vulnerability Gogs Zero-Day Exposes Servers to Remote Code Execution A critical zero-day vulnerability has been discovered in the open-source self-hosted Git service, Gogs, allowing for remote code execution (RCE) on affected servers. The flaw, identified by Rapid7, stems from an argument… SecurityWeek · May 29, 2026 Critical CVE-2025-8110zero-dayremote code executiongit
threat-intel 'The Com' Cyberattacks Support Violence & Sexploitation This report details the activities of 'The Com,' a decentralized cybercriminal collective primarily composed of North American teenagers, many linked to groups like ShinyHunters, Lapsus$, and Scattered Spider. The group… Dark Reading · May 29, 2026 Critical USGBcybercrimechild exploitationhacktivism
vulnerability Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code A critical remote code execution (RCE) vulnerability has been identified in Gogs, a popular self-hosted Git service, allowing authenticated users to execute arbitrary code. The flaw, detailed by Jonah Burgess, stems from… The Hacker News · May 28, 2026 Critical rcegitrebase
vulnerability Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks Fortinet rolled out hotfixes for the security defect in April, warning that it had been exploited in the wild as a zero-day and urging immediate patching. The post Critical FortiClient EMS Vulnerability Exploited in Fres… SecurityWeek · May 28, 2026 Critical CVE-2026-35616
vulnerability KMW CCTV Security Cameras This advisory details a critical vulnerability in KMW CCTV Security Cameras, specifically versions KM-IP521 (V4.04.91.230307) and KM-IP421 (V4.04.53.210416), allowing unauthorized access to camera feeds and settings via… CISA Advisories · May 28, 2026 Critical CVE-2026-5386WOcctvpasswordunauthenticated
vulnerability Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter This advisory details a critical vulnerability in the Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter, specifically version 7.03T.07. The device contains hardcoded administrative cr… CISA Advisories · May 28, 2026 Critical CVE-2026-7786CNfirmwarecredentialsiot
threat-intel XCharge C6 This CISA advisory details a critical vulnerability series affecting XCharge C6 charging controllers worldwide. The vulnerabilities include a firmware validation flaw, a stack-based buffer overflow, and a misconfigured r… CISA Advisories · May 28, 2026 Critical CVE-2026-9037CVE-2026-9038CVE-2026-9039USfirmwarebuffer overflowremote management
threat-intel Sextortionist sentenced to 33 years for targeting 145 children A Canadian man, Ramanan Pathmanathan, has been sentenced to 33 years in prison for a long-running sextortion scheme targeting over 145 children, primarily in the United States. The scheme involved blackmailing victims wi… BleepingComputer · May 28, 2026 Critical CAUSsextortionchild_exploitationonline_abuse
threat-intel AI-Assisted Exploit Development Outpaces Scanner Detection Research from Cogent indicates that AI-assisted exploit development is dramatically accelerating, reducing exploit creation time from 125 days to just 0.5 days using large language models. This creates significant ‘visib… Dark Reading · May 27, 2026 Critical USaiexploitvulnerability
vulnerability CISA gives feds 4 days to patch actively exploited cPanel plugin flaw The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. federal agencies four days to secure their servers against a critical vulnerability in the LiteSpeed cPanel user-end plugin, which is active… BleepingComputer · May 27, 2026 Critical CVE-2026-48172
vulnerability CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert urging immediate patching of a zero-day vulnerability (CVE-2026-48172) in the LiteSpeed cPanel plugin. This flaw allows for privileg… SecurityWeek · May 27, 2026 Critical CVE-2026-48172UScpanelzero-dayprivilege escalation
vulnerability KnowledgeDeliver flaw exploited as a zero-day to install web shells Hackers exploited a critical zero-day vulnerability in a server running the KnowledgeDeliver learning management system (LMS) to deploy the Godzilla web shell. BleepingComputer · May 26, 2026 Critical CVE-2026-5426
vulnerability Microsoft Issues Out-of-Band SharePoint Patch Microsoft has released an out-of-band security patch to address a critical remote code execution vulnerability (CVE-2026-45659) in SharePoint Server. The flaw allows authenticated attackers to execute code without elevat… Dark Reading · May 26, 2026 Critical CVE-2026-45659CHremote code executionsharepointzero-day
vulnerability ABB Terra AC This report details a vulnerability in ABB Terra AC wallbox chargers, specifically versions up to 1.8.34. An attacker could exploit unencrypted communication to the Charging Station Management System (CSMS) by sending sp… CISA Advisories · May 26, 2026 Critical CVE-2025-5517WOocppheap overflowfirmware
vulnerability Eppendorf BioFlo 320 This CISA advisory details a critical vulnerability in Eppendorf BioFlo 320 bioreactors due to a hard-coded VNC password, allowing unauthorized remote access and control. The vulnerability affects all versions of the Bio… CISA Advisories · May 26, 2026 Critical CVE-2026-7251WOvncpasswordremote access
vulnerability Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment Hardcoded machineKey values in a configuration file enabled ViewState deserialization attacks leading to remote code execution. The post Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment appeared first… SecurityWeek · May 26, 2026 Critical CVE-2026-5426
vulnerability CISA orders feds to patch actively exploited Drupal vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive requiring federal agencies to patch a critical SQL injection vulnerability (CVE-2026-9082) in the Drupal content management system.… BleepingComputer · May 26, 2026 Critical CVE-2026-9082USGBDEsql injectiondrupalcisa
threat-intel KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike A zero-day vulnerability in Digital Knowledge KnowledgeDeliver LMS was exploited to deploy the Godzilla web shell and establish Cobalt Strike Beacon access. The flaw, stemming from hard-coded ASP.NET machine keys, allowe… The Hacker News · May 26, 2026 Critical CVE-2026-5426JPzero-daydeserializationasp.net
ransomware Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks A critical vulnerability (CVE-2026-26980) in Ghost CMS is being exploited to hijack over 700 websites, primarily through ClickFix attacks. Threat actors are leveraging this SQL injection flaw to steal admin API keys and… The Hacker News · May 25, 2026 Critical CVE-2026-26980CNsql injectionclickfixjavascript
threat-intel Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects Anthropic’s Claude Mythos AI model has identified a massive number of vulnerabilities – estimated between 6,200 and 23,000 – across over 1,000 open-source software projects. Many of these vulnerabilities, particularly t… SecurityWeek · May 25, 2026 Critical UKaivulnerabilityopen source