
PoisonedRefresh Rootkit Injects PHP Web Shells into F5 BIG-IP Memory
SophosLabs published analysis of PoisonedRefresh, a fileless Linux rootkit that injects PHP web shells directly into F5 BIG-IP APM Apache

SophosLabs published analysis of PoisonedRefresh, a fileless Linux rootkit that injects PHP web shells directly into F5 BIG-IP APM Apache

Microsoft’s September security updates cause Remote Desktop Services failures on Windows Server 2019, 2022, and 2025, with some systems requiring

Microsoft’s KB5002914 Office security update breaks copy-and-paste operations and formula dragging in Excel, with affected users removing the update to

Critical cPanel vulnerability lets authenticated hosting account holders execute root-level code and take complete control of entire server infrastructure.

SAP released patches for CVE-2026-44756, a maximum-severity memory corruption flaw enabling unauthenticated remote code execution in SAP kernel systems.

Microsoft’s September Patch Tuesday delivered 974 security fixes—the largest single batch ever—driven partly by AI-assisted vulnerability discovery tools.

ShinyHunters extortion gang claims theft of over 200,000 driver records from Florida DMV’s DAVID online platform. No official confirmation yet

Grindr will pay £26 million to settle UK lawsuit over sharing users’ HIV status and sensitive personal data with third

Hackers who stole nearly 4,000 bitcoin from Liquid Network returned 3,400 BTC but kept 598.5 bitcoin worth $47 million. Network

Security researchers disclosed a vulnerability in OpenAI’s Artifactory enabling unauthorized cross-account artifact access and covert data exfiltration.
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.