News

Application Security
PoisonedRefresh Rootkit Injects PHP Web Shells into F5 BIG-IP Memory
SophosLabs published analysis of PoisonedRefresh, a fileless Linux rootkit that injects PHP web shells directly into F5 BIG-IP APM Apache server memory, leaving no disk ...
Application Security
September Windows Server Updates Break Remote Desktop Services
Microsoft's September security updates cause Remote Desktop Services failures on Windows Server 2019, 2022, and 2025, with some systems requiring hard reset reported September 10.
Application Security
Microsoft Excel KB5002914 Update Breaks Copy and Paste Functions
Microsoft's KB5002914 Office security update breaks copy-and-paste operations and formula dragging in Excel, with affected users removing the update to restore functionality reported September 10.
Application Security
cPanel Critical RCE Enables Full Server Takeover via Mail Account
Critical cPanel vulnerability lets authenticated hosting account holders execute root-level code and take complete control of entire server infrastructure.
Application Security
SAP Patches CVSS 10.0 Kernel RCE in Extended Passport Processing
SAP released patches for CVE-2026-44756, a maximum-severity memory corruption flaw enabling unauthenticated remote code execution in SAP kernel systems.
Application Security
Microsoft Ships Record 974 Security Patches in September Batch
Microsoft's September Patch Tuesday delivered 974 security fixes—the largest single batch ever—driven partly by AI-assisted vulnerability discovery tools.
Cybersecurity
ShinyHunters Claims Breach of Florida DMV DAVID Database
ShinyHunters extortion gang claims theft of over 200,000 driver records from Florida DMV's DAVID online platform. No official confirmation yet from the state.
Cybersecurity
Grindr Settles UK HIV Data Sharing Lawsuit for £26 Million
Grindr will pay £26 million to settle UK lawsuit over sharing users' HIV status and sensitive personal data with third parties for commercial purposes.
Cybersecurity
Liquid Network Attackers Return 3,400 Bitcoin, Keep $47 Million
Hackers who stole nearly 4,000 bitcoin from Liquid Network returned 3,400 BTC but kept 598.5 bitcoin worth $47 million. Network remains paused pending fix.
Cybersecurity
OpenAI Artifactory Flaw Enabled Cross-Account Data Theft
Security researchers disclosed a vulnerability in OpenAI's Artifactory enabling unauthorized cross-account artifact access and covert data exfiltration.