Over 14,000 Dahua security cameras connected to the internet have been hacked in a 35-day online attack that affected devices around the world. This shows the rising danger of unsafe and unprotected surveillance systems. Researchers at Hunt.io found the operation by looking into a public directory with 2,616 files related …
Read More »Google issues warning of new Chrome zero-day flaw exploited
Google has updated the Chrome browser to fix a serious security issue in the V8 engine and 11 other flaws. The security flaw, called CVE-2026-85046, is a type confusion. Researcher Salvatore Gulizia, known as “Serotav,” told Google about it. The update makes Chrome version 152.0.7977.82/.83 for Windows and macOS, and …
Read More »Critical Zimbra RCE Flaw Actively Exploited in the Wild
CERT Polska has alerted that bad actors are actively exploiting a security flaw in Zimbra Collaboration Suite to execute code remotely. The bug known as CVE-2026-73570 lets attackers who are not logged in run any commands on affected servers as the zimbra user. There is a flaw with Zimbra’s SNMP …
Read More »Critical WordPress Plugin Flaw Exposes 600,000 Sites to Attacks
A big security flaw in the Forminator Forms WordPress plugin might let unapproved users upload harmful PHP files. This could give them full control over weak websites. The flaw, known as CVE-2026-15748, impacts Forminator Forms versions 1.56.1 and older and has a CVSS score of 9.8. Forminator Forms is a popular …
Read More »Apple Patches 28 Security Flaws in macOS, iOS, and iPadOS
Apple has put out security updates for macOS, iOS, and iPadOS. These updates fix 28 problems that could let users lose data, crash apps, access kernel memory, and run unwanted code. The updates came out on August 17, 2026. They have macOS Tahoe 26.6.2, iOS 26.6.1, iPadOS 26.6.1, iOS 18.7.10, and …
Read More »AI Finds Nation-State-Level Zoom Flaw in Under 24 Hours, Zero-Click Attack Exposed
A serious security flaw in Zoom might let a hacker take control of someone else’s device in a live meeting without the victim needing to click a link, download anything, or do anything else. The weakness, dubbed “Zoomsday,” was found by a cybersecurity company called A Security using open AI …
Read More »SolarWinds Patches 15 Critical Serv-U Flaws
SolarWinds has shared important security updates for its Serv-U file transfer software. These updates fix 15 problems that could let attackers get higher access and, in some cases, run code with root user rights. These fixes came in Serv-U version 2026.3, released on July 21, 2026, as part of the …
Read More »Oracle fixes 1,400+ vulnerabilities; critical flaws threaten enterprise servers
Oracle has fixed over 1,400 security holes in its July 2026 Critical Patch Update (CPU). Most of these flaws were probably found by artificial intelligence. According to Oracle, the latest quarterly CPU includes 1,449 security patches, addressing 1,434 unique CVEs across 334 products. Vulnerabilities have been fixed in products like Database …
Read More »Windows LegacyHive 0, AWS, Fortinet, TP-LINK multiple flaws got hackers attention
A Windows security flaw called LegacyHive (MSNightmare) misuses the User Profile Service. This allows local users to gain higher privileges, change admin accounts, and run code with admin rights. The public proof‑of‑concept (PoC) from the MSNightmare GitHub account describes the bug as a “Windows user profile service arbitrary hive load …
Read More »Cursor, SonicWall, SharePoint 0-day exploited to the wild
A serious security flaw in Cursor, a popular AI code editor used by more than 7 million developers, lets attackers run any code on Windows systems. Just opening a harmful repository can start this process. It doesn’t need any clicks, confirmations, or approvals from the user. The flaw was found by …
Read More »
InfoSecBulletin Cybersecurity for mankind