Microsoft fixed 3 critical security issues in Microsoft 365 Copilot and Copilot Chat in Microsoft Edge. These were released on May 7, 2026, and users or admins don’t need to do anything. Microsoft’s Security Response Center shared updates on CVE-2026-26129, CVE-2026-26164, and CVE-2026-33111 to show their ongoing promise of openness …
Read More »New Ivanti EPMM 0-Day Vuln Actively Exploited in attacks
Ivanti has released an important security notice for its Endpoint Manager Mobile (EPMM) product. It reveals several serious weaknesses being used by attackers, like CVE-2026-6973, and asks all EPMM users to install updates right away. Ivanti said that CVE-2026-6973 is being actively used by hackers. This issue needs admin login …
Read More »Update Now! Google Chrome 148 Released Fix for 127 Security Vulns
Google has officially released Chrome 148 for Windows, Mac, and Linux. The new version is 148.0.7778.96 for Linux and 148.0.7778.96/97 for Windows and Mac. This update focuses a lot on security, fixing 127 issues all at once. Out of 127 vulnerabilities fixed, three are rated Critical, more than twenty are …
Read More »Palo Alto to Patch Zero-Day Flaw Exploited to Gain Root Access
Palo Alto Networks is fixing a serious PAN-OS zero-day flaw that was used to hack some of its firewall. Tracked as CVE-2026-0300, this issue is a buffer overflow that affects the User-ID Authentication Portal (Captive Portal) service of PAN-OS software. “Limited exploitation has been observed targeting Palo Alto Networks User-ID …
Read More »Critical 9.8 CVSS Flaws in Qualcomm Chipsets Allow Remote Takeover
Qualcomm has unveiled its May 2026 Security Bulletin, revealing serious flaws with its software and hardware. The bulletin points out several Critical issues that could let unauthorized users access and damage memory on millions of devices using Qualcomm chipsets. The company is sharing updates with Original Equipment Manufacturers (OEMs) and …
Read More »WhatsApp Reveals File Spoofing, URL Scheme Flaw
Meta-owned WhatsApp has released two new security warnings about flaws fixed earlier this year in the well-known messaging app. One issue is CVE-2026-23863, a medium-risk attachment spoofing problem that affects WhatsApp for Windows before version 2.3000.1032164386.258709. An attacker could use the flaw to make a harmful document with NUL bytes …
Read More »
CVE-2026-0073
Google Confirms Critical Android 0-Click Flaw
Google has released the May 2026 Android Security Bulletin, warning everyone about a critical remote code execution (RCE) flaw. Tracked as CVE-2026-0073, this serious flaw is found in the core part of the Android System. It lets a bad actor to get remote shell access without needing the device owner …
Read More »Apache Server Exposes Millions of Servers to Remote Code Execution Attacks
The Apache Software Foundation launched an important security update for Apache HTTP Server. This update fixes five security issues, including a serious double-free problem that could allow Remote Code Execution (RCE) in version 2.4.67, which came out on May 4, 2026. All users with version 2.4.66 or older should upgrade …
Read More »
CVE-2026-31431
CISA Adds Actively Exploited Linux “Copy Fail” 0-Day Vuln Exploited to Root Systems
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a new security flaw affecting different Linux versions to its list of Known Exploited Vulnerabilities (KEV). They mentioned that there is proof of this flaw being used in real attacks. The flaw, known as CVE-2026-31431 (CVSS score: 7.8), is a type …
Read More »Microsoft Defender wrongly Flags DigiCert as Trojan:Win32/Cerdigent.A!dha
Microsoft Defender sent out many false alerts after a wrong security update made it mark two real DigiCert root certificates as malicious. This could have stopped SSL/TLS checks and code-signing work in businesses everywhere. A Defender antimalware signature update released around April 30, 2026, introduced a detection labeled Trojan:Win32/Cerdigent.A!dha, which …
Read More »
InfoSecBulletin Cybersecurity for mankind