Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

Forkast
forkast.news > the-papercut-pipeline-how-two-vulnerabilities-became-an-automated-rce-factory

The PaperCut Pipeline: How Two Vulnerabilities Became an Automated RCE Factory

21+ hour, 23+ min ago   (148+ words) Two PaperCut vulnerabilities are now chained into a fully automated attack pipeline with in-memory persistence—and 47% of installations can't patch. On August 26, security researchers at Huntress identified anomalous activity in customer logs involving base64-encoded commands like whoami and tasklist. This…...

Forkast
forkast.news > stylesmuggler-turns-adobe-commerces-own-template-engine-into-an-unauthenticated-rce-chain

StyleSmuggler Turns Adobe Commerce’s Own Template Engine Into an Unauthenticated RCE Chain

2+ day, 5+ hour ago   (117+ words) CVE-2026-75650 lets attackers inject PHP through Magento's email template system, then triggers execution automatically. Multiple threat groups are already inside. The authentication gap has reached the payment layer. Simultaneously, a separate attacker group has been observed dropping a 485-byte PHP…...

Thurrott.com
thurrott.com > podcasts > windows-weekly > 341510 > windows-weekly-1000-ensheepified

Windows Weekly 1000: Ensheepified

2+ day, 7+ hour ago   (212+ words) Leo, Richard, and Paul celebrate the 1000th episode of the podcast and discuss Windows 11, IFA, AI and dev, XBOX and gaming and more. Stream this episode and subscribe Enjoy Windows Weekly on YouTube The canary in the coal mine has finally…...

Shattered
shattered.io > microsoft-patch-tuesday-974-bugs-2-zero-days-2026

Microsoft Patch Tuesday: 974 Bugs, 2 Zero-Days [2026]

2+ day, 21+ hour ago   (711+ words) The scale of this release, reported first by CyberScoop and detailed further by Help Net Security, has turned a routine monthly ritual into a stress test for enterprise patch management. Security teams are no longer just racing a clock, they…...

eSecurity Planet
esecurityplanet.com > threats > news-adobe-commerce-cve-2026-75650-stylesmuggler

CVE-2026-75650 Adobe Commerce Zero-Day: Patch Isn't Enough

3+ day, 14+ hour ago   (897+ words) Adobe patched the actively exploited CVE-2026-75650 Magento zero-day, but compromised stores still need malware hunting and broad credential rotation. Adobe has patched CVE-2026-75650, a critical Adobe Commerce and Magento Open Source vulnerability that attackers were exploiting before a fix was…...

Qualys
blog.qualys.com > vulnerabilities-threat-research > 09/08/2026 > microsoft-patch-tuesday-september-2026-security-update-review

Microsoft and Adobe Patch Tuesday, September 2026 Security Update Review

3+ day, 13+ hour ago   (356+ words) This Patch Tuesday is Microsoft’s largest security update ever, marking a significant increase over other recent massive releases, including the 570 security flaws fixed in July and 400 fixed in August. Qualys InstaScan posted detections for ETM Agent Insta-enabled customers 13 mins after…...

Tech Times
techtimes.com > articles > 327116 > 20/26/0909 > september-2026-patch-tuesday-zdi-ranks-exchange-server-20-wormable-bugs-ahead-zero-days.htm

September 2026 Patch Tuesday: ZDI Ranks Exchange Server and 20 Wormable Bugs Ahead of Zero-Days

3+ day, 12+ hour ago   (605+ words) The Exchange Server situation warrants front-of-queue treatment over the two named zero-days. CVE-2026-55007 allows a remote, unauthenticated attacker to execute code on an affected Exchange server by sending an email containing a malicious Visio attachment. The code runs when the…...

The Hacker News
thehackernews.com > 2026 > 09 > four-spy-groups-used-same-chrome-and.html

Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

3+ day, 10+ hour ago   (594+ words) The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo, PerplexedGoblin, RedBravo, TA412, Tide Castle, and Violet Typhoon) on August 28, 2026. "Within days, several other espionage-motivated clusters began using BlueMoon,…...

Cyber Security News
cybersecuritynews.com > maplibre-zero-click-vulnerability

MapLibre Vulnerability Exposes 2.7M Users to Zero-Click Attacks

3+ day, 17+ hour ago   (310+ words) A critical cross-site scripting vulnerability in the widely used MapLibre GL JS library could expose applications and an estimated 2.7 million users to zero-click attacks. This created an index-shifting condition: once an attribute was removed, the next attribute moved into its…...

HostingAdvice.com
hostingadvice.com > blog > a-critical-whmcs-rce-just-got-patched-did-you-update > amp

A Critical WHMCS RCE Just Got Patched. Did You Update?

3+ day, 16+ hour ago   (642+ words) Lillian Castro, Senior Editor Lillian Castro brings more than 30 years of editing and journalism experience to our team. She has written and edited for major news organizations, including The Atlanta Journal-Constitution and the New York Times, and she previously served…...