New Gogs zero-day flaw lets hackers get remote code execution
New Gogs zero-day flaw lets hackers get remote code execution By Sergiu Gatlan May 28, 2026 10:25 AM An unpatched zero-day vulnerability in the Gogs self-hosted Git service…
New Gogs zero-day flaw lets hackers get remote code execution By Sergiu Gatlan May 28, 2026 10:25 AM An unpatched zero-day vulnerability in the Gogs self-hosted Git service…
…The attackers retrieved this certificate and installed it on a self-made device, which then appeared as a legitimate part of KT’s network, capturing cellular traffic from nearby devices connecting to…
…The agency's urgent alert comes after hackers disrupted more than 30 community water systems in Minnesota in attacks that started last Sunday and continued through Monday. CISA's alert refers to…
…7-Zip fixes RCE flaw exploitable with malicious archives Critical Langflow RCE flaw exploited to hack AI app servers Critical UniFi OS bug lets hackers gain root without authentication CISA sets urgent…
N-able warns of N-central auth bypass flaw exploited in attacks By Bill Toulas August 3, 2026 01:00 PM N-able is warning customers that hackers are exploiting an authentication…
…PyPI package with 1.1M monthly downloads hacked to push infostealer New npm supply-chain attack self-spreads to steal auth tokens Backdoored PyTorch Lightning package drops credential stealer Hackers compromise Axios…
…The campaign was initially discovered by Malwarebytes , whose researchers say that the 'Pro' installer is a trojanized copy of Claude that works as expected but deploys a PlugX malware chain in the…
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access By Ionut Ilascu July 29, 2026 07:44 PM The Russian state-sponsored hacking group Laundry Bear, also known as…
…Critical SQL injection flaw now targeted in attacks Hackers are exploiting a critical LiteLLM pre-auth SQLi flaw Hackers bypass SonicWall VPN MFA due to incomplete patching Hackers exploit auth bypass flaw…
…However, the infection chain has been completely changed, with multiple attack stages and TookPS being used in the first phase to install and configure an SSH bot that delivered the other malicious…