaws affecting its flagship Commerce Cloud and S/4HANA platforms — systems widely used by multinational corporations, government agencies, manufacturers, retailers, and financial institutions worldwide. The May… Continue Reading
Critical Flaw In Apache HTTP Server Enables DoS & Remote Code Execution (RCE) Attacks post, mei 6, 2026mei 13, 2026 A newly disclosed high-severity vulnerability in the widely used Apache HTTP Server is prompting urgent warnings from cybersecurity experts, after researchers demonstrated that the flaw could be exploited to trigger denial-of-service (DoS) attacks and, under certain conditions, achieve remote code execution (RCE). The issue, tracked as CVE-2026-23918, carries a CVSS… Continue Reading
Critical Palo Alto PAN-OS Vulnerability Actively Exploited For Remote Code Execution (RCE) post, mei 6, 2026mei 13, 2026 Cybersecurity firm Palo Alto Networks has issued an urgent security advisory warning customers of an actively exploited zero-day vulnerability affecting its widely deployed firewall operating system, PAN-OS. The flaw, identified as CVE-2026-0300, has been classified as critical, with CVSS score of 9.3 and allows attackers to gain full control of… Continue Reading
Microsoft Edge Stores Passwords In Memory As Plaintext post, mei 5, 2026mei 6, 2026 An attacker who has administrative privileges can access Microsoft Edge user passwords—even when they aren’t actively being used—because the browser keeps them in cleartext within process memory as part of a design choice by Microsoft. A newly disclosed cybersecurity finding has raised concerns among IT professionals and enterprise administrators after… Continue Reading
WARNING: New Linux Vulnerability Enables Root Access Across Every Major Linux Distribution post, april 30, 2026mei 1, 2026 A newly disclosed security flaw in the Linux kernel is raising serious concerns across the cybersecurity community, after researchers revealed that it can grant full root access on a wide range of systems with remarkable reliability. The vulnerability—tracked as CVE-2026-31431 and dubbed “Copy Fail”—affects Linux kernel versions released over nearly… Continue Reading
Major Security Flaw In GitHub Enables Remote Code Execution Across Millions of Repositories post, april 28, 2026april 29, 2026 A critical vulnerability discovered within GitHub’s internal infrastructure has raised serious concerns across the global software development community, after researchers revealed it could allow attackers to execute arbitrary code on backend systems using a single command. The flaw, tracked as CVE-2026-3854, was identified by Wiz Research and affects both GitHub’s… Continue Reading
Critical Vulnerability Exposes Linux Systems To Root-Level Takeover post, april 25, 2026april 29, 2026 A newly disclosed security flaw affecting Linux systems has raised fresh concerns about the integrity of core package management infrastructure, after researchers revealed that a vulnerability lurking for over a decade could allow attackers to escalate privileges and gain root-level control. The flaw, dubbed “Pack2TheRoot,” has been formally tracked as… Continue Reading
FIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security Patches post, april 24, 2026mei 18, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has revealed that an unnamed federal civilian agency’s Cisco Firepower device running Adaptive Security Appliance (ASA) software was compromised in September 2025 with a new malware called FIRESTARTER. FIRESTARTER, per CISA and the U.K.’s National Cyber Security Centre (NCSC), is assessed to be a backdoor… Continue Reading
North Korea’s Lazarus Targets macOS Users via ClickFix post, april 24, 2026april 29, 2026 North Korea’s Lazarus Group is using ClickFix attacks to launch cyberattacks using novel macOS malware. That’s according to security vendor Any.Run, which on April 21 published research concerning a new nation-state threat campaign. Authored by offensive security expert and Birmingham Cyber Arms founder Mauro Eldritch, the report covers a wave… Continue Reading
Hackers claim control over Venice San Marco anti-flood pumps post, april 12, 2026april 13, 2026 Hackers breached Venice ’s San Marco flood system, claiming control of pumps and the ability to disable defenses and flood coastal areas. The technologies that govern the physical world are the quiet infrastructure of modern life. From energy grids to water systems, from factories to flood defenses, operational technology (OT)… Continue Reading