Cybersecurity
204 articles RSS
Foxconn Confirms Nitrogen Ransomware Attack on North American Factories with 8 TB Data and 11 Million Documents Stolen
World's largest electronics manufacturer acknowledges cyberattack claimed by Nitrogen ransomware group on North American factories; attackers allege 8 TB data theft including confidential schematics for Apple, Nvidia, Google and others, with production now resuming.
PostgreSQL Ships Coordinated Security Release Fixing 11 CVEs Across Five Supported Versions
PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 landed May 14, fixing 11 security flaws and over 60 bugs, with four CVEs rated 8.8.
Apple and Google Begin Rolling Out End-to-End Encrypted RCS Between iPhones and Androids as iOS 26.5 Ships With Beta Support
On May 11, 2026 Apple shipped iOS 26.5 with beta support for end-to-end encrypted RCS messaging across iPhone and Android, the first large-scale interoperable encrypted messaging deployment between competing mobile platforms.
XBOW Discloses 'Dead.Letter' Use-After-Free in Exim's BDAT Path, CVSS 9.8 Pre-Auth RCE Against GnuTLS Builds 4.97 to 4.99.2
CVE-2026-45185, found by XBOW's Federico Kirschbaum and patched in Exim 4.99.3, lets an unauthenticated SMTP client corrupt the heap via a TLS close_notify during a CHUNKING transfer.
Microsoft Unveils MDASH, a Multi-Model Agentic Security Harness That Tops the CyberGym Leaderboard and