Critical cPanel Zero-Day Exploited in Sorry Ransomware Wave
CVE-2026-41940 in cPanel exploited as zero-day, deploying Sorry ransomware across 44,000+ servers. CISA mandates immediate patching.
Read more →Latest cybersecurity news, vulnerabilities, and threat intelligence
CVE-2026-41940 in cPanel exploited as zero-day, deploying Sorry ransomware across 44,000+ servers. CISA mandates immediate patching.
Read more →
Chinese espionage operation SHADOW-EARTH-053 deploys ShadowPad across eight countries targeting governments, defense, and journalists.
Read more →
Apache patches CVE-2026-23918, a double-free flaw in mod_http2 enabling RCE with two HTTP/2 frames. Immediate upgrade to 2.4.67 urged.
Read more →
Anthropic accidentally leaked Claude Code source code via an npm source map file, exposing unreleased features and internal security mechanisms.
Read more →
BeyondTrust discloses CVE-2026-1731, a critical 9.9 CVSS pre-auth RCE flaw affecting Remote Support and Privileged Remote Access with 11,000 exposed instances.
Read more →
Rapid7 attributes Notepad++ supply chain attack to Chinese APT Lotus Blossom. Chrysalis backdoor deployed to targets across Asia and Americas.
Read more →
Attackers compromised eScan antivirus update servers, deploying multi-stage malware to hundreds of systems across Asia.
Read more →
Two US cybersecurity professionals plead guilty to operating as BlackCat ransomware affiliates, extorting $1.2M from victims including healthcare organizations. Face 20 years in prison.
Read more →
Critical CVE-2026-0625 (CVSS 9.3) in legacy D-Link DSL routers actively exploited. Unauthenticated attackers can execute commands and hijack DNS. No patches available.
Read more →
Chinese-linked threat actors exploit three VMware ESXi zero-days (CVE-2025-22224, CVSS 9.3) to escape VMs and compromise hypervisors using sophisticated MAESTRO toolkit.
Read more →