🚨 EXCLUSIVE: Manchester City found guilty on virtually all charges relating to breaches of Premier League financial regulations. #MCFC expected to appeal against verdict issued by independent commission. Sanctions undecided, process ongoing @TheAthleticFC https://t.co/Muxqp4beK9
I feel like the World Cup 3rd place play off should be played with the same spirit of a Sidemen charity match. There are no stakes reslly. Might as well give the fans a show to send them off.
🚨💣 BREAKING: Éderson to Manchester United, here we go!
Deal done with Atalanta for €45m package with add-ons included, agreement now in place.
Medical and formal steps to follow but deal in place.
Éderson will sign a four year deal plus option, as @TheAthleticFC reports.
The Mandalorian and Grogu is the best Star Wars movie since Rogue One. The story , the pacing, the action sequences, visual effects. Enjoyable watch from start to finish. Masterpiece.
We are excited to announce a major milestone for Uganda’s digital landscape. Today, @UCC_Official officially signed an operational license agreement with @Starlink, marking a definitive step toward the commencement of their satellite internet services in the country.
The signing was under the guidance of H.E. @KagutaMuseveni, who welcomed Starlink’s commitment to complying with Uganda’s laws and regulatory requirements.
This partnership aligns with @MoICT_Ug’s core mission of ensuring security, revenue assurance, and proper accountability within the telecommunications sector.
The agreement was witnessed by our Permanent Secretary, @azawedde , U.S. Ambassador to Uganda, H.E. William Popp, H.E. @RobieKakonge_, Uganda’s Ambassador to the USA and Mr. @ryangoodnight , Senior Director at @SpaceX
As we welcome Starlink to the Pearl of Africa, we remain committed to fostering an environment where innovative technology meets robust regulation for the benefit of all Ugandans.
❗️🚨 Microsoft Edge keeps every saved password in process memory as cleartext from the moment it launches. Microsoft's responsed when reported: "by design."
All of them. Including credentials for sites you won't open this session.
Researcher @L1v1ng0ffTh3L4N tested every major Chromium browser. Edge is the only one that behaves this way.
Chrome decrypts credentials on demand, and App-Bound Encryption locks the keys to an authenticated Chrome process so other processes can't reuse them.
In Chrome, plaintext surfaces only during autofill or when a password is viewed, making memory scraping far less useful.
What makes this extra weird is that Edge still demands re-authentication before revealing those passwords in its Password Manager UI, while the same browser process already holds every one of them in plaintext.
In shared environments, this turns into a credential harvest. On a terminal server, an attacker with admin rights can read the memory of every logged-on user process. In the published PoC video, a compromised admin account lifts stored credentials from two other logged-on (and even disconnected) users with Edge running.
Microsoft's official response when notified: "by design."
The finding was disclosed April 29 at BigBiteOfTech by PaloAltoNtwks Norway, alongside a small educational tool that lets anyone verify the cleartext storage for themselves.
🚨 BREAKING: cPanel and WHM, the control panels behind an estimated 70+ million websites, have a critical security flaw that lets anyone become root admin without a password. CVE-2026-41940 affects every supported version. It’s already being exploited in the wild.
watchTowr Labs published the full attack today, after the hosting company KnownHost confirmed the bug was already being used to break into a significant chunk of the internet.
If you've never heard of cPanel: it's the dashboard that hosting providers and millions of website owners use to manage their servers, domains, email accounts, databases, and SSL certificates. WHM is the admin version that controls the entire server. If someone gets root access to WHM, they get the keys to the kingdom and to every apartment inside it.
How the attack works, in plain English:
🔴 Step 1: The attacker sends a deliberately wrong login. cPanel still creates a temporary "you tried to log in" record on disk and gives the attacker a cookie tied to it.
🔴 Step 2: The attacker tweaks the cookie to disable cPanel's password encryption. Normally cPanel encrypts the password field on disk. With one small change to the cookie, cPanel just stores it as plain text instead.
🔴 Step 3: The attacker sends a fake login attempt where the password field secretly contains hidden line breaks. cPanel does not strip these line breaks out, so they get written straight to the session file. Each line break creates a brand new fake record. The attacker uses this to inject lines that say "this user is root" and "this user already authenticated successfully."
🔴 Step 4: The attacker visits one more random page on the site to nudge cPanel into re-reading the file. cPanel then promotes the injected fake lines into its main session memory.
🔴 Step 5: On the next request, cPanel sees a flag that says "this user already passed the password check." cPanel trusts that flag, skips checking the actual password, and lets the attacker in as root.
From start to finish, the attack takes a handful of HTTP requests.
If you run cPanel or WHM, the patched versions are:
🔴 cPanel/WHM 110.0.x → 11.110.0.97
🔴 cPanel/WHM 118.0.x → 11.118.0.63
🔴 cPanel/WHM 126.0.x → 11.126.0.54
🔴 cPanel/WHM 132.0.x → 11.132.0.29
🔴 cPanel/WHM 134.0.x → 11.134.0.20
🔴 cPanel/WHM 136.0.x → 11.136.0.5
If your version is older than these, assume someone has already broken in and act accordingly. Patch right now, then rotate every password and key the server touched: root passwords, API tokens, SSL private keys, SSH keys, mail passwords, and database passwords.