Security news.
Today's cybersecurity landscape is heavily influenced by AI, with new research highlighting its weaponization by adversaries and exposing vulnerabilities in AI-powered tools. Critical flaws in widely used systems like cPanel, TP-Link Omada, and N-able N-central are also being actively exploited, underscoring the ongoing need for vigilant patching and robust security practices.
cPanel Critical Flaw Allows Database Root SQL Execution
cPanel has patched a critical vulnerability (CVE-2026-58048, CVSS 9.4) that allowed authenticated hosting customers to execute SQL commands in the database's root context, bypassing account privilege boundaries.
AI Notetaker Vulnerability Exposes Government, Corporate Calls
A Google Firebase misconfiguration in the AI meeting tool tl;dv allowed users to query other users' meeting information and potentially join video calls, exposing sensitive government and corporate discussions.
TP-Link Omada Flaws Lead to Full Network Takeover
Researchers discovered 15 new vulnerabilities in the TP-Link Omada networking ecosystem that can be chained together to achieve a complete network takeover.
Google Deletes ADK AI Workflows After Privileged Agent Attack
Google removed three AI agent workflows from its Agent Development Kit (ADK) Python repository after research showed a public GitHub issue could manipulate a triage agent to trigger a privileged code-fixing agent.
N-able N-central Flaw Actively Exploited, Added to CISA KEV
CISA has added an N-able N-central authentication bypass vulnerability (CVE-2026-18577, CVSS 8.2) to its Known Exploited Vulnerabilities catalog, confirming active exploitation of this incomplete patch for a previous flaw.
Decades-Old BMC Vulnerability Exposes Thousands of Data Centers
A long-standing vulnerability in Baseboard Management Controllers (BMC) exposes authentication hashes before login in over 24,000 internet-accessible server-management interfaces, leaving data centers open to attacks.
Midnight Blizzard Targets Hotel Wi-Fi to Breach Microsoft 365 Accounts
Microsoft has linked the Russian threat actor Midnight Blizzard (APT29) to a global campaign exploiting hotel Wi-Fi networks with custom malware to breach Microsoft 365 accounts and steal credentials.
Pass-ta-key Attacks Hijack Google-Synced Passkeys
Researchers uncovered three "Pass-ta-key" attacks that allow malware on compromised Windows devices to abuse Google Password Manager's synced passkeys, enabling account takeovers, user verification bypass, and private key extraction.