Follow Cyber Kendra on Google News! | WhatsApp | Telegram

Add as a preferred source on Google
Security

Stale GitHub Token Let ChainDrop Worm Poison Keyv, Cacheable

Jared Wray, founder and CEO of Hyphen AI and maintainer of the Keyv and Cacheable npm packages, has published a postmortem confirming that a stale f…

PrettyPrague Zero-Day Exploit Hits Avast Antivirus

A security researcher known as Chaotic Eclipse has released a working proof-of-concept exploit for an unpatched privilege escalation vulnerability i…

Virtualizor Compromised via BGP Hijack, Hosts Hit Hard

A BGP hijack against Virtualizor's update infrastructure pushed a malicious package onto VPS hypervisors running the panel, handing attackers roo…

cPanel Patches CVE-2026-65643 Root Code Execution Flaw

cPanel has patched CVE-2026-65643 , a flaw in its domain parking and addon domain functionality that lets an ordinary hosting customer write files an…

Next.js Patches Two Critical RCE Flaws in 15.5.24, 16.3.3

Vercel has patched two critical remote code execution flaws in Next.js: one that triggers when the framework optimizes an attacker-supplied AVIF imag…

Core Lightning Vulnerabilities Prompt CLN Offline Warning

Blockstream’s Core Lightning team has told node operators to install an embargoed security build or shut their nodes down, after a run of AI-generate…

Signal Contact Discovery Enclave Flaws Allow Code Execution

Security research firm V12 has disclosed two vulnerabilities in Signal's Contact Discovery Service that allowed the untrusted server host to bre…

Log4j Deserialization Bypass Is Real but Not Log4Shell

A security researcher using the handle U-Sec (Wujie Security) published details of a deserialization filter bypass in Apache Log4j 2, reporting that…

Apple Patches 122 Flaws including macOS Screen Sharing Flaw (CVE-2026-65400)

Apple shipped four security updates on August 17, 2026, fixing 122 vulnerabilities in iOS 18.7.10 and iPadOS 18.7.10, 29 in iOS 26.6.1 and iPadOS 26.…