The vulnerable code has shipped by default in essentially every mainstream distribution since 2011. The flaw needs no special permission, no unusual settings, and no network
CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
The vulnerabilities are listed below –
CVE-2026-48282 (CVSS score: 10.0) – A path traversal vulnerability in Adobe ColdFusion that could lead to arbitrary code execution in the context of the
Accenture confirms breach after hacker offers stolen data for sale
Chinese hackers develop LONGLEASH malware to expand ORB network
County Government Reportedly Paid $1 Million to Cyber Extortion Group
The alleged victim, believed to be a small Ohio county, reportedly paid the extortion group to prevent the public release of sensitive stolen data.
The post County Government Reportedly Paid $1 Million to Cyber Extortion Group appeared first on SecurityWeek.
Hidden backdoor in Tenda router firmware grants admin access
Critical Gitea Flaw Under Active Exploitation, Researchers Warn
Attackers are exploiting the critical Gitea vulnerability CVE-2026-20896 to bypass authentication with a single HTTP header and access vulnerable repositories and secrets.
The post Critical Gitea Flaw Under Active Exploitation, Researchers Warn appeared first on SecurityWeek.
RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service
Zimperium’s zLabs, which found the operation, says it looks like a new variant of Oblivion, a $300-a-month rent-a-malware tool
Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots
From there, they could read live conversations, steal the data users shared, and make the bots send attacker-written messages, including requests to re-enter a password.
Security firm Varonis found it
