vulnerability

cPanel 0-Day Authentication Bypass Vulnerability Actively Exploited in the Wild

A critical authentication bypass vulnerability (CVE-2026-41940) in cPanel & WHM has been actively exploited in the wild, allowing unauthenticated attackers to gain root-level access to hosting control panels. With a public proof-of-concept exploit released, cPanel has issued emergency patches and urged administrators to update immediately to prevent widespread compromise across millions of hosting accounts globally.

https://cybersecuritynews.com/cpanel-0-day-authentication-bypass-vulnerability/

Linux Kernel 0-Day “Copy Fail” Roots Every Major Distribution Since 2017

A critical zero-day vulnerability named “Copy Fail” (CVE-2026-31431) in the Linux kernel, affecting every major distribution since 2017, allows any unprivileged local user to gain root access by exploiting a flaw in the kernel's cryptographic template via the AF_ALG socket and splice() system call. The vulnerability, discovered by Theori and exploited by Xint Code Research Team, enables file page cache corruption undetectable by integrity tools, and also facilitates Kubernetes container escapes; a patch has been released and administrators are urged to update immediately.

https://cybersecuritynews.com/linux-kernel-0-day-copy-fail/

Wiz Hands GitHub AI-aided Bug Report That Isn’t Total Slop

Wiz researchers discovered a high-severity vulnerability (CVE-2026-3854) in GitHub's git infrastructure that allowed remote attackers full read/write access to private repositories using a single command. By leveraging AI-augmented tools for automated reverse engineering, they rapidly identified the flaw, leading to GitHub issuing fixes within six hours and awarding Wiz one of the largest payouts in its bug bounty history.

https://www.theregister.com/2026/04/29/github_woah_a_genuinely_helpful/

Critical Chrome Vulnerabilities Enables Remote Code Execution Attacks

Google has released a critical update for Chrome version 147.0.7727.137/138 that fixes 30 security vulnerabilities, including four severe use-after-free flaws enabling remote code execution attacks. Users and enterprises are strongly urged to update their browsers immediately to protect against remote attacks that could bypass Chrome’s sandbox and compromise systems without additional user interaction.

https://cybersecuritynews.com/chrome-vulnerabilities-2/

CISA Warns Microsoft Windows Shell 0-Click Vulnerability Exploited in Attacks

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about a critical zero-day vulnerability in the Microsoft Windows Shell, tracked as CVE-2026-32202, which is actively being exploited. This vulnerability allows attackers to perform network spoofing, potentially intercepting sensitive data and bypassing access controls, prompting CISA to mandate immediate patching by May 12, 2026, particularly for federal agencies, while strongly urging all organizations to apply mitigations to protect their networks.

https://cybersecuritynews.com/windows-shell-0-click-vulnerability/

Cursor AI Coding Agent Vulnerability Allow Attackers to Execute Code on Developer’s Machine

A high-severity vulnerability (CVE-2026-26268) in Cursor, an AI-powered coding environment, allows attackers to execute arbitrary code remotely on a developer’s machine by simply getting them to clone a malicious Git repository. The exploit leverages legitimate Git features—embedded bare repositories and Git hooks—triggering malicious scripts automatically without user interaction when the Cursor AI agent processes the repository, posing a significant risk to developer environments and organizational infrastructure.

https://cybersecuritynews.com/cursor-ai-coding-agent-vulnerability/

Microsoft Confirms Active Exploitation of Windows Shell CVE-2026-32202

Microsoft has confirmed active exploitation of a high-severity Windows Shell vulnerability (CVE-2026-32202) that allows unauthorized attackers to perform spoofing and access sensitive information. This zero-click exploit, linked to an incomplete patch for CVE-2026-21510 and used by the Russian state-sponsored group APT28, enables credential theft through automatic network authentication when victims open malicious Windows Shortcut files, highlighting ongoing risks despite recent patches.

https://thehackernews.com/2026/04/microsoft-confirms-active-exploitation.html

FIRESTARTER: Cisco ASA Backdoor

On April 23, 2026, CISA and the UK National Cyber Security Centre revealed FIRESTARTER, a persistent backdoor implant targeting Cisco Adaptive Security Appliance firmware via CVE-2025-20333 and CVE-2025-20362, enabling advanced persistent threat actor UAT-4356 (linked to the earlier ArcaneDoor campaign) to maintain long-term access even after patching and rebooting. The malware hooks into Cisco’s core LINA process to execute attacker shellcode triggered by specially crafted WebVPN requests, requiring a hard power cycle or full device reimaging to fully remove, highlighting a serious evolution in firmware-level threats that challenge conventional patch-and-monitor security models.

