Follow Cyber Kendra on Google News! | WhatsApp | Telegram

Add as a preferred source on Google
Security

New "Certighost" Flaw Lets Any Domain User Seize Full Windows Domain

Microsoft has patched a serious Active Directory Certificate Services (AD CS) flaw that handed any low-privileged domain user the keys to an entire W…

Bing Images Bugs Let Anyone Run Code as SYSTEM

Microsoft has patched three critical remote code execution flaws, two of them in Bing Images, that allowed anyone on the internet to run commands on …

Most GitHub Enterprise Servers Still Unpatched for New RCE

Nearly nine out of ten self-hosted GitHub Enterprise Server instances remain vulnerable to a critical remote code execution flaw that needs nothing m…

WP2Shell (CVE-2026-63030): Checker, Patch & Detection Guide

Last updated: 23 July 2026 · Now includes in-the-wild exploitation data and the WAF-bypass warning. Written for site owners, admins and defende…

15-Year-Old Nginx Vulnerability Exposes Critical RCE Flaw

nginx just took its third critical hit in the same fragile corner of its codebase this year — and this one has been sitting there since 2011. Tracked…

HuggingFace Breached by Autonomous AI Agent Swarm

Hugging Face has confirmed a security breach unlike anything the AI platform has faced before — an intrusion planned and executed end-to-end by an au…

WP2Shell: Critical WordPress Flaw Lets Anyone Run Code

WordPress does not force-push updates onto sites that have opted out of them. Doing so overrides an administrator's explicit choice, and the proj…

Cursor's Unpatched 0-Day Lets a Fake Git Binary Hijack Your Windows PC

A security flaw in Cursor, the AI-powered code editor used by more than 7 million developers, lets attackers run arbitrary code on a victim's Win…

Progress Confirms ShareFile Zero-Day Behind Storage Zone Shutdown, Ships Emergency Patches

Progress Software has confirmed the mystery behind last week's abrupt shutdown of ShareFile Storage Zone Controllers: a high-severity zero-day vu…

Researchers Turn Claude Code and Codex Into Malware Launchers With a Poisoned README

Ask an AI coding agent to review an open-source library for security flaws, and it might just run the malware hiding inside it instead. That's th…

Januscape: New KVM Bug Lets a Malicious Cloud VM Crash Its Own Host

A newly disclosed Linux kernel bug shows the wall separating a cloud tenant's virtual machine from the physical server underneath it isn't as…

15-Year-Old Linux Kernel Bug 'GhostLock' Lets Any Local User Seize Root, Break Out of Containers

A privilege-escalation flaw that has quietly sat inside the Linux kernel since 2011 has finally been exposed — and it hands root access to any unpriv…

Critical Unpatched Flaw in CyberPanel Lets Any User Seize Root on the Server

A newly disclosed zero-day in CyberPanel — one of the most widely deployed open-source hosting control panels — allows any authenticated user, even o…

19-Year-Old Linux Kernel Bug Earns $80K Bounty, Grants Root in Under a Second

A single line of code merged into the Linux kernel back in 2007 sat quietly for nearly two decades before anyone realized it could hand attackers a f…

Root Access for the Taking: 'Bad Epoll' Exploit Code Now Public

A working exploit for a Linux kernel vulnerability that hands any logged-in user a root shell is now sitting in the open, and the flaw it targets is …

One Malicious Link, Full Root Access — Nebula Security Demos the World's First Android 17 Exploit Chain

Clicking an unknown link has always been risky advice, but a new exploit published today makes the danger more visceral than ever. YC-backed security…

CVE-2026-55200 — Critical libssh2 Flaw Enables Zero-Auth RCE

A critical security flaw in libssh2 — the SSH library silently embedded in curl, backup utilities, and IoT firmware worldwide — lets unauthenticated …

Squidbleed: 1997 Squid Proxy Bug Leaks HTTP Credentials

Security researchers have uncovered a nearly three-decade-old vulnerability in Squid Proxy that lets anyone sharing the same proxy silently steal oth…

6 Strategies to Reduce the Risk of Targeted Attacks in a Digital-First World

In a world where nearly every aspect of life is connected to technology, personal and professional security has become more complex than ever. Digita…