Jira, Confluence Among Eight Atlassian Products Under Attack Attackers are targeting an Atlassian vulnerability affecting eight products, including Jira, Confluence, and Bitbucket. The flaw allows unauthenticated access to files in self-hosted deployments when attackers know the exact file path. Attackers began probing the flaw within hours of the PoC becoming public, showing just how quickly …
Cybersecurity
Chrome 155 Patches 247 Flaws, Four Critical Google is giving you 247 fresh reasons to finally hit that update button for Chrome on Windows, macOS, and Linux. The massive patch drops the hammer on four critical use-after-free bugs and 53 high-severity issues. While memory-safety flaws like these are practically an open invitation for remote code …
GitLab Patches AI Gateway RCE GitLab patched a CVSS 9.9 flaw that could let authenticated users escape its self-hosted AI Gateway sandbox and execute system commands. These gateways can contain sensitive authentication material and connect the platform’s AI features to underlying AI infrastructure. AI security conversations tend to focus heavily on prompts and model behavior, …
NetScaler Needs Another Patch as Attacks Hit Just when you thought you were done patching, attackers are exploiting a new NetScaler zero-day, CVE-2026-88779, to crash customer-managed ADC and Gateway appliances configured as SAML services or identity providers. Constant abuse forces services offline, and unfortunately, your patches for earlier zero-days don’t fix this new flaw. Install …
AI Agents Leak 13,000 Internal Images on GitHub More than 13,000 internal images from 300 organizations were exposed on GitHub after AI coding agents found ways to share screenshots. About 93% of the images were stored under employees’ personal GitHub accounts, putting much of the activity outside normal corporate repository monitoring. The 93% figure shows …
WatchGuard VPN Flaw Opens Door to Root Access WatchGuard patched a Fireware vulnerability that could allow a malicious VPN server to execute commands as root on a connected Firebox appliance. CVE-2026-86131 impacts specific BOVPN over TLS client configurations, although WatchGuard says it has not observed exploitation in the wild. If you’re using these appliances, the …
Spectre Leaks Linux Root Hash in Minutes A new Spectre v2 attack dubbed Branch Target Reuse (BTR) can leak a Linux root password hash in three to five minutes on tested Intel systems. It exploits stale CPU predictions lingering after just-in-time code changes. Before you panic-format your drives, know that this local lab exploit required …
BigCommerce Stores Exposed Through Compromised App Attackers used stolen Ribon credentials to access merchant customer data without breaching BigCommerce’s core platform. Exposed information included customer names, email addresses, phone numbers, and shipping addresses, creating potential opportunities for follow-on social engineering. I’d use this incident to ask how much customer data an attacker could reach if …
OpenAI Hits Pause After Agent Finds a DNS Exit The AI looked at its secure sandbox, laughed, and walked right out the DNS side door. OpenAI suspended tool-enabled training and testing for its most advanced models after an internal agent casually dodged internet restrictions to chat with an outside bot. Tasked with the mundane chore …
WordPress Core Flaw Draws Rapid RCE Attempts Threat actors wasted no time turning a patch into an exploit manual, probing WordPress sites less than five hours after the fix for CVE-2026-87902 dropped. Patchstack later observed this activity rapidly escalate to dropping malicious PHP files. The critical Core flaw affects versions 4.7.0 through 7.1.1 and permits …