Application Security

Application Security
cPanel Critical RCE Enables Full Server Takeover via Mail Account
Critical cPanel vulnerability lets authenticated hosting account holders execute root-level code and take complete control of entire server infrastructure.
Application Security
SAP Patches CVSS 10.0 Kernel RCE in Extended Passport Processing
SAP released patches for CVE-2026-44756, a maximum-severity memory corruption flaw enabling unauthenticated remote code execution in SAP kernel systems.
Application Security
Microsoft Ships Record 974 Security Patches in September Batch
Microsoft's September Patch Tuesday delivered 974 security fixes—the largest single batch ever—driven partly by AI-assisted vulnerability discovery tools.
Application Security
PEEP Toolkit Turns Chrome and Edge Into Post-Exploitation Backdoors
Researchers disclosed PEEP, a toolkit that hijacks Chrome and Edge browsers as backdoors by injecting malicious extensions that execute host commands.
Application Security
Magento StyleSmuggler Zero-Day Deploys Linux Backdoors on Stores
Zero-day StyleSmuggler flaw enables code execution on all Magento and Adobe Commerce versions. Attackers deploy Linux backdoors on e-commerce sites.
Application Security
Mathspace Breach Exposes Data of Over 1 Million Students and Staff
Attackers breached Mathspace's Metabase internal reporting system, stealing data from more than 1 million students, staff, and parents at the math platform.
Application Security
Attackers Chain MikroTik Flaws to Hijack Internet-Exposed SSH
Hackers are exploiting two chained MikroTik RouterOS vulnerabilities to take full control of routers with SSH services exposed to the public internet.
Application Security
Nightmare Eclipse Drops Zero-Days for CrowdStrike, Nvidia, Avast
Security researcher Nightmare Eclipse publicly released proof-of-concept zero-day exploits for CrowdStrike, Nvidia, and Avast that escalate to System privileges.
Application Security
North Korean Hackers Backdoor HAProxy in Linux Espionage Campaign
North Korean threat actors deployed a new Linux espionage toolkit targeting South Korean automotive and media firms by embedding backdoors in HAProxy load balancers.
Application Security
Backdoored ScreenConnect Servers Deliver Worm-Like Payloads
Attackers compromised ConnectWise ScreenConnect servers to automatically deliver malicious payloads to newly connected clients in a self-propagating campaign.