Russian Hackers Target Poland’s Power Grid in Failed Wiper Malware Attack
In late December 2025, Poland’s critical energy infrastructure narrowly escaped a crippling cyberattack that targeted its power…
continue reading..
Microsoft Shared BitLocker Encryption Keys With FBI in Guam Pandemic Fraud Investigation
Microsoft has confirmed that it provided the Federal Bureau of Investigation with BitLocker recovery keys that allowed…
continue reading..
Microsoft Warns of Sophisticated Multi-Stage AiTM Phishing and BEC Campaign Exploiting SharePoint to Breach Multiple Organizations
The threat actors behind this campaign targeted multiple organizations primarily in the energy sector, starting with phishing…
continue reading..
Microsoft’s WinAppCli: A Unified CLI for Windows App Development
In early 2026, Microsoft introduced WinAppCli, an open-source command-line interface aimed at simplifying the process of building,…
continue reading..
Unsecured Database Leaks 149 Million User Credentials Across Major Platforms
A huge database of login credentials — nearly 149 million usernames and passwords — was found publicly…
continue reading..
CVE-2025-53967: Unauthenticated Command Injection Leading to Full Remote Code Execution in Framelink Figma MCP Server
Vulnerability Overview Executive Summary A high-severity command injection vulnerability exists in the Framelink Figma MCP Server. Due…
continue reading..
CVE-2026-0756: Unauthenticated Remote Code Execution via Command Injection in github-kanban-mcp-server
Vulnerability Summary CVE ID: CVE-2026-0756Component: github-kanban-mcp-server (@sunwood-ai-labs/github-kanban-mcp-server)Vulnerability Type: OS Command InjectionAttack Class: Unauthenticated Remote Code ExecutionSeverity: CriticalCVSS…
continue reading..
CVE-2026-0764: Critical Unauthenticated Deserialization RCE in GPT Academic Leading to Root-Level System Compromise
Top-Level Summary Vulnerability Background This issue arises because the GPT Academic application accepts serialized data uploaded by…
continue reading..
CVE-2026-0768: Unauthenticated Langflow RCE Enables Full Server Takeover
CVE-2026-0768 – Langflow Unauthenticated Remote Code Execution CVE ID: CVE-2026-0768Product: LangflowVulnerability Type: Unauthenticated Remote Code Execution (RCE)Severity:…
continue reading..
