❌

Normal view

There are new articles available, click to refresh the page.
Today β€” 23 July 2026Main stream

New Kimi K3 AI Agent Uncovers Redis Remote Code Execution Flaws in Just 27 Minutes

By: Divya
23 July 2026 at 09:04

Moonshot AI’s newly unveiled Kimi K3 model is attracting considerable attention in the cybersecurity community after successfully demonstrating its ability to autonomously identify critical vulnerabilities in Redis within minutes. This 2.8-trillion-parameter AI agent reportedly discovered multiple remote code execution (RCE) vulnerabilities across various Redis versions, specifically 6.2.22, 7.4.9, 8.6.4, and 8.8.0. This highlights the increasing […]

The post New Kimi K3 AI Agent Uncovers Redis Remote Code Execution Flaws in Just 27 Minutes appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical FreePBX Flaws Let Unauthenticated Attackers Execute Code and Take Over Administrator Accounts

By: Divya
23 July 2026 at 07:30

Critical security vulnerabilities in FreePBX have been disclosed, exposing organizations to risks of unauthenticated remote code execution and the takeover of administrator accounts. These flaws, tracked under GitHub advisories GHSA-37j8-fhxx-9vhp and GHSA-g27h-xf3q-h3rm, affect FreePBX versions 16 and 17, carrying a CVSS v4 base score of 9.3, which highlights their severity. Security researchers warn that these […]

The post Critical FreePBX Flaws Let Unauthenticated Attackers Execute Code and Take Over Administrator Accounts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical FreeRDP Clipboard Flaw Could Let Malicious RDP Servers Execute Code

By: Divya
23 July 2026 at 07:19

A critical heap buffer overflow vulnerability in FreeRDP’s Windows client could allow a malicious Remote Desktop Protocol (RDP) server to corrupt memory and potentially execute arbitrary code on a connecting client. This flaw specifically affects the Clipboard Redirection (CLIPRDR) virtual channel in wfreerdp, where an attacker-controlled response can exceed the size that the client originally […]

The post Critical FreeRDP Clipboard Flaw Could Let Malicious RDP Servers Execute Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Exim Vulnerability Lets Attackers Access Files Outside the Mail Spool

By: Divya
23 July 2026 at 07:12

A high-severity directory traversal vulnerability has been discovered in the Exim mail transfer agent. This flaw allows local attackers to access files outside the intended mail spool directory and potentially escalate their privileges. It is tracked as EXIM-Security-2026-06-22.1 and assigned GCVE-25-2026-07-45-1. The vulnerability affects Exim versions 4.88 through 4.99.4 and was announced on July 22, […]

The post Exim Vulnerability Lets Attackers Access Files Outside the Mail Spool appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical Check Point SmartConsole Flaw Exploited in the Wild to Bypass Authentication

By: Divya
23 July 2026 at 05:54

A critical authentication bypass vulnerability affecting Check Point SmartConsole has been actively exploited in the wild, allowing attackers to gain unauthorized access to security management systems under specific configurations. The flaw, tracked as CVE-2026-16232, carries a CVSS score of 9.3 and impacts Check Point Security Management and Multi-Domain Management deployments, particularly when management interfaces are […]

The post Critical Check Point SmartConsole Flaw Exploited in the Wild to Bypass Authentication appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Ubuntu Snap-Confine Vulnerability Allows Unprivileged Users to Execute Code as Root

By: Divya
23 July 2026 at 05:35

A recently disclosed vulnerability in Ubuntu’s snap ecosystem, identified as CVE-2026-8933, presents a critical local privilege escalation flaw. This vulnerability allows unprivileged users to execute arbitrary code with root privileges. Qualys discovered the issue in snap-confine, a core component used by snapd to set up execution environments for snap applications. It affects specific Ubuntu releases […]

The post Ubuntu Snap-Confine Vulnerability Allows Unprivileged Users to Execute Code as Root appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars

By: Divya
23 July 2026 at 05:13

A critical Bluetooth vulnerability in dealer-installed KARR Security Systems is putting over 2 million vehicles at risk of unauthorized access and immobilization. This situation has prompted urgent calls for drivers to update affected devices. Researchers at the University of California, San Diego, revealed that the flaw allows attackers within Bluetooth range to issue commands such […]

