❌

Reading view

There are new articles available, click to refresh the page.

Two Joomla Extensions Hit by Zero-Day File Upload Attacks Before Patches Landed

CISA added CVE-2026-48939 and CVE-2026-56291 to its Known Exploited Vulnerabilities catalog after automated attackers exploited file upload flaws in iCagenda and Balbooa Forms weeks before either bug had a CVE number.

Two Joomla Extensions Hit by Zero-Day File Upload Attacks Before Patches Landed on Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses.

Amazon Q’s MCP Flaw Is an Industry Warning: AI Tools Still Lack Workspace Trust Standards

CVE-2026-12957 in Amazon Q is the third MCP auto-execution vulnerability in three AI coding tools. The pattern reveals a shared design failure, not just a single vendor mistake.

Amazon Q’s MCP Flaw Is an Industry Warning: AI Tools Still Lack Workspace Trust Standards on Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses.

❌