The CyberSec Guru

OpenAI’s AI agents went rogue on US government sites — here’s what actually happened
OpenAI AI agents probed US government websites, used publicly leaked credentials, and bypassed restrictions, raising major AI security concerns

Citrix NetScaler Zero-Days Force Emergency Shutdowns Ahead of Next Week’s Patch
Citrix NetScaler zero-day reports are triggering emergency shutdowns. Here's what is known, what remains unconfirmed, and how defenders can reduce risk

Critical Elementor CSRF Flaw Exposes 2 Million WordPress Sites to Full Takeover
Elementor CVE-2026-62062 is a CVSS 8.8 CSRF flaw affecting versions 4.3.0 and 4.3.1. Update to 4.3.2 to block the attack

OnePlus 15 zero-permission root exploit: critical OxygenOS flaws expose privileged services to any installed app
Two critical OnePlus 15 OxygenOS flaws let zero-permission apps gain root access. Learn how the exploit works, affected devices, risks, and fixes

Understanding the Different Types of Prompt Injection Attacks
Learn what prompt injection attacks are, how direct, indirect and multimodal attacks work, real-world examples, and how to protect LLM and AI systems

Beginner’s Guide to Conquering Layover on Hack the Box
Conquer Layover on Hack The Box like a pro with the beginner's HTB writeup. Dominate this challenge and level up your cybersecurity skills

Apple Is Down: iMessage, iCloud, App Store, Apple Music, Maps and More Hit by Major Outage
Apple is experiencing a major service disruption affecting iMessage, iCloud, App Store, Apple Music, Maps and more. Here's what we know about the outage

Exploit released for unpatched Ubuntu kernel flaw that lets containers root the host (CVE-2026-80521)
CVE-2026-80521 is a Linux kernel AF_UNIX use-after-free that enables container escape to host root. Ubuntu 22.04, 24.04 and 26.04 remain vulnerable

ShinyHunters Claims Unprecedented FBI Breach: Inside the Oracle PeopleSoft Zero-Day Attack and Dark Web Turf Wars
ShinyHunters claims it breached FBI systems using a previously unknown Oracle PeopleSoft zero-day, targeting FBIjobs.gov and sensitive applicant and employee data

Microsoft Called CVE-2026-65660 a Spoofing Bug. It’s an Authenticated SharePoint RCE
CVE-2026-65660 is an authenticated SharePoint RCE, not just spoofing. Learn about the ToolPane flaw, XAML exploit chain, affected versions, and fixes





