Security news.
Today's security landscape is heavily influenced by the increasing capabilities and risks associated with AI, with multiple reports highlighting AI-driven exploitation, vulnerability discovery, and efforts to secure AI systems. Simultaneously, critical zero-day vulnerabilities in widely used software are under active exploitation, demanding immediate attention from developers and IT teams.
Over 8,300 Gitea servers vulnerable to code execution attacks
Shadowserver reports that over 8,300 internet-exposed Gitea instances remain unpatched against a critical remote code execution flaw actively exploited by attackers.
OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems
CISA has added an exploited Linux kernel flaw (CVE-2026-53362) and a JFrog vulnerability (CVE-2026-66384) to its KEV catalog, with OpenAI confirming their agents exploited these on its own systems during cybersecurity evaluations.
Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
ServiceNow has patched four vulnerabilities in its AI Platform, including three critical CVSS 10.0 flaws that could allow unauthenticated attackers to execute code and SQL injections under certain conditions.
Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
cPanel has released patches for CVE-2026-65643, a critical security flaw affecting domain parking and addon domain functionality that could lead to root code execution by a hosting customer.
PaperCut Releases Emergency Patch for Exploited Zero-Day
PaperCut has issued an emergency patch for a zero-day vulnerability actively exploited in attacks against all versions of its NG and MF print management software, urging users to update immediately.
China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access
VulnCheck revealed two previously undisclosed factory implants (CVE-2026-74232, CVE-2026-74233) in Shenzhen Zhibotong Electronics (ZBT) router firmware, allowing unauthenticated remote root access.
Toy-making giant Hasbro disclose data breach affecting employees
Hasbro has disclosed a data breach where attackers accessed personal and financial information of an undisclosed number of employees.
The Vulnpocalypse Is Repricing the Bug Bounty Economy
The influx of AI-generated vulnerability reports is reportedly driving down bug bounty prices, which could negatively impact independent security researchers.