A chain of five vulnerabilities in the Markdown Preview Enhanced VS Code extension let a crafted markdown file write to files on a developer’s machine. All five are now patched.
News
-
-
A critical Forminator plugin vulnerability lets attackers upload malicious files without logging in. Here is a quick checklist to find out if your site is exposed.
-
A single attacker has spent 17 months scraping Salesforce and ServiceNow customer portals worldwide, not by exploiting a flaw but by using guest user permissions exactly as they were configured.
-
The critical NetScaler authentication bypass, CVE-2026-19490, was routine to fix. The pattern behind it, of gateway appliances patched on a normal cycle, is the real risk.
-
A researcher-recovered toolkit shows how one operator compromised over 14,500 Dahua cameras in five weeks using credential attacks, a decade-old auth bypass, and abuse of the vendor’s own cloud relay.
-
A record 93 active ransomware groups sounds alarming, but Q2 2026 data suggests ransomware market fragmentation is a sign of pressure, not strength.
-
Two chained Microsoft SharePoint flaws, patched in July and August, let an attacker take over an on-premises server without any credentials at all.
-
Attackers weaponised a VMware vCenter flaw within five days of disclosure. That speed should change how businesses think about critical patching.
-
N-able’s patch for its N-central platform didn’t fully close the door attackers used. Here is the step-by-step check for anyone running it, beyond just installing the update.
-
Veeam, HashiCorp’s Terraform MCP Server and Django all patched critical flaws within 48 hours, including a CVSS 10.0 bug. Here’s what happened and what to check.