News

CVE-2026-62062

Critical Elementor CSRF Flaw Exposes 2 Million WordPress Sites to Full Takeover

The CyberSec Guru

Elementor CVE-2026-62062 is a CVSS 8.8 CSRF flaw affecting versions 4.3.0 and 4.3.1. Update to 4.3.2 to block the attack

OnePlus 15 zero-permission root exploit

OnePlus 15 zero-permission root exploit: critical OxygenOS flaws expose privileged services to any installed app

The CyberSec Guru

Two critical OnePlus 15 OxygenOS flaws let zero-permission apps gain root access. Learn how the exploit works, affected devices, risks, and fixes

Apple Is Down: iMessage, iCloud, App Store, Apple Music, Maps and More Hit by Major Outage

The CyberSec Guru

Apple is experiencing a major service disruption affecting iMessage, iCloud, App Store, Apple Music, Maps and more. Here's what we know about the outage

CVE-2026-80521 Ubuntu Kernel Flaw Lets Containers Escape to Host Root

Exploit released for unpatched Ubuntu kernel flaw that lets containers root the host (CVE-2026-80521)

The CyberSec Guru

CVE-2026-80521 is a Linux kernel AF_UNIX use-after-free that enables container escape to host root. Ubuntu 22.04, 24.04 and 26.04 remain vulnerable

ShinyHunters Claims FBI Breach

ShinyHunters Claims Unprecedented FBI Breach: Inside the Oracle PeopleSoft Zero-Day Attack and Dark Web Turf Wars

The CyberSec Guru

ShinyHunters claims it breached FBI systems using a previously unknown Oracle PeopleSoft zero-day, targeting FBIjobs.gov and sensitive applicant and employee data

CVE-2026-65660 Microsoft SharePoint RCE Exploit Explained

Microsoft Called CVE-2026-65660 a Spoofing Bug. It’s an Authenticated SharePoint RCE

The CyberSec Guru

CVE-2026-65660 is an authenticated SharePoint RCE, not just spoofing. Learn about the ToolPane flaw, XAML exploit chain, affected versions, and fixes

Malicious indexed-btree npm Package

Malicious npm package ‘indexed-btree’ evades install-script defenses and detonates at runtime

The CyberSec Guru

The malicious indexed-btree npm package bypassed npm v12 install-script defenses using a runtime trigger, Slack and Telegram exfiltration, and Ethereum-based C2

Linux Kernel Vulnerabilities 4 Public Root Exploits and 3 CISA KEV Flaws

Public Exploits Drop for Four Linux Kernel Flaws as CISA Warns of Active Exploitation: A Complete Technical Breakdown

The CyberSec Guru

Four Linux kernel vulnerabilities now have public root exploits, while CISA warns of three actively exploited kernel flaws. CVEs, affected versions, fixes and mitigations

TikTok Hacked by AI

How an open-weight AI model hacked TikTok: the DepthFirst Labs camera and microphone exploit

The CyberSec Guru

Researchers at DepthFirst Labs used an AI agent to exploit TikTok code, demonstrating a zero-click RCE chain that could access a phone’s camera, microphone and photos

Chat Control 2.0

Chat Control 2.0: The September 29 Trilogue and the Future of Digital Privacy in Europe

The CyberSec Guru

Chat Control 2.0 explained: what the September 29 EU trilogue means for encryption, private messages, detection orders, age verification and Chat Control 1.0

123…32 Next