
cPanel Patches Critical Flaw Letting Customers Run SQL as Root
cPanel patched CVE-2026-58048, a CVSS 9.4 privilege-escalation flaw letting an authenticated hosting customer execute SQL in the database root context.

cPanel patched CVE-2026-58048, a CVSS 9.4 privilege-escalation flaw letting an authenticated hosting customer execute SQL in the database root context.

Forescout disclosed 15 TP-Link Omada zero-touch provisioning vulnerabilities that chain with earlier RCE flaws into full fleet-wide network compromise.

The Greatness phishing-as-a-service platform has expanded to device-code and AiTM phishing, with attacks spoofing RingCentral to target Microsoft 365 users.

Unit 42 found XCSSET v40 targeting macOS developers via compromised Xcode projects, adding a Chrome hijacker and Telegram trojanizer to

A Google Firebase misconfiguration in the tl;dv AI meeting tool lets users query others’ meeting data and potentially join calls,

Water-sector cyberattacks have hit utilities in at least 12 US states, up from seven, with Georgia confirmed after a Clayton

Unit 42 reveals three Pass-ta-key attacks that let malware hijack Google-synced passkeys on Windows by abusing Chrome’s TPM trust and

Socket found 18 malicious npm packages impersonating Alibaba developer tools that deliver a cross-platform RAT with remote control and data-theft

Threat actors poisoned Xanadu’s mrmustard 0.7.4 on PyPI with an info-stealer that exfiltrates SSH keys and AWS credentials from research

Censys found a Chinese-speaking actor using the leaked DarkSword exploit kit to deploy the GHOSTBLADE info-stealer on iOS devices and
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.