CISA says ransomware crews now exploit TeamCity CVE-2026-63077. Upgrade to 2025.11.7 or 2026.1.3, take the server off the Internet, and check for compromise.
A pre-auth SQL injection in Roundcube's virtuser_query plugin is now exploited. Update to 1.6.16 or 1.7.1 or disable the plugin. Here's what to check today.
A cPanel CalDAV/CardDAV flaw lets any hosting account run code as root. Update to 11.134.0.57, 11.136.0.41 or 11.138.0.8, plus WP Toolkit 6.11.3, today.
GitLab's issue-by-email address carries an account-wide token that can push code and run CI jobs past IP allowlists. How to rotate it and check for misuse.
Friday's 5-minute cyber brief: ransomware on TeamCity build servers, exploited Roundcube webmail, cPanel root for any account, and a risky GitLab email token.
CompTIA CySA+ V4 (CS0-004) study guide for 2026: domains, V3 retirement timeline, a practical lab-first plan, and how CySA+ fits…
Attackers went from probing to writing PHP in under a day. Verify you’re on a fixed release....
If auth sits in a Tomcat security constraint, an alternate endpoint name can skip it....
No known exploit yet — that’s the window, not a reason to wait....
Shared kernel, pre-auth, PoCs out. Role checks won’t save you....
WordPress under active exploitation, Tomcat WebSocket bypass, Palo Alto HIGHEST urgency, SAP OVERPASS with public PoCs....
AI security tools can miss threats when attackers craft adversarial inputs. Here’s how malware, phishing, and behavior models get fooled…
CISA added two Check Point CVSS 9.8s to KEV yesterday. Federal due September 25 — patch gateways and management Jumbo…