The flaw leads to denial-of-service on default configurations and to remote code execution if ASLR is disabled.
Hi, what are you looking for?
The flaw leads to denial-of-service on default configurations and to remote code execution if ASLR is disabled.
Participants demonstrated exploits for Windows, Linux, VMware, Nvidia, and AI products.
Introduced in 2008, the critical-severity security defect was patched this week in NGINX Plus and NGINX open source.
Other noteworthy stories that might have slipped under the radar: Nvidia cloud gaming data breach, Android 17 security upgrades, FBI warning after ShinyHunters hacks Canvas.
Microsoft has shared mitigations for CVE-2026-42897 until a permanent patch can be released for affected Exchange Server versions.
The non-bank lender discovered a ransomware attack nearly one year ago, but only recently completed its investigation.
Two employee devices were compromised in the attack, and credential material was stolen from OpenAI code repositories.
The hacking group is encouraging miscreants to use the code in supply chain attacks, promising monetary rewards.
The refresh resolves critical-severity use-after-free and other types of bugs in various browser components.
The zero-day, tracked as CVE-2026-20182, has been exploited in targeted attacks by a sophisticated threat actor identified as UAT-8616.
For AI data centers, where the stakes are the highest and performance constraints are the tightest, security and performance are no longer a zero-sum game.
The vulnerability, tracked as CVE-2026-46300, is similar to the recently disclosed exploits named Dirty Frag and Copy Fail.
Independent benchmarking finds Mythos highly effective for source code audits, reverse engineering, and native-code analysis, though its exploit validation and reasoning capabilities remain inconsistent.
The acquisition enables Akamai to expand its Zero Trust portfolio to add protection directly into the browser.
Salt Typhoon has hit an energy entity in Azerbaijan. Twill Typhoon has targeted Asian entities with an updated RAT.
The goal of the guidance, which outlines minimum elements, is to help organizations enhance transparency in AI systems and supply chains.