Exploits

CVE-2026-64531

OVSwrap (CVE-2026-64531): How a 13-Year-Old Open vSwitch Bug Became a Reliable Linux Root Exploit

The CyberSec Guru

OVSwrap (CVE-2026-64531) is a Linux kernel privilege escalation flaw affecting Open vSwitch. Explore the vulnerability, exploit chain and more

COLDCARD firmware vulnerability

Nearly $40 Million in Bitcoin Stolen After COLDCARD Seed Generation Flaw Exposes Hundreds of Wallets

The CyberSec Guru

A critical COLDCARD firmware flaw reduced seed entropy, potentially exposing Bitcoin wallets. Learn how the vulnerability works, who is affected, and how to secure your funds

Cisco Warns of Active Exploitation of Secure Firewall Management Center Flaw Caused by Hardcoded Credentials

The CyberSec Guru

Cisco confirms active exploitation of CVE-2026-20316, a hardcoded credentials flaw in Secure Firewall Management Center. Learn affected versions, impact, IoCs, and hotfixes

VMware vulnerabilities

Critical VMware Flaws Allow Authentication Bypass, Remote Code Execution, and VM Escape

The CyberSec Guru

Broadcom has patched five VMware vulnerabilities, including critical authentication bypass, remote code execution, and VM escape flaws affecting vCenter etc

Claude shared chats indexed by Google

Claude Shared Chats Indexed by Search Engines Raise Privacy Concerns

The CyberSec Guru

Public Claude shared conversations were discovered in Google and Bing search results, exposing resumes, company projects, and other sensitive information. Learn what happened, why it occurred, and how to protect your shared chats

Meta authorization vulnerability

Critical Meta Authorization Flaw Exposed Customer Support Emails, Chats, and Uploaded Files

The CyberSec Guru

A critical Meta authorization vulnerability exposed customer support emails, chats, uploaded files, and PII through broken access controls

GitLab Remote Code Execution

GitLab Vulnerabilities Allow Remote Code Execution on Default Installations Through Oj Parser Exploit Chain

The CyberSec Guru

GitLab fixed critical vulnerabilities allowing remote code execution through the Oj JSON parser. Learn affected versions, exploit chain, impact, and patches

Certighost (CVE-2026-54121)

CertiGhost Exploit Allows Low-Privileged Active Directory Users to Impersonate a Domain Controller

The CyberSec Guru

A newly disclosed AD CS vulnerability, Certighost (CVE-2026-54121), allows low-privileged domain users to impersonate a Domain Controller

CVE-2026-16232

Check Point Warns of Actively Exploited SmartConsole Authentication Bypass (CVE-2026-16232): Patch Immediately

The CyberSec Guru

Check Point warns CVE-2026-16232 is actively exploited. Learn technical details, affected versions, IoCs, CISA KEV status, mitigations and patch

Claude Cowork Sandbox Escape

Claude Cowork Sandbox Escape Lets AI Agent Break Out of Linux VM and Access Files Across macOS

The CyberSec Guru

Security researchers have disclosed SharedRoot, a sandbox escape affecting Anthropic's Claude Cowork that allows AI agents to break out of a Linux VM