A PaperCut vulnerability chain let attackers bypass login and run code on print servers, and the vendor needed a second emergency patch after the first one was bypassed.
News
-
-
Two quotes, two different labels: one for “ethical hacking”, one for a “penetration test”. Here’s how to tell what you’re actually buying before you sign.
-
The NCSC has warned about internet-exposed edge devices three times since April. The failures are basic. The problem is nobody owns fixing them.
-
CVE-2026-21962 scores a perfect 10 on the CVSS scale and has been under active, automated attack since January. Here’s what it does and how to check if you’re exposed.
-
A critical Keycloak password reset flaw let unauthenticated attackers seize any account, admins included. Here is what happened and what to patch now.
-
WilmerHale paid at least $18 million and Goodwin Procter around $10 million to the Luna Moth extortion group, which broke in using phone calls and fake IT visits rather than …
-
A chain of five vulnerabilities in the Markdown Preview Enhanced VS Code extension let a crafted markdown file write to files on a developer’s machine. All five are now patched.
-
A critical Forminator plugin vulnerability lets attackers upload malicious files without logging in. Here is a quick checklist to find out if your site is exposed.
-
A single attacker has spent 17 months scraping Salesforce and ServiceNow customer portals worldwide, not by exploiting a flaw but by using guest user permissions exactly as they were configured.
-
The critical NetScaler authentication bypass, CVE-2026-19490, was routine to fix. The pattern behind it, of gateway appliances patched on a normal cycle, is the real risk.