Google has released Chrome 152.0.7977.75/.76 for Windows and macOS and Chrome 152.0.7977.75 for Linux, addressing 26 security vulnerabilities across the browser.
The update includes two critical use-after-free flaws affecting Shared Tab Groups and WebGL, making prompt installation important for both...
A newly disclosed vulnerability in Hugging Face Transformers could allow malicious AI model repositories to place attacker-controlled Python files on a user’s system before the user approves remote code execution.
Tracked as CVE-2026-80047, the issue affects Hugging Face Transformers versions...
Two critical vulnerabilities affecting Langflow and Ruby on Rails deployments are being actively exploited, with attackers quickly moving from public disclosure to reconnaissance, secret harvesting, and potential remote code execution, according to VulnCheck telemetry.
The first issue, tracked as CVE-2026-0768,...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities affecting PaperCut NG and PaperCut MF to its Known Exploited Vulnerabilities (KEV) Catalog, warning that threat actors are actively exploiting the flaws in real-world attacks.
The flaws,...
D-Link has released a firmware update for critical access-control and information-disclosure flaws affecting its DIR-X1860Z router.
The vulnerabilities could allow an unauthenticated attacker connected to the local network to change the router administrator password and recover wireless configuration details, including...
ServiceNow has released security updates for four vulnerabilities in its Now Platform and ServiceNow AI platform, including three critical flaws that could allow unauthenticated attackers to execute code, access sensitive instance data, modify records, or escalate privileges.
The company published...
A critical attack chain could let attackers within Bluetooth range take full control of Unitree G1 humanoid robots, gaining root-level code execution on the locomotion computer that controls movement, cameras, speakers, voice features, and other peripherals.
The flaws could allow...
Threat actors are increasingly abusing overlooked Active Directory service principal name (SPN) misconfigurations to launch stealthier Kerberoasting attacks, turning ordinary user accounts into high-value credential targets.
The technique, dubbed “Ghost SPN” by Trellix researchers, can allow an intruder with delegated...
A newly disclosed vulnerability in cPanel and WHM, the widely used web hosting control panel software, could let a low-privileged, authenticated user seize root-level control of an entire server.
Tracked as CVE-2026-65643, the flaw resides in cPanel's domain parking functionality...
PaperCut has confirmed that hackers are actively exploiting an unpatched vulnerability in its widely used PaperCut NG and PaperCut MF print management software, prompting the company to rush out an emergency patch just hours after issuing its first warning.
The...