A security flaw dubbed nginx-poolslip has been revealed in NGINX version 1.31.0, the newest stable version of the most used web server software. The discovery, made by security researcher Vega of the NebSec security team, was announced via X (formerly Twitter) on May 21, 2026, sending shockwaves through the global …
Read More »Microsoft Defender 0-Days Being Actively Exploited
Two new Microsoft Defender flaws have been found, and they are being used by attackers. This allows local attackers to gain SYSTEM level access and could interrupt protection on Windows systems. The bugs are called CVE‑2026‑41091 (Elevation of Privilege) and CVE‑2026‑45498 (Denial of Service). They were shared on May 19, …
Read More »The Gentlemen Ransomware Attacks Windows, Linux, NAS, BSD, and ESXi Systems
The Gentlemen ransomware group has quickly become one of the most active and growing cybercrime threats since it was first seen in late 2025. The Gentlemen is unique because it has the capability to attack with many types of systems, such as Windows, Linux, NAS, BSD, and VMware ESXi. Attack …
Read More »
PoC released
Windows ‘MiniPlasma’ zero-day Exploit Publicly Disclosed
A cybersecurity researcher has shared a PoC for a Windows flaw called “MiniPlasma.” This lets attackers get SYSTEM privileges on fully updated Windows systems. The exploit was shared by a researcher called Chaotic Eclipse, or Nightmare Eclipse. They released the source code and a working file on GitHub after saying …
Read More »NGINX CVE-2026-42945 Exploited in the Wild
A new security flaw affecting NGINX Plus and NGINX Open is being used by hackers days after it was made public, according to VulnCheck. The flaw, known as CVE-2026-42945 (CVSS score: 9.2), is a heap buffer overflow in the ngx_http_rewrite_module that affects NGINX versions 0.6.27 to 1.30.0. An AI security …
Read More »OpenClaw Flaws Expose 245,000 Public AI Agent Servers
A series of four security flaws found in OpenClaw, a rapidly growing open-source platform for self-operating AI agents, has put about 245,000 public server instances at risk of being hacked, having credentials stolen, and being installed with secret backdoors. Originally started as “Clawdbot” in late 2025, OpenClaw links big language …
Read More »Palo Alto PAN-OS 0-Day Exploited: Patches released
A critical flaw in Palo Alto Networks PAN-OS is putting business firewalls at risk. It lets unverified attackers run any code they want with full control. Tracked as CVE-2026-0300 is a buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software which …
Read More »Ivanti Patches Multiple falws in Secure Access, Xtraction, vTM and Endpoint Manager
Ivanti has put out its May 2026 Patch Tuesday security updates. They found flaws in four products. They also said that AI tools are helping their engineers find mistakes that regular scanners miss. They warned that AI finding issues will probably lead to more flaws being reported in the future. …
Read More »Microsoft Patch Tuesday May 2026 fixed 120 flaws, Including 29 Critical RCE
Microsoft’s May 2026 Patch Tuesday brings many updates for businesses. It fixes 120 security flaws in Windows, Office, Azure, developer tools, and Microsoft 365 apps. Among these, 29 critical flaws let attackers run code from far away. Microsoft says there are no zero-days used in attacks or announced before this …
Read More »Zoom Rooms and Workplace vulns Expose Users to Elevated Access Attacks
A new set of flaws in Zoom’s software can let hackers take control of systems. Zoom has launched security updates to fix three different flaws in its Windows and iOS apps. The most serious of these flaws lets authorized attackers gain higher system powers, changing a regular user account into …
Read More »
InfoSecBulletin Cybersecurity for mankind