Exploits

WhatsApp lock screen bypass

WhatsApp Lock Screen Bypass on Android: How an Incoming Video Call Exposes Your Full Photo Gallery and How to Block It

The CyberSec Guru

A WhatsApp video call can expose private photos on some locked Android phones. See affected devices, how the bypass works, and how to block it

X Users Hit by Unsolicited Password Reset Emails

X Users Are Getting Hit With Unsolicited Password Reset Requests – Here’s How to Protect Your Account

The CyberSec Guru

Thousands of X users are receiving unsolicited password reset emails. Here's what it means, whether your account is hacked, and how to enable Password Reset Protect

PaperCut zero-day

PaperCut Under Active Attack: Full Technical Analysis of the Pre-Auth RCE Chain (CVE-2026-81578 + CVE-2026-82078)

The CyberSec Guru

Active exploitation of PaperCut NG/MF pre-auth RCE (CVE-2026-81578, CVE-2026-82078). Full chain analysis, IOCs, detection & emergency patch guidance

New X Account Takeover Vulnerability

Breaking: New X Account Takeover Exploit Reportedly Being Used by Threat Actors, Live Footage Surfaces

The CyberSec Guru

A potentially new X account takeover exploit is reportedly being used by threat actors. Live footage has surfaced, but the attack method remains unconfirmed

ServiceNow CVE-2026-18885, CVE-2026-18886 & CVE-2026-74820 Critical CVSS 10.0 Flaws

ServiceNow Patches Three CVSS 10.0 Vulnerabilities Allowing Unauthenticated Code Execution and SQL Injection

The CyberSec Guru

ServiceNow patched three CVSS 10.0 vulnerabilities allowing unauthenticated code execution, privilege escalation and SQL injection

Next.js RCE vulnerability

Critical Next.js & libheif RCE Vulnerabilities: Inside the August 2026 AVIF Zero-Day Exploit Chain

The CyberSec Guru

Critical Next.js RCE vulnerabilities affect AVIF image optimization and Windows servers. Learn about libheif, GHSA-2xp9-vwfh-vxw4, CVE-2026-75604

Log4j2 deserialization vulnerability

New Log4j2 Flaw Could Enable Remote Code Execution Through Java Deserialization

The CyberSec Guru

A newly reported Log4j2 flaw can bypass deserialization protections through Java MarshalledObject, potentially enabling RCE, DoS and malicious log injection

CVE-2026-15748

Critical WordPress Alert: Dissecting CVE-2026-15748 (Forminator RCE) & CVE-2026-15826 (UPB Auth Bypass)

The CyberSec Guru

CVE-2026-15748 enables critical Forminator RCE, while CVE-2026-15826 allows User Profile Builder authentication bypass. Learn how to detect and patch both

CVE-2026-19478

Critical GitLab GraphQL Vulnerability CVE-2026-19478: Patch Now to Prevent Unauthenticated Project Modification

The CyberSec Guru

GitLab patched critical CVE-2026-19478, a CVSS 9.4 GraphQL flaw allowing unauthenticated attackers to modify or delete public projects

CVE-2026-8452

CVE-2026-8452: Technical Analysis of the Citrix NetScaler Memory Overflow Vulnerability

The CyberSec Guru

CVE-2026-8452 is a high-severity NetScaler vulnerability affecting ADC and Gateway. See affected builds, technical details, impact and patch guidance