🚨 A public PoC has been released for CVE-2026-49176.
The vulnerability affects Microsoft Windows 10 Version 1607 and allows a local privilege escalation (LPE) due to improper privilege management in Windows WalletService.
🔗 https://t.co/oxhXTMtPEZ
#Windows#Microsoft#CVE
🚨 AI agents are increasingly being deployed with long-lived credentials, excessive privileges and poorly managed identities
If one is compromised, attackers can abuse its access to invoke tools, automate attack chains, and move across systems at machine speed #AI#CyberSecurity
🚨 CVE-2026-58319: A vulnerability in Apache Doris allows unauthenticated attackers to access FE HTTP admin APIs.
Users should upgrade to Apache Doris 3.1.0 to mitigate the issue.
#ApacheDoris#CyberSecurity#CVE
A newly disclosed OpenSSL “HollowByte” vulnerability allows remote DoS attacks using as little as 11 bytes of malicious data.
Organizations running affected OpenSSL versions should apply available mitigations and updates as soon as possible.
#OpenSSL#CyberSecurity#DoS
🌟 At just 19 years old, he becomes only the sixth player in football history to achieve this milestone.
Congratulations to Spain on winning the 2026 FIFA World Cup! 🏆🇪🇸
🚨 UPDATE: A public PoC is now available for CVE-2026-63030 (wp2shell).
The flaw exploits an unauthenticated SQL injection in WordPress core and can be chained into RCE via REST batch route confusion.
🔗 https://t.co/zhBVQLiB9n
#WordPress#CyberSecurity#RCE
🚨 MetaMask narrowly avoided a supply chain attack.
A North Korean developer, posing as “Tyler Knapp,” contributed to MetaMask’s core code for nearly a month before being detected
Consensys revoked access, paused releases, and confirmed no backdoors or fund compromise #MetaMask
🚨 RWT Token was exploited on BNB Chain, resulting in an estimated $118K loss.
The attacker abused a logic flaw in an unprotected sell() function, combined with a flash loan, to manipulate the RWT/USDT liquidity pool and drain funds.
💸 Estimated loss: ~118K USDT
#DeFi#Crypto
🚨 Attackers exploited two SonicWall SMA 1000 zero-days before they were publicly disclosed, gaining root access to targeted devices.
The activity has been linked to UTA0533, which deployed custom malware and captured unencrypted LDAP credentials from compromised VPN appliances.
🚨 UPDATE: The #wp2shell attack chain now includes two CVEs, and a public PoC is available.
• CVE-2026-63030 — REST batch routing bypass
• CVE-2026-60137 — SQL injection
When chained together, they can allow unauthenticated remote code execution (RCE) on vulnerable WordPress
🚨 Critical WordPress wp2shell flaw now blocked by Cloudflare’s emergency WAF rules. Website owners should update without delay to prevent potential RCE attacks.
#WordPress#Infosec#CyberSecurity
🚨 CVE-2026-15682: A zero-day vulnerability in AnyDesk could allow local attackers to abuse the Send Support Information feature to write files outside their intended location, potentially causing application crashes.
#CyberSecurity#CVE#AnyDesk#ZeroDay#ThreatWire
@ajs6888 You’re right. The source is public, but xAI explicitly keeps GitHub Issues and external PRs closed. The goal is transparency, not community-driven development.
🚨 Grok Build: Grok Build has been released as open source, with data sharing disabled by default. While the code is publicly available, GitHub Issues and Pull Requests remain closed.
#AI#OpenSource#Grok#TechNews
🚨 CVE-2026-42533, CVE-2026-60005 & CVE-2026-56434: F5 has disclosed three high-severity vulnerabilities affecting NGINX Plus and NGINX Open Source, potentially leading to memory corruption, worker crashes, or remote code execution.
#CyberSecurity#CVE#NGINX#F5#ThreatWire
🚨 CVE-2026-14266: A 7-Zip vulnerability (CVSS 7.0) could allow remote code execution (RCE) via specially crafted XZ archives. Update to 7-Zip 26.02. No active exploitation has been confirmed.
#CyberSecurity#CVE#7Zip#RCE#ThreatWire
🚨 n8n Enterprise Vulnerability: A flaw in n8n’s Enterprise token exchange could allow a valid JWT from one trusted issuer to authenticate as a different user, potentially leading to account takeover.
#CyberSecurity#JWT#n8n#ThreatWire
🚨 CVE-2026-15378: A blind SSRF vulnerability in Red Hat OpenShift AI could expose cloud credentials and Kubernetes secrets through the guardrails-detectors component.
#CyberSecurity#CVE#OpenShift#Kubernetes#ThreatWire
🚨 Suno Breach: AI music company Suno was reportedly breached using the Shai-Hulud worm, exposing source code, customer data, and details of its AI training datasets. The company says the incident occurred in November 2025.
#CyberSecurity#DataBreach#AI#ThreatWire