Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
GitLab Vulnerabilities Allow Attackers to Execute Remote Code on Default GitLab Installations
7+ hour, 49+ min ago (591+ words) A newly disclosed exploit chain in GitLab shows how two long-buried memory-safety flaws in a Ruby JSON parsing library, Oj, could be combined to achieve remote code execution on default GitLab installations, exposing source code, Rails secrets, and internal services....
Foxit Updater Vulnerability Gives Standard Users SYSTEM-Level Control of Windows Devices
21+ hour, 35+ min ago (409+ words) Foxit PDF Reader has been found vulnerable to a local privilege escalation flaw that allows standard Windows users to gain full SYSTEM-level control under specific conditions. The issue, tracked as CVE-2026-57239, was disclosed following research into Foxit’s updater and service…...
Tego AI Discloses Second Claude Flaw in a Week: Hidden Link Silently Sends Files to Attackers
1+ day, 7+ hour ago (986+ words) Tel Aviv, Israel, July 24th, 2026, CyberNewswire One week after disclosing that Anthropic’s Claude Tag Slack integration could be driven by plain “@Claude” text, Tego AI today published a second piece of research on the Claude ecosystem. This one focuses on Claude…...
Cl0p Hackers Exploit Windchill Servers to Steal Companies’ Secret Product Designs
1+ day, 12+ hour ago (534+ words) Cl0p ransomware affiliates are exploiting exposed PTC Windchill and FlexPLM servers to steal engineering and product-design data. The campaign combines software flaws to gain access without credentials, install hidden server-side access, and remove sensitive files before demanding payment. Attackers use a…...
Certighost Active Directory CS Exploit Allows Low-Privileged Users to Compromise Domain
1+ day, 8+ hour ago (432+ words) A newly disclosed Active Directory Certificate Services (AD CS) vulnerability, dubbed Certighost, allowed a low-privilege domain user to impersonate a Domain Controller and take over an entire Active Directory domain. Tracked as CVE-2026-54121, the flaw was patched in Microsoft’s July…...
How Infostealer Logs Became the Fuel Behind Massive Cloud Data Breaches
1+ day, 16+ hour ago (579+ words) Rather than breaking into networks, modern threat actors buy their way in by purchasing “stealer logs” containing valid usernames, passwords, session cookies, and SSO tokens harvested from infected endpoints, then replaying those sessions directly against cloud consoles, SaaS platforms, and…...
ChonkyChicken Malware Steals Chrome Credentials, Moves Laterally and Spies on Victims
1+ day, 13+ hour ago (490+ words) ChonkyChicken is a newly identified remote access trojan designed to turn one infected Windows device into a platform for credential theft, network movement, and surveillance. The malware is part of the TAG-195, also called Golden Chickens or Venom Spider, malware-as-a-service…...
JetBrains Fixes Critical IntelliJ IDEA Code Execution Flaw and Four TeamCity Vulnerabilities
1+ day, 13+ hour ago (445+ words) JetBrains has released security updates to address a critical code execution vulnerability in IntelliJ IDEA, alongside four high-severity vulnerabilities in TeamCity. Development teams and CI administrators are urged to apply these patches immediately to prevent potential remote attacks. JetBrains published…...
New HTTP/2 Vulnerability Lets Hackers Crash Servers With Memory Exhaustion Attacks
1+ day, 14+ hour ago (461+ words) The issue affects multiple HTTP/2 implementations that fail to manage resource consumption properly when handling stalled data flows, enabling attackers to degrade or completely disrupt services. HTTP/2, defined in RFC 9113, is widely used to improve web performance through multiplexing, header…...
FakeAgent Campaign Uses Malicious Bing Ads and Claude.ai Artifacts to Infect Corporate Users
1+ day, 13+ hour ago (808+ words) A dangerous new malware campaign is tricking corporate workers who simply want a desktop version of a popular AI assistant. Between July 21 and July 22, 2026, at least 29 organizations saw unusual software installs and hidden persistence on their systems after staff searched…...