ransomware ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors This week’s security news is dominated by AI-related threats, including a vulnerability exploited in Metabase, a new Shai-Hulud worm leveraging the MCP Registry, and a Chinese review of Palo Alto Networks. Alongside these, researchers are bypassing Spectre defenses, CSS attacks are targeting webmail, and a new ransomw… The Hacker News · Aug 10, 2026 High CVE-2026-34348CVE-2026-18497CVE-2026-63508CHransomwaresupply-chainvishing
vulnerability Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup A critical vulnerability (CVE-2026-59774) in Gitea versions 1.22.1 through 1.27.0 allows unauthenticated attackers to read files accessible to the service account. While a direct remote code execution exploit hasn't been… The Hacker News · Aug 5, 2026 Critical CVE-2026-59774CVE-2026-60004CVE-2026-20896vulnerabilityorg-moderemote code execution