North Korea–Linked Lazarus Group Deploys Medusa Ransomware in Targeted Healthcare and Nonprofit Extortion Campaigns
In early 2026, new threat analysis revealed that the North Korean state-linked Lazarus cyber-espionage and cybercrime organization…
continue reading..
ShinyHunters Claims Massive Odido Data Breach, Threatens to Leak Millions of Customer Records
A notorious cybercrime group claiming to be ShinyHunters has asserted responsibility for a major data breach at…
continue reading..
SolarWinds Patches Severe Serv-U Bugs Allowing Full Server Compromise
Recently, SolarWinds released urgent security updates to address multiple critical security flaws in its Serv-U file transfer…
continue reading..
Children’s Data Failures Cost Reddit £14.47 Million in UK Penalty
The United Kingdom’s Information Commissioner’s Office (ICO) has issued a £14.47 million fine to social media company…
continue reading..
CVE-2026-27464: Metabase Flaw Lets Low-Privilege Users Steal Database Credentials via Notification Templates
CVE-2026-27464 — Metabase Credential Exposure Vulnerability CVE Name: Credential Extraction via Notification Template EvaluationCVE ID: CVE-2026-27464CVSS v3.1…
continue reading..
CVE-2026-27471: Critical ERPNext Access Control Flaw Exposes Sensitive Business Documents to Remote Attackers
CVE-2026-27471 Product: ERPNext (Open Source ERP Tool)Vulnerability Type: Access Control Bypass / Unauthorized Document AccessAttack Vector: Remote…
continue reading..
CRITICAL MOODLE RCE ALERT: CVE-2026-26045 & CVE-2026-26046 Enable Full Server Takeover Through Backup Restore and Admin Command Injection
Moodle Security Advisory Product: Moodle LMSVendor: Moodle Pty LtdAffected Components: Impact: Remote Code Execution (RCE), Command InjectionRisk…
continue reading..
CVE-2026-27487: OpenClaw CLI Command Injection Flaw Enables Local System Compromise on macOS
CVE-2026-27487 Product: OpenClaw CLI (macOS keychain integration)Vulnerability Type: OS Command Injection (CWE-78)CVSS v3.1 Score: 7.6 (High)Severity: HighAttack…
continue reading..
CVE-2026-27168: Critical Heap Overflow in SAIL Image Library Opens Door to Remote Code Execution
CVE-2026-27168 CVE ID: CVE-2026-27168Product: SAIL (Simple and Flexible Image Library)Affected Component: XWD image codec (sail-codecs-xwd)Vulnerability Type: Heap-Based…
continue reading..
