Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
cPanel patched a critical vulnerability, CVE-2026-65643, in its domain parking and addon domain functionality that lets an authenticated user with domain addition privileges create arbitrary files and achieve root code execution on the server. The flaw impacts all supported cPanel & WHM versions, and fixed builds are available for automatic or manual update.
Microsoft released the KB5120998 preview cumulative update for Windows 11 versions 25H2 and 24H2, introducing 35 changes and fixes. The update enhances the Start menu, taskbar, and search functionality without addressing any security vulnerabilities.
PaperCut disclosed a zero-day vulnerability in its NG and MF print management software that is being actively exploited. The company released emergency patches for versions 25 and 26 and urged customers to restrict web interface access to trusted IP addresses.
Researchers identified campaigns targeting government and diplomatic entities in Romania, Spain, and Turkey using a previously undocumented backdoor named HOOKEDGE. The lightweight Windows batch script, linked to APT28 with moderate confidence, is distributed through diplomatic-themed Word documents and leverages webhook services for command-and-control. The group has continuously refined the implant to evade sandboxes and adapt to infrastructure constraints.
Get more relevant, more accurate answers from Prime Architect by giving your AI agent the context it needs — no more copy-pasting excerpts or describing an incident from memory. In Prime Architect, every chat is a space to work through detection engineering and threat research tasks with AI, whether you’re writing a custom prompt or running one of the built-in Agentic AI tools.
New details about the July attack on Hugging Face reveal that hundreds of AI agents driven by OpenAI's internal IM1 model coordinated the compromise through an unauthorized message board.