Critical vm2 Flaw Lets Attackers Escape Node.js Sandbox and Execute Arbitrary Code (CVE-2026-22709)
A serious security vulnerability has been discovered in vm2, a popular JavaScript sandbox library widely used in…
continue reading..
U.S. Charges Dozens in Nationwide ATM Jackpotting Scam Tied to Millions in Losses
The U.S. Department of Justice (DoJ) has taken another major step in dismantling a sprawling international criminal…
continue reading..
New Deepfake Phishing Attacks via Zoom and Microsoft Teams Target Bitcoin Users
A new and highly sophisticated deepfake phishing attack is actively targeting Bitcoin and cryptocurrency users through video…
continue reading..
Legacy Telnet Service Under Fire: CISA Adds CVE-2026-24061 to KEV After Active Exploitation
CVE-2026-24061 is a critical authentication bypass vulnerability affecting the GNU InetUtils telnetd service. When exploited, it allows…
continue reading..
CISA Flags Years-Old Linux Privilege Escalation Bug as Actively Exploited, Adds CVE-2018-14634 to KEV Catalog
CVE-2018-14634 is a local privilege escalation vulnerability in the Linux kernel that was originally published in 2018.…
continue reading..
SmarterMail Authentication Bypass Added to CISA KEV as Active Exploitation Intensifies(CVE-2026-23760)
CVE-2026-23760 is a critical authentication bypass vulnerability affecting SmarterMail, the email and collaboration server developed by SmarterTools.…
continue reading..
Microsoft Office Zero-Day CVE-2026-21509 Actively Exploited, Allows Attackers to Bypass Built-In Security Protections
CVE-2026-21509 is a security feature bypass vulnerability in Microsoft Office that allows an attacker to circumvent Office…
continue reading..
New Linux Kernel Flaws Allow Remote System Crashes and Guest-Triggered Host Denial-of-Service
Product: Linux KernelAffected Scope: Core kernel subsystems, networking, virtualization, storage, and device driversAttack Surface: Local, guest-to-host, network…
continue reading..
WordPress Privilege Escalation Flaw Exposes Sites to Full Admin Takeover (CVE-2025-14866)
CVE-2025-14866 is a high-impact privilege escalation vulnerability affecting the Melapress Role Editor WordPress plugin (versions ≤ 1.1.1).The…
continue reading..
