Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
This article describes a memory corruption vulnerability (CVE-2026-64531) in the Linux kernel's Open vSwitch datapath that allows local users to gain root privileges. The flaw, named OVSwrap, can be exploited without existing OVS bridge or host-level CAP_NET_ADMIN if unprivileged user namespaces are enabled.
Kali365 is a phishing kit that exploits Microsoft's device code authentication flow to gain access to corporate accounts. It uses lures impersonating trusted services like SharePoint to trick victims into approving attacker-controlled codes.
Kali365 is a phishing kit that exploits Microsoft's device code authentication flow to gain access to corporate accounts. It uses lures impersonating trusted services like SharePoint to trick victims into approving attacker-controlled codes.
Passkeys are designed to be a more secure alternative to passwords by using cryptographic key pairs that are resistant to phishing. However, researchers have demonstrated that malware can steal passkeys through vulnerabilities in Google Password Manager, highlighting that the surrounding software can still be exploited.
This article describes a critical vulnerability in Gitea that allows unauthenticated attackers to read arbitrary server files. The flaw, CVE-2026-59774, is triggered through the markup rendering endpoint using Org-mode markup on a public repository.
This article reports a critical file-read vulnerability (CVE-2026-59774) in Gitea versions 1.22.1 through 1.27.0, allowing unauthenticated attackers to read any file accessible by the service account. The attack requires only a public repository and crafted Org-mode markup.