Google’s Threat Analysis Group found a critical Zimbra XSS vulnerability in the Classic Web Client that lets a crafted email hijack a live session. Zimbra has patched it in version …
News
-
-
An exposed criminal server reveals exactly which plugin flaws powered a mass WordPress webshell attack. Use this checklist to check your own sites now.
-
A local Windows Defender vulnerability, CVE-2026-50656, let any logged-in user reach SYSTEM for nearly 29 days before Microsoft shipped a fix.
-
GhostLock’s real lesson isn’t the bug, it’s the eleven weeks most businesses spent unpatched after the fix shipped. Linux kernel patching needs urgency.
-
BeyondTrust has fixed two pre-authentication bypass flaws in Remote Support and Privileged Remote Access. Here is a practical checklist for IT teams still running self-hosted appliances.
-
A 16-year-old hypervisor escape vulnerability in Linux KVM shows guest isolation is an assumption, not a fact. Here’s why that should change how you scope security testing.
-
What happens during a thick client penetration test, what testers find most often, and how to choose a provider.
-
A US county paid roughly $1 million to a group that never encrypted a single file, exposing how far data-theft extortion has moved beyond classic ransomware.
-
Researchers at JFrog traced a fresh npm supply chain attack to North Korea’s Lazarus group, six lookalike packages built to steal developer credentials and cloud keys.
-
A newly exploited SharePoint server vulnerability lets low-privilege accounts run code on your server. Here’s how to check exposure and patch it this week.