Software

Over 8,300 Gitea servers vulnerable to code execution attacks

Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver. The code injection vulnerability (CVE-2026-60004) targeted in these attacks was reported by Salesforce security researcher Shai Rod, and it allows authenticated attackers to execute arbitrary shell commands with the privileges […]

Over 8,300 Gitea servers vulnerable to code execution attacks Read More »

Toy-making giant Hasbro disclose data breach affecting employees

Hasbro, one of the world’s largest toy and game companies, has disclosed that attackers have accessed the personal and financial information of an undisclosed number of employees. Founded in 1923, Hasbro is a publicly traded American multinational entertainment conglomerate on the NASDAQ and owns many brands, including Monopoly, Clue, Nerf, Transformers, Play-Doh, Peppa Pig, Scrabble,

Toy-making giant Hasbro disclose data breach affecting employees Read More »

ServiceNow warns of three max severity security vulnerabilities

ServiceNow released security patches for three new maximum-severity AI Platform vulnerabilities that can be exploited in code injection, SQL injection, and privilege escalation attacks. The ServiceNow AI Platform (formerly known as the Now Platform) is an enterprise-grade Platform-as-a-Service (PaaS) that helps integrate AI into core enterprise workflows and powers more than 100,000 enterprise AI apps

ServiceNow warns of three max severity security vulnerabilities Read More »

Windows 11 KB5120998 update released with 35 changes and fixes

Microsoft released the KB5120998 preview cumulative update for Windows 11 versions 25H2 and 24H2, which comes with 35 changes, including improvements to the Start menu, taskbar, and Windows search. KB5120998 is a preview update that lets IT administrators test Windows bug fixes, improvements, and new features before they roll out to all users during next

Windows 11 KB5120998 update released with 35 changes and fixes Read More »

Nearly 700 rogue AI agents coordinated in the Hugging Face attack

New details about the July attack on Hugging Face reveal that hundreds of AI agents driven by OpenAI’s internal IM1 model coordinated the compromise through an unauthorized message board. Last month, Hugging Face disclosed that autonomous AI agents exploited two vulnerabilities in its dataset-processing pipeline to execute code, steal cloud and cluster credentials, and move

Nearly 700 rogue AI agents coordinated in the Hugging Face attack Read More »

Critical Avada WordPress theme flaw enables zero-click RCE

A critical vulnerability chain in the popular Avada theme for WordPress can be exploited by an unauthenticated attacker to execute arbitrary PHP code on the server. The exploit chains six security issues into a zero-click attack. The flaws are collectively tracked as CVE-2026-18431 and received a 9.8 critical severity score. The attack comprises exploits for

Critical Avada WordPress theme flaw enables zero-click RCE Read More »

ATF confirms “major incident” after recent Qilin breach claims

ATF, the regulatory agency that enforces federal laws governing firearms and explosives in the United States, has confirmed that one of its systems was compromised after breach claims made by the Qilin ransomware gang. This follows Qilin adding the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives to its dark web data leak portal on

ATF confirms “major incident” after recent Qilin breach claims Read More »

CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered government agencies to patch their Citrix NetScaler appliances against an actively exploited vulnerability by Saturday. Tracked as CVE-2026-8452, this high-severity security flaw stems from a memory overflow weakness affecting NetScaler ADC and NetScaler Gateway appliances configured with Gateway VPN or AAA (Authentication, Authorization, and Auditing)

CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday Read More »

Carhartt data breach exposes information of 12.9 million accounts

The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned. Founded in 1889, Carhartt is an American apparel company with workwear and streetwear manufacturing facilities in Kentucky and Tennessee and more than 3,000

Carhartt data breach exposes information of 12.9 million accounts Read More »

Webinar: How Google Workspace breaches happen and what to do next

Google Workspace has become a critical part of how fast-growing companies operate, giving employees access to email, files, applications, and other business resources. But when attackers find a way into that environment, the same connectivity can create opportunities for a breach to spread. On September 23, 2026, BleepingComputer will host a live webinar titled “Breach

Webinar: How Google Workspace breaches happen and what to do next Read More »