Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
A security researcher has released working exploit code for four Linux kernel flaws that each let a local user gain
New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
Swati KhandelwalSep 18, 2026Vulnerability / Web Security WordPress today released patches to fix a new set of vulnerabilities in its
Gyazo server flaw exploited to steal 23.6 million user records
The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them
Critical Microsoft Azure AI Foundry Vulnerability Allows Attackers to Escalate Privileges
Microsoft has patched a maximum-severity security flaw in Azure AI Foundry, its enterprise platform for building and managing generative AI
Tutor LMS Flaw Exposes 100,000+ WordPress Sites to Remote Code Execution
A high-severity flaw in the Tutor LMS WordPress plugin could let a low-privileged user take control of an affected server.
WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
Ravie LakshmananSep 18, 2026Malware / Web Security Cybersecurity researchers have discovered a cluster of 13 npm packages that have been
New Check Point flaw lets hackers execute code with root privileges
Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root
Steam Windows 0-Day Vulnerability Allows Users to Silently Escalate to Full SYSTEM Privileges
A newly disclosed Windows zero-day affecting the Steam Client Service can reportedly let a standard local user obtain NT AUTHORITYSYSTEM
OpenAI details more cases of AI agents taking unauthorized actions
OpenAI has presented new examples of what they call “AI model misalignment” from the past six months, including unauthorized file uploads, following
Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
A critical vulnerability in Check Point’s Security Management and Log Servers could allow an attacker without login credentials to run
OpenAI Models Searched for Leaked API Keys and Uploaded Files Without Permission
OpenAI has disclosed six cases in which AI models concealed errors, used an exposed API key, uploaded data to public
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Swati KhandelwalSep 17, 2026Vulnerability / DNS Security Every release of the Unbound DNS resolver before 1.26.1 has a critical heap