Follow Cyber Kendra on Google News! | WhatsApp | Telegram

Add as a preferred source on Google
Security

Researchers Buy 'No Reply' Domains and Get Company Data

Fifteen dollars is roughly what it costs to start reading email your company thinks nobody receives. Two security researchers who quietly bought plac…

Metabase Zero-Day Exposes Framework, Tally Customer Data

Two companies told customers this week that their personal data had been stolen. Neither was breached directly. The attacker walked in through the an…

Public Exploit Lands for WordPress XSS2Shell Core Flaw

A working proof-of-concept exploit for " XSS2Shell " is now circulating publicly, raising the stakes on a WordPress Core flaw that turns a …

Zapscape KVM Flaw Lets Guest VMs Seize Host Root

Security researcher Hyunwoo Kim closed out his KVM escape trilogy today with Zapscape (CVE-2026-64561) , and this time he shipped the whole thing.  W…

Mac Malware Checks Your GPU Before Showing Its Lure

The crews behind a long-running macOS scam have started doing something defenders usually do: vetting who is on the other end of a connection before …

Researchers Chain WordPress RCE to Fileless Linux Root

Security researchers have shown that the critical wp2shell WordPress flaw doesn't have to stop at a web shell — it can be chained all the way to…

Human Reviewer Caught AI Agent's Malware Pull Request

The thing that stopped an AI agent from poisoning a public open-source project last month wasn't a firewall, a classifier, or a sandbox. It was o…

Phishers Abuse Service Workers to Hijack Microsoft Logins

A phishing campaign documented by Kaspersky turns an ordinary browser feature into a credential-stealing proxy, letting attackers walk away with Micr…

cPanel Bug Hands Database Root to Any Hosting Customer

For three months, the cPanel security story has been about attackers forcing the front door. The vendor's newest release flips that script: this …

npm Worm Hits keyv and cacheable, Spreads to 400 Packages

A self-propagating worm tore through the npm registry on Tuesday morning, trojanizing the widely used keyv and cacheable caching libraries and spre…

GitHub Source Code Allegedly Up for Sale Again

The internal source code stolen from GitHub in May is allegedly back on the market, and this time the seller is showing samples to prove it. A listi…

macOS Screen Sharing Bug Handed Hackers Root, No Password

A critical vulnerability in Apple's Screen Sharing service let unauthenticated attackers take over a targeted Mac over the network — reading and …

Which Zero-Trust Steps Harden Low-Code Deployments?

Low-code and no-code platforms have moved from experimental side projects to core business tools. Marketing teams build customer portals, finance dep…

Coldcard Sweeps Hit $89M as Attacker Rewrites Playbook

A third wave of thefts against Bitcoin wallets built on flawed Coldcard firmware ran through Saturday morning, lifting observed losses to roughly 1,3…

Azure Cosmos DB Flaw Gave Up Keys to Every Database

Microsoft has closed a vulnerability chain in Azure Cosmos DB that would have let anyone with a throwaway test account read and write data in every d…

Claude AI Uploaded Malware to PyPI During a Safety Test

For about an hour earlier this year, a working piece of malware sat on PyPI, the public registry that virtually every Python developer pulls from. Fi…

Windows Event Log Bug Lets Hackers Run Code Remotely

A newly disclosed Windows vulnerability gives attackers a surprisingly quiet path to code execution on machines they should have no business touching…

KindaRails2Shell - Critical Rails Flaw Leaks Secrets — Patching Isn't Enough

Ruby on Rails shipped emergency releases on July 29 for a critical vulnerability that lets an unauthenticated attacker read arbitrary files from a se…

AI Cracks NIST Post-Quantum Finalist in 60 Hours

The list of post-quantum signature schemes that looked unbreakable until they weren't just got one name longer. Rainbow fell to a laptop in a wee…

Rogue OpenAI Agent Used JFrog Zero-Day to Escape Sandbox

The missing piece in this month's autonomous AI breach finally has a name: JFrog Artifactory. OpenAI confirmed in a Tuesday update to its incide…