The post KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical RefluXFS Linux Kernel Flaw Lets Local Attackers Gain Root Access

By: Divya
23 July 2026 at 01:48

A critical vulnerability in the Linux kernel, identified as CVE-2026-64600 and referred to as RefluXFS. This vulnerability enables an unprivileged local user to gain root access on systems that utilize reflink-enabled XFS filesystems. The flaw resides in the XFS copy-on-write path and has reportedly existed since the release of Linux kernel version 4.1 in 2017. […]

The post Critical RefluXFS Linux Kernel Flaw Lets Local Attackers Gain Root Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Yesterday β€” 22 July 2026Main stream

CISA Warns WordPress Core SQL Injection Vulnerability Is Actively Exploited in Attacks

By: Divya
22 July 2026 at 07:33

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has classified a critical SQL injection vulnerability in WordPress Core, tracked as CVE-2026-60137, as one of its Known Exploited Vulnerabilities (KEV) due to its active exploitation in real-world attacks. This vulnerability affects the core functionality of WordPress when themes or plugins fail to properly validate untrusted input […]

The post CISA Warns WordPress Core SQL Injection Vulnerability Is Actively Exploited in Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Zimbra 10.1.20 Fixes Critical SNMP Command Injection and Multiple XSS Flaws

By: Divya
22 July 2026 at 06:32

Zimbra has released version 10.1.20 of its Collaboration Suite (ZCS) to address multiple high-severity security vulnerabilities. This release includes a critical command injection flaw in the SNMP monitoring component and several cross-site scripting (XSS) issues affecting the Classic Web Client. The update, published on July 20, 2026, provides a permanent fix for a previously disclosed […]

The post Zimbra 10.1.20 Fixes Critical SNMP Command Injection and Multiple XSS Flaws appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Critical ASUS Router Flaw Lets Remote MITM Attackers Execute Arbitrary Commands

By: Divya
22 July 2026 at 06:04

ASUS has announced a significant security vulnerability in its router firmware that could enable remote attackers to execute arbitrary commands through a man-in-the-middle (MITM) attack. This raises substantial concerns for both enterprise and home network security. The flaw, identified as CVE-2026-13385, impacts multiple branches of ASUS router firmware, including the widely used versions 3.0.0.4_386, 3.0.0.4_388, […]

The post Critical ASUS Router Flaw Lets Remote MITM Attackers Execute Arbitrary Commands appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

SolarWinds Serv-U Update Fixes 15 Critical Vulnerabilities Enabling Remote Code Execution as Root

By: Divya
22 July 2026 at 04:45

SolarWinds has released Serv-U 2026.3, which includes fixes for a cluster of 9.1 CVSS critical vulnerabilities that allow remote code execution (RCE) and privilege escalation up to root on Unix-like systems. This update significantly strengthens the managed file transfer (MFT) and FTP server platform against potential takeovers. While Windows instances are rated as having a […]

The post SolarWinds Serv-U Update Fixes 15 Critical Vulnerabilities Enabling Remote Code Execution as Root appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Google Chrome Update Fixes 12 High-Severity Vulnerabilities That Enable Browser Attacks

By: Divya
22 July 2026 at 01:19

Google has released a Chrome security update that addresses 12 high-severity vulnerabilities affecting various components, including WebAudio, ANGLE, Chromecast, extensions, Skia, the V8 JavaScript engine, certificate handling, the user interface, and GPU elements. Many of these vulnerabilities involve memory corruption issues, such as out-of-bounds reads and writes, use-after-free bugs, stack buffer overflows, and type confusion. […]

The post Google Chrome Update Fixes 12 High-Severity Vulnerabilities That Enable Browser Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Before yesterdayMain stream

Critical Gitea Flaw Lets Public-Only Tokens Write to Private Repositories and Trigger Actions Workflows

