Follow Cyber Kendra on Google News! | WhatsApp | Telegram

Add as a preferred source on Google
Vulnerability

Azure Cosmos DB Flaw Gave Up Keys to Every Database

Microsoft has closed a vulnerability chain in Azure Cosmos DB that would have let anyone with a throwaway test account read and write data in every d…

KindaRails2Shell - Critical Rails Flaw Leaks Secrets — Patching Isn't Enough

Ruby on Rails shipped emergency releases on July 29 for a critical vulnerability that lets an unauthenticated attacker read arbitrary files from a se…

AI Agent Finds Firefox JIT Flaw That Also Broke Tor

Mozilla has patched a JavaScript engine bug that let attackers run code inside Firefox's renderer process, and the Tor Project has now backported…

UnAuth vBulletin RCE Exploit Goes Public Weeks After Patch

A working exploit for a critical vBulletin flaw is now circulating in the open, handing unauthenticated attackers a direct route to running PHP code …

New "Certighost" Flaw Lets Any Domain User Seize Full Windows Domain

Microsoft has patched a serious Active Directory Certificate Services (AD CS) flaw that handed any low-privileged domain user the keys to an entire W…

Bing Images Bugs Let Anyone Run Code as SYSTEM

Microsoft has patched three critical remote code execution flaws, two of them in Bing Images, that allowed anyone on the internet to run commands on …

Most GitHub Enterprise Servers Still Unpatched for New RCE

Nearly nine out of ten self-hosted GitHub Enterprise Server instances remain vulnerable to a critical remote code execution flaw that needs nothing m…

15-Year-Old Nginx Vulnerability Exposes Critical RCE Flaw

nginx just took its third critical hit in the same fragile corner of its codebase this year — and this one has been sitting there since 2011. Tracked…

WP2Shell: Critical WordPress Flaw Lets Anyone Run Code

WordPress does not force-push updates onto sites that have opted out of them. Doing so overrides an administrator's explicit choice, and the proj…

Progress Confirms ShareFile Zero-Day Behind Storage Zone Shutdown, Ships Emergency Patches

Progress Software has confirmed the mystery behind last week's abrupt shutdown of ShareFile Storage Zone Controllers: a high-severity zero-day vu…

Researchers Turn Claude Code and Codex Into Malware Launchers With a Poisoned README

Ask an AI coding agent to review an open-source library for security flaws, and it might just run the malware hiding inside it instead. That's th…

15-Year-Old Linux Kernel Bug 'GhostLock' Lets Any Local User Seize Root, Break Out of Containers

A privilege-escalation flaw that has quietly sat inside the Linux kernel since 2011 has finally been exposed — and it hands root access to any unpriv…

Critical Unpatched Flaw in CyberPanel Lets Any User Seize Root on the Server

A newly disclosed zero-day in CyberPanel — one of the most widely deployed open-source hosting control panels — allows any authenticated user, even o…

One Malicious Link, Full Root Access — Nebula Security Demos the World's First Android 17 Exploit Chain

Clicking an unknown link has always been risky advice, but a new exploit published today makes the danger more visceral than ever. YC-backed security…

CVE-2026-55200 — Critical libssh2 Flaw Enables Zero-Auth RCE

A critical security flaw in libssh2 — the SSH library silently embedded in curl, backup utilities, and IoT firmware worldwide — lets unauthenticated …

Squidbleed: 1997 Squid Proxy Bug Leaks HTTP Credentials

Security researchers have uncovered a nearly three-decade-old vulnerability in Squid Proxy that lets anyone sharing the same proxy silently steal oth…

OpenAI's Codex AI Discovers "HTTP/2 Bomb" That Can Crash Major Web Servers in Seconds

An AI model just found a decade-old attack that human security researchers somehow missed — and it works against almost every major web server on the…

An AI Security Tool Dug Up a 2-Year-Old Redis Bug That Lets Attackers Take Over Servers

A flaw that sat undetected in Redis for over two years — silently present in every stable release since version 7.2.0 — has been patched after an AI-…

A Forged Kernel Key and a Rootful Helper: Inside the CIFSwitch Linux Privilege Escalation

A security researcher has disclosed a Linux local privilege escalation — dubbed CIFSwitch — that lets any unprivileged user silently escalate to roo…

BadHost (CVE-2026-48710): One Rogue Header Line Unlocks Your Entire AI Stack

A single, malformed HTTP header is all it takes to walk past the front door of thousands of Python-powered AI applications — no credentials, no token…