Friday , August 28 2026
cPanel

ALERT
Patch Now! Critical Exchange Server, cPanel, and Kubernetes Flaws Exploited

cPanel & WHM and WP Squared have recently provided fixes for five critical flaws. These issues include the ability to read any file and SQL injection, which threaten server safety and data privacy.

The biggest flaw found this time let anyone get into sensitive system resources without permission.

Crack 85 Accounts and Steal 2,500+ Records
8-Agent AI Framework Used to Compromise Gov’t Entities in Asia

A cyberattack using open-source AI tools almost ran on its own. It affected government systems in Asia, compromised into 85...
Read More
Crack 85 Accounts and Steal 2,500+ Records  8-Agent AI Framework Used to Compromise Gov’t Entities in Asia

270+ Zimbra servers compromised in continuous attacks

Threat actors have already compromised more than 270 Zimbra instances in attacks that let them run code remotely. These attacks...
Read More
270+ Zimbra servers compromised in continuous attacks

Singapore Approves 200MW Data-Centre Expansion Under Second Call

Singapore has picked four data-centre plans for a total of 200MW of power in its second Data Centre Call for...
Read More
Singapore Approves 200MW Data-Centre Expansion Under Second Call

Chameleon SEO Poisoning
Hackers poison Bing and Google search results to deliver phishing banking pages

Bank customers looking for a login page can now fall into a trap before getting a strange email or text....
Read More
Chameleon SEO Poisoning  Hackers poison Bing and Google search results to deliver phishing banking pages

Mysterious AI model “Ox Alpha” with free 100 trillion tokens a day for coders

A mysterious AI model dubbed "Ox Alpha" has surfaced online and created noise within the developer community after releasing on...
Read More
Mysterious AI model “Ox Alpha” with free 100 trillion tokens a day for coders

After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

A group of hackers named “Madarax” claims they have stolen and are offering to sell the personal information of about...
Read More
After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

A new hacking technique has been demonstrated to steal data from Elon Musk's Grok AI. It uses a simple trick...
Read More
Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

About thousands of leaked AWS keys Held Full Admin Rights

More than 9,300 AWS access keys that were made public from August 2022 to August 2026 are still active, says...
Read More
About thousands of leaked AWS keys Held Full Admin Rights

US Bank investigates LockBit’s Data Breach Claims

US Bank is looking into LockBit's claims about a breach and stolen data. The ransomware group says they will share...
Read More
US Bank investigates LockBit’s Data Breach Claims

Five new malware families actively targeting Asian Gov.t infra

Central Asian government agencies have been attacked in a cyber spy operation that used a small but different range of...
Read More
Five new malware families actively targeting Asian Gov.t infra

CVE-2026-29205 (CVSS 8.6) – Arbitrary File Read: A mix of wrong privilege dropping and not enough path filtering lets attackers read random files through some cpdavd endpoints. This impacts versions 120 and above.

CVE-2026-32993 (CVSS 8.3) – HTTP Header Injection: An insecure endpoint in cpsrvd was found to let users add any HTTP headers. This affects versions 132 and up.

CVE-2026-32992 (CVSS 8.2) – Credential Theft via DNS Cluster: SSL checks were not completely applied in the DNS Cluster system. A bad server could do a man-in-the-middle attack to steal credentials. This impacts versions 126 and above.

CVE-2026-29206 (CVSS 8.1) – SQL Injection: The sqloptimizer script has a flaw that lets anyone run any SQL query they want. This is important because it affects all versions of cPanel and WHM.

CVE-2026-32991 (CVSS 7.1)  Team Member Privilege Escalation: Low-privilege team users (role=default) can gain full owner rights using certain UAPI modules. This applies to versions 110 and above.

Patches have been sent out to different release levels so all active users can protect their environments.

Exchange Server

Microsoft has sent out an urgent alert for groups using on-site email systems. A new security flaw in Outlook Web Access (OWA) is now being targeted by attackers, who can run harmful code just by sending a specially made email.
The flaw, known as CVE-2026-42897 (CVSS 8.1), is a big risk for company security because it affects the user’s browser.
According to the Exchange Team, this is a Microsoft Exchange Server Spoofing Vulnerability that hinges on user interaction within a web browser. The mechanism of the attack is deceptively simple: “An attacker could exploit this issue by sending a specially crafted email to a user. If the user opens the email in Outlook Web Access and certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context”.

Microsoft has confirmed that this flaw has been used in real situations, which means criminals are already using it to get around security measures.

The vulnerability impacts several generations of on-premises servers:

Exchange Server 2016 (Any update level)
Exchange Server 2019 (Any update level)
Exchange Server Subscription Edition (SE) (Any update level)

Kubernetes 

Researchers have found security flaw in Kubernetes-based database systems. This issue is in CloudNativePG (CNPG) and is called CVE-2026-44477 with a high CVSS score of 9.4. It lets users with low privileges gain full PostgreSQL superuser access and run any commands on the operating system.

The flaw is with how this exporter connects. It first connects as the postgres superuser through a local Unix socket. Then, it tries to lower its access with the SET ROLE pg_monitor command. But this lowering is not real.

Researchers identified two distinct ways this flaw can be weaponized in the wild:

Path 1: Custom Metric Sabotage: Any database user who owns a schema on the search_path of a scraped database can “shadow” a common function used in a custom metric query. Within one scrape interval (typically 30 seconds), their malicious shadow expression executes with superuser rights.

Path 2: The “Stock” Vulnerability: Even deployments using only default configurations are at risk. A specific metric, pg_extensions, used an unqualified call that could be shadowed by any non-superuser who owns a user database.
This vulnerability affects all deployments on any supported release with default monitoring enabled.

Affected Versions: All versions prior to 1.28.3 and version 1.29.0. The CloudNativePG team has put out three fixes for the problem, now available in Patched Versions 1.28.3 and 1.29.1.

Microsoft’s MDASH VS Anthropic’s Mythos VS OpenAI’s Daybreak

Check Also

Splunk

Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

Splunk has issued security fixes for 17 weaknesses in different apps and add-ons, such as …