Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data
A security researcher discovered a broken access control vulnerability in Meta’s support infrastructure.
The post Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data appeared first on SecurityWeek.
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
Clover Health Investments Discloses Data Breach
Using social engineering, hackers compromised employee accounts with access to personal and health information.
The post Clover Health Investments Discloses Data Breach appeared first on SecurityWeek.
Microsoft shares manual fix for WSUS sync delays and timeouts
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2shell.
“By the early hours of Saturday morning (UTC), successful exploitation was already well
Exploitation of ServiceNow Vulnerability Seen Days After Disclosure
The ServiceNow AI platform vulnerability tracked as CVE-2026-6875 can be exploited for remote code execution.
The post Exploitation of ServiceNow Vulnerability Seen Days After Disclosure appeared first on SecurityWeek.
Zimbra Update Patches Critical Vulnerabilities
The latest Zimbra refresh resolves command injection, XSS, restriction bypass, and SSRF security defects.
The post Zimbra Update Patches Critical Vulnerabilities appeared first on SecurityWeek.
Windows LegacyHive zero-day flaw gets free, unofficial patches
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to encrypt model weights, vector indexes, training datasets, and other AI infrastructure files across the host filesystem.
The entry
