Skip to Content

Jira, Confluence Among Eight Atlassian Products Under Attack Attackers are targeting an Atlassian vulnerability affecting eight products, including Jira, Confluence, and Bitbucket. The flaw allows unauthenticated access to files in self-hosted deployments when attackers know the exact file path. Attackers began probing the flaw within hours of the PoC becoming public, showing just how quickly …

Read More about Security News Update: How to Protect Self-Hosted Jira and Confluence From Atlassian File Access Vulnerability? and more

Chrome 155 Patches 247 Flaws, Four Critical Google is giving you 247 fresh reasons to finally hit that update button for Chrome on Windows, macOS, and Linux. The massive patch drops the hammer on four critical use-after-free bugs and 53 high-severity issues. While memory-safety flaws like these are practically an open invitation for remote code …

Read More about Security News Update: Why Is Google Prompting Me to Update Chrome 155 Right Now? and more

GitLab Patches AI Gateway RCE GitLab patched a CVSS 9.9 flaw that could let authenticated users escape its self-hosted AI Gateway sandbox and execute system commands. These gateways can contain sensitive authentication material and connect the platform’s AI features to underlying AI infrastructure. AI security conversations tend to focus heavily on prompts and model behavior, …

Read More about Security News Update: How to Patch CVSS 9.9 RCE Vulnerability in GitLab AI Gateway? and more

NetScaler Needs Another Patch as Attacks Hit Just when you thought you were done patching, attackers are exploiting a new NetScaler zero-day, CVE-2026-88779, to crash customer-managed ADC and Gateway appliances configured as SAML services or identity providers. Constant abuse forces services offline, and unfortunately, your patches for earlier zero-days don’t fix this new flaw. Install …

Read More about Security News Update: How to fix NetScaler CVE-2026-88779 zero-day vulnerability on Gateway appliances? and more

AI Agents Leak 13,000 Internal Images on GitHub More than 13,000 internal images from 300 organizations were exposed on GitHub after AI coding agents found ways to share screenshots. About 93% of the images were stored under employees’ personal GitHub accounts, putting much of the activity outside normal corporate repository monitoring. The 93% figure shows …

Read More about Security News Update: Why Are AI Coding Agents Leaking Internal Screenshots on GitHub? and more

WatchGuard VPN Flaw Opens Door to Root Access WatchGuard patched a Fireware vulnerability that could allow a malicious VPN server to execute commands as root on a connected Firebox appliance. CVE-2026-86131 impacts specific BOVPN over TLS client configurations, although WatchGuard says it has not observed exploitation in the wild. If you’re using these appliances, the …

Read More about Security News Update: How Does WatchGuard Fireware VPN Flaw Grant Root Access to Firebox Appliances? and more

Spectre Leaks Linux Root Hash in Minutes A new Spectre v2 attack dubbed Branch Target Reuse (BTR) can leak a Linux root password hash in three to five minutes on tested Intel systems. It exploits stale CPU predictions lingering after just-in-time code changes. Before you panic-format your drives, know that this local lab exploit required …

Read More about Security News Update: How Can a Spectre Attack Leak Your Linux Root Password Hash in 3 Minutes? and more

BigCommerce Stores Exposed Through Compromised App Attackers used stolen Ribon credentials to access merchant customer data without breaching BigCommerce’s core platform. Exposed information included customer names, email addresses, phone numbers, and shipping addresses, creating potential opportunities for follow-on social engineering. I’d use this incident to ask how much customer data an attacker could reach if …

Read More about Security News Update: How Were BigCommerce Stores Exposed Through the Ribon App Integration? and more

OpenAI Hits Pause After Agent Finds a DNS Exit The AI looked at its secure sandbox, laughed, and walked right out the DNS side door. OpenAI suspended tool-enabled training and testing for its most advanced models after an internal agent casually dodged internet restrictions to chat with an outside bot. Tasked with the mundane chore …

Read More about Security News Update: How Did an OpenAI Agent Escape Its Sandbox Through a DNS Side Door? and more

WordPress Core Flaw Draws Rapid RCE Attempts Threat actors wasted no time turning a patch into an exploit manual, probing WordPress sites less than five hours after the fix for CVE-2026-87902 dropped. Patchstack later observed this activity rapidly escalate to dropping malicious PHP files. The critical Core flaw affects versions 4.7.0 through 7.1.1 and permits …

Read More about Security News Update: Is WordPress Site at Risk From New CVE-2026-87902 Core Vulnerability? and more