Follow Cyber Kendra on Google News! | WhatsApp | Telegram

Add as a preferred source on Google
Vulnerability

Metabase Zero-Day Exposes Framework, Tally Customer Data

Two companies told customers this week that their personal data had been stolen. Neither was breached directly. The attacker walked in through the an…

Public Exploit Lands for WordPress XSS2Shell Core Flaw

A working proof-of-concept exploit for " XSS2Shell " is now circulating publicly, raising the stakes on a WordPress Core flaw that turns a …

Mac Malware Checks Your GPU Before Showing Its Lure

The crews behind a long-running macOS scam have started doing something defenders usually do: vetting who is on the other end of a connection before …

cPanel Bug Hands Database Root to Any Hosting Customer

For three months, the cPanel security story has been about attackers forcing the front door. The vendor's newest release flips that script: this …

macOS Screen Sharing Bug Handed Hackers Root, No Password

A critical vulnerability in Apple's Screen Sharing service let unauthenticated attackers take over a targeted Mac over the network — reading and …

Azure Cosmos DB Flaw Gave Up Keys to Every Database

Microsoft has closed a vulnerability chain in Azure Cosmos DB that would have let anyone with a throwaway test account read and write data in every d…

KindaRails2Shell - Critical Rails Flaw Leaks Secrets — Patching Isn't Enough

Ruby on Rails shipped emergency releases on July 29 for a critical vulnerability that lets an unauthenticated attacker read arbitrary files from a se…

AI Agent Finds Firefox JIT Flaw That Also Broke Tor

Mozilla has patched a JavaScript engine bug that let attackers run code inside Firefox's renderer process, and the Tor Project has now backported…

UnAuth vBulletin RCE Exploit Goes Public Weeks After Patch

A working exploit for a critical vBulletin flaw is now circulating in the open, handing unauthenticated attackers a direct route to running PHP code …

New "Certighost" Flaw Lets Any Domain User Seize Full Windows Domain

Microsoft has patched a serious Active Directory Certificate Services (AD CS) flaw that handed any low-privileged domain user the keys to an entire W…

Bing Images Bugs Let Anyone Run Code as SYSTEM

Microsoft has patched three critical remote code execution flaws, two of them in Bing Images, that allowed anyone on the internet to run commands on …

Most GitHub Enterprise Servers Still Unpatched for New RCE

Nearly nine out of ten self-hosted GitHub Enterprise Server instances remain vulnerable to a critical remote code execution flaw that needs nothing m…

15-Year-Old Nginx Vulnerability Exposes Critical RCE Flaw

nginx just took its third critical hit in the same fragile corner of its codebase this year — and this one has been sitting there since 2011. Tracked…

WP2Shell: Critical WordPress Flaw Lets Anyone Run Code

WordPress does not force-push updates onto sites that have opted out of them. Doing so overrides an administrator's explicit choice, and the proj…

Progress Confirms ShareFile Zero-Day Behind Storage Zone Shutdown, Ships Emergency Patches

Progress Software has confirmed the mystery behind last week's abrupt shutdown of ShareFile Storage Zone Controllers: a high-severity zero-day vu…

Researchers Turn Claude Code and Codex Into Malware Launchers With a Poisoned README

Ask an AI coding agent to review an open-source library for security flaws, and it might just run the malware hiding inside it instead. That's th…

15-Year-Old Linux Kernel Bug 'GhostLock' Lets Any Local User Seize Root, Break Out of Containers

A privilege-escalation flaw that has quietly sat inside the Linux kernel since 2011 has finally been exposed — and it hands root access to any unpriv…

Critical Unpatched Flaw in CyberPanel Lets Any User Seize Root on the Server

A newly disclosed zero-day in CyberPanel — one of the most widely deployed open-source hosting control panels — allows any authenticated user, even o…

One Malicious Link, Full Root Access — Nebula Security Demos the World's First Android 17 Exploit Chain

Clicking an unknown link has always been risky advice, but a new exploit published today makes the danger more visceral than ever. YC-backed security…

CVE-2026-55200 — Critical libssh2 Flaw Enables Zero-Auth RCE

A critical security flaw in libssh2 — the SSH library silently embedded in curl, backup utilities, and IoT firmware worldwide — lets unauthenticated …