News

FTC YouTube investigation

FTC Investigates YouTube Over Account Suspensions and Content Moderation Policies

The CyberSec Guru

The FTC is reportedly preparing a potential lawsuit against YouTube over account suspensions, content policies and allegations of misleading users

Valve 12TB leak

Valve 12TB Leak: Public Endpoint Exposes Portal 2 Beta and F-Stop Data

The CyberSec Guru

A reported 12TB Steam archive has surfaced with Portal 2, F-Stop and Sonic 4 Episode 2 beta builds, reportedly exposed through a public unauthenticated endpoint

GTA 6 Netflix outage

Netflix Crashes During GTA 6 Trailer Premiere: What Happened?

The CyberSec Guru

Netflix crashed for thousands of users during the GTA 6 trailer premiere. Here's what happened, what NSEZ-503 means, and what the outage reveals about streaming infrastructure

Manchester Airport cyber attack

Manchester Airports Group Cyber Attack Exposes Data of 8.7 Million Customers Across Three UK Airports

The CyberSec Guru

Manchester Airports Group confirms a cyber-attack affecting 8.7 million customers at Manchester, Stansted and East Midlands airports. Email addresses, phone numbers, vehicle registrations and postcodes were exposed

openapi-react-query-codegen npm compromise

OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack: Malicious Versions, GitHub Actions Abuse, Credential Theft and IoCs

The CyberSec Guru

@7nohe/openapi-react-query-codegen was compromised in a Mini Shai-Hulud npm supply-chain attack. See affected versions, GitHub Actions abuse, malware behavior, IoCs and remediation

PaperCut zero-day

PaperCut Under Active Attack: Full Technical Analysis of the Pre-Auth RCE Chain (CVE-2026-81578 + CVE-2026-82078)

The CyberSec Guru

Active exploitation of PaperCut NG/MF pre-auth RCE (CVE-2026-81578, CVE-2026-82078). Full chain analysis, IOCs, detection & emergency patch guidance

New X Account Takeover Vulnerability

Breaking: New X Account Takeover Exploit Reportedly Being Used by Threat Actors, Live Footage Surfaces

The CyberSec Guru

A potentially new X account takeover exploit is reportedly being used by threat actors. Live footage has surfaced, but the attack method remains unconfirmed

ServiceNow CVE-2026-18885, CVE-2026-18886 & CVE-2026-74820 Critical CVSS 10.0 Flaws

ServiceNow Patches Three CVSS 10.0 Vulnerabilities Allowing Unauthenticated Code Execution and SQL Injection

The CyberSec Guru

ServiceNow patched three CVSS 10.0 vulnerabilities allowing unauthenticated code execution, privilege escalation and SQL injection

Next.js RCE vulnerability

Critical Next.js & libheif RCE Vulnerabilities: Inside the August 2026 AVIF Zero-Day Exploit Chain

The CyberSec Guru

Critical Next.js RCE vulnerabilities affect AVIF image optimization and Windows servers. Learn about libheif, GHSA-2xp9-vwfh-vxw4, CVE-2026-75604

TeamPCP hackers

Two Alleged TeamPCP Hackers Charged in Australia After Massive Software Supply Chain Attacks

The CyberSec Guru

Two alleged TeamPCP hackers have been charged in Australia over major supply chain attacks targeting Trivy, Checkmarx KICS and LiteLLM. Here's what happened