Security news.
Today's security landscape highlights a mix of sophisticated attacks and critical patching efforts. From a new GPU exploit bypassing NVIDIA ECC to ongoing Chinese state-sponsored espionage and widespread exploitation of known vulnerabilities, defenders face continuous challenges in securing diverse digital infrastructures.
New GPUThor Attack Bypasses NVIDIA ECC for Root Access
A novel Rowhammer attack, GPUThor, can defeat error-correcting code (ECC) protections on NVIDIA GPUs, leading to denial-of-service and root-level privilege escalation.
CISA Adds Six Actively Exploited Vulnerabilities to KEV Catalog
CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, including flaws in Red Hat, Microsoft SQL Server, and Ajax.NET Professional, based on evidence of active exploitation.
FBI Disrupts China-Linked QTFY Infrastructure Targeting U.S. Orgs
The FBI and DoJ announced the disruption of QScan and QTRouter, two hacking platforms operated by Chinese state-sponsored group QTFY, used to steal data from critical infrastructure and sensitive networks.
Hackers Target Microsoft SharePoint RCE Chain with PoC Exploit
Attackers are actively exploiting a chain of two Microsoft SharePoint vulnerabilities to achieve arbitrary code execution on unpatched servers.
Ubiquiti Patches Three Max-Severity Remote Exploitable Vulnerabilities
Ubiquiti has released security patches addressing three maximum-severity vulnerabilities that can be exploited remotely without privileges.
Android Malware Hijacks Update System for Car Head Units
Threat actors behind a prominent click-fraud botnet are now targeting vehicle infotainment modules, abusing legitimate update functionality to spread infections.
Boston Scientific Reports Cyberattack Disrupting Global Operations
Medical technology company Boston Scientific has confirmed a cyberattack that caused global operational disruptions by impacting some of its IT systems.
Unpatched Kaltura mwEmbed Flaws Allow Remote File Read and Code Execution
CERT/CC disclosed two unpatched vulnerabilities (CVE-2026-19913, CVE-2026-19912) in Kaltura's HTML5 video player library, enabling remote, unauthenticated attackers to read arbitrary files and execute code.