By: Divya
21 July 2026 at 03:34

Gitea administrators are strongly encouraged to upgrade their systems following the discovery of a critical authorization vulnerability. This flaw allows public-only API tokens to modify private pull request branches and potentially trigger Gitea Actions workflows. The vulnerability, tracked as CVE-2026-58443 and GHSA-xxjv-752h-3vp2, affects Gitea versions up to and including 1.26.4. The issue has been resolved […]

The post Critical Gitea Flaw Lets Public-Only Tokens Write to Private Repositories and Trigger Actions Workflows appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Exploit Palo Alto PAN-OS Flaw to Deploy Qilin Ransomware

By: Divya
21 July 2026 at 00:26

Hackers are exploiting a high-severity vulnerability in Palo Alto Networks’ PAN-OS to gain initial access to corporate networks and deploy Qilin ransomware. Multiple intrusions investigated in June 2026 began with the exploitation of CVE-2026-0257, an authentication bypass flaw affecting GlobalProtect portal and gateway deployments. The attacks evolved from external VPN compromises to domain-wide encryption, with […]

The post Hackers Exploit Palo Alto PAN-OS Flaw to Deploy Qilin Ransomware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

GPT-5.6 Sol Ultra Discovers WordPress Pre-Auth SQL Injection Leading to RCE

By: Divya
20 July 2026 at 09:14

A critical vulnerability chain in WordPress, called wp2shell, that allegedly allows unauthenticated attackers to exploit a pre-authentication SQL injection flaw to achieve remote code execution (RCE) on typical WordPress installations running MySQL. Security researcher Adam Kues discovered this vulnerability chain using GPT-5.6 Sol Ultra during a multi-agent audit of the WordPress source code. GPT-5.6 Sol […]

The post GPT-5.6 Sol Ultra Discovers WordPress Pre-Auth SQL Injection Leading to RCE appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Kimai Docker Vulnerability Exposes Default APP_SECRET, Enabling Account Takeover

By: Divya
20 July 2026 at 01:53

Kimai users who are running the official Docker image are strongly urged to update their installations after a critical vulnerability, tracked as CVE-2026-52824 and GHSA-jr9p-4h4j-6c58, was discovered. This vulnerability exposes installations to the risk of account takeover due to a publicly known application secret. The flaw affects Kimai versions 2.57.0 and earlier, and it has […]

The post Kimai Docker Vulnerability Exposes Default APP_SECRET, Enabling Account Takeover appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

TP-Link Kasa Camera Flaws Let Attackers Steal Admin Credentials and Geolocation Data

By: Divya
17 July 2026 at 05:48

TP-Link has revealed several serious vulnerabilities affecting its Kasa EC70 and EC71 smart camera models, which could expose users to credential theft and geolocation data leakage. These vulnerabilities are CVE-2026-9770 and CVE-2026-13230 and specifically affect version 4 of both devices. Attackers with access to the same local network could exploit these flaws, raising concerns about […]

The post TP-Link Kasa Camera Flaws Let Attackers Steal Admin Credentials and Geolocation Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

CISA Warns of Two Fortinet FortiSandbox Flaws Exploited to Execute Commands

By: Divya
17 July 2026 at 05:19

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities in Fortinet FortiSandbox to its Known Exploited Vulnerabilities (KEV) catalog. These flaws are actively being exploited in the wild to execute unauthorized commands on affected systems. The vulnerabilities, tracked as CVE-2026-39808 and CVE-2026-25089, involve OS command injection weaknesses (CWE-78) and impact FortiSandbox […]

The post CISA Warns of Two Fortinet FortiSandbox Flaws Exploited to Execute Commands appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

7-Zip Vulnerability Lets Attackers Trigger Heap Buffer Overflow Using Malicious Files

By: Divya
17 July 2026 at 01:55

A newly disclosed vulnerability in 7-Zip could allow attackers to execute arbitrary code by tricking users into opening a specially crafted XZ-compressed file. Tracked as CVE-2026-14266 and identified by Trend Micro’s Zero Day Initiative as ZDI-26-444 (ZDI-CAN-30169), the flaw is a heap-based buffer overflow in the archive utility’s handling of XZ chunked data. The vulnerability […]

The post 7-Zip Vulnerability Lets Attackers Trigger Heap Buffer Overflow Using Malicious Files appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌
❌