Monday , September 28 2026

Vulnerabilities

“nginx-poolslip” NGINX 0-Day Affects Millions of NGINX Servers To RCE

nginx-poolslip

A security flaw dubbed nginx-poolslip has been revealed in NGINX version 1.31.0, the newest stable version of the most used web server software. The discovery, made by security researcher Vega of the NebSec security team, was announced via X (formerly Twitter) on May 21, 2026, sending shockwaves through the global …

Read More »

PoC released
Windows ‘MiniPlasma’ zero-day Exploit Publicly Disclosed

MiniPlasma

A cybersecurity researcher has shared a PoC for a Windows flaw called “MiniPlasma.” This lets attackers get SYSTEM privileges on fully updated Windows systems. The exploit was shared by a researcher called Chaotic Eclipse, or Nightmare Eclipse. They released the source code and a working file on GitHub after saying …

Read More »

OpenClaw Flaws Expose 245,000 Public AI Agent Servers

OpenClaw

A series of four security flaws found in OpenClaw, a rapidly growing open-source platform for self-operating AI agents, has put about 245,000 public server instances at risk of being hacked, having credentials stolen, and being installed with secret backdoors. Originally started as “Clawdbot” in late 2025, OpenClaw links big language …

Read More »

Microsoft Patch Tuesday May 2026 fixed 120 flaws, Including 29 Critical RCE

Microsoft’s May 2026 Patch Tuesday brings many updates for businesses. It fixes 120 security flaws in Windows, Office, Azure, developer tools, and Microsoft 365 apps. Among these, 29 critical flaws let attackers run code from far away. Microsoft says there are no zero-days used in attacks or announced before this …

Read More »