https://thecyberthrone.in/2026/04/28/firestarter-cisco-asa-backdoor/

Exploits Turn Windows Defender Into Attacker Tool

Threat actors are exploiting three publicly available proof-of-concept vulnerabilities—BlueHammer, RedSun, and UnDefend—to turn Microsoft Defender's built-in security functions against the systems it is meant to protect, enabling SYSTEM-level access and disrupting update mechanisms. While Microsoft has patched BlueHammer, the other two remain unpatched, and these exploits are actively used in targeted attacks that highlight systemic validation weaknesses in Defender’s privileged workflows, underscoring the need for updated defenses and multi-factor authentication for remote access.

https://www.darkreading.com/cyberattacks-data-breaches/exploits-turn-windows-defender-attacker-tool

We Found a Stable Firefox Identifier Linking All Your Private Tor Identities

Researchers discovered a privacy vulnerability in Firefox-based browsers whereby the order of IndexedDB databases returned by the indexedDB.databases() API serves as a stable, process-scoped identifier. This allows unrelated websites to link user activity across origins and defeats privacy features in Firefox Private Browsing and Tor Browser, including Tor's “New Identity” function, by exposing a deterministic fingerprint until the browser process restarts. Mozilla has released a fix that canonicalizes the database order to eliminate this leakage and restore expected privacy guarantees.

https://fingerprint.com/blog/firefox-tor-indexeddb-privacy-vulnerability/

How a Roblox Cheat and One AI Tool Brought Down Vercel’s Entire Platform

In early 2026, a security breach at Vercel was triggered by an employee at Context.ai downloading a Roblox cheat bundled with Lumma Stealer malware, which compromised internal systems and enabled attackers to access non-sensitive environment variables stored by Vercel. This incident exposed the risks posed by broad OAuth permissions granted to third-party AI tools and highlighted how non-sensitive environment variables were less protected, prompting Vercel to change its default encryption settings; the breach has led to widespread credential rotations and raised concerns over the security trade-offs in AI tooling and developer convenience.

https://webmatrices.com/post/how-a-roblox-cheat-and-one-ai-tool-brought-down-vercel-s-entire-platform

Mozilla: Anthropic’s Mythos Found 271 Zero-Day Vulnerabilities in Firefox 150

Mozilla reported that Anthropic’s AI model Mythos Preview identified 271 security vulnerabilities in the unreleased Firefox 150 source code, significantly more than previous AI models. Mozilla’s CTO stated that AI tools like Mythos could decisively shift cybersecurity defenses by making vulnerability detection faster and more efficient, potentially transforming how software security is maintained.

https://arstechnica.com/ai/2026/04/mozilla-anthropics-mythos-found-271-zero-day-vulnerabilities-in-firefox-150/

All Vulnerabilities Are Exploitable: The New Reality of Software Risk

Javed Hasan, CEO and Cofounder of Lineaje, explains that rapid software evolution and AI-generated code have made all software vulnerabilities potentially exploitable, as automated tools can quickly create working exploits. He argues that traditional vulnerability management is outdated, urging organizations to adopt continuous security practices that assume every vulnerability can be weaponized, embedding security directly into development with automated governance to reduce risk in dynamic software environments.

https://www.cybersecurity-insiders.com/all-vulnerabilities-are-exploitable-the-new-reality-of-software-risk/

Fracturing Software Security With Frontier AI Models

Unit 42's research reveals that frontier AI models significantly enhance the ability to autonomously discover software vulnerabilities, accelerating the exploitation of zero-day and N-day flaws and enabling complex attack chains at unprecedented speed and scale. These advancements pose heightened risks to open-source software and software supply chains, as AI-driven attacks can rapidly identify and exploit vulnerabilities, necessitating stronger prevention, rapid patching, and automated incident response strategies for security teams.

https://unit42.paloaltonetworks.com/ai-software-security-risks/

Critical Anthropic’s MCP Vulnerability Enables Remote Code Execution Attacks

A critical architectural vulnerability in Anthropic’s Model Context Protocol (MCP) SDK exposes over 150 million downloads to remote code execution (RCE) attacks, potentially compromising up to 200,000 servers. Identified by OX Security, the flaw enables attackers to take full control of affected environments, gaining access to sensitive data and internal systems; despite recommendations, Anthropic has not applied a protocol-level fix, leaving several projects vulnerable.

https://cybersecuritynews.com/anthropics-mcp-vulnerability/

Scroll to Top