Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code
The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura’s HTML5 video player library that allow a remote,
Google Chrome 152 Released With 327 Security Fixes, Including 10 Critical Vulnerabilities
Google has released Chrome 152 for Windows, macOS, and Linux, delivering 327 security fixes and improvements. The update addresses 10
Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
Ravie LakshmananAug 26, 2026Vulnerability / Cryptojacking The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation
LACMA data breach last year exposed social security and medical data
The Los Angeles County Museum of Art (LACMA) has announced that a breach last year exposed customer and employee information.
Hackers abuse npm mirrors to host phishing redirect pages
Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors
U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called
CISA Red Team Breaches Critical Infrastructure to Reveal SOC and Cloud Security Gaps
CISA’s latest advisory for red teams warns critical infrastructure operators that security systems can fail even if they have a
Massive DDoS attack disrupts Norways government digital services
A large distributed denial-of-service (DDoS) attack has disrupted Norway’s shared government digital infrastructure since Monday, affecting services used by the
AI Security Startup Alice Raises $140 Million as Enterprise AI Threats Surge
Alice, the AI trust, safety, and security company formerly known as ActiveFence, has closed a $140 million funding round led
A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the
Anthropic Rolls Out Enterprise-Managed Auth for Claudes MCP Connectors
Anthropic has taken its Model Context Protocol (MCP) connector framework a significant step further, announcing on August 24, 2026, that
Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
Ravie LakshmananAug 25, 2026Vulnerability / Enterprise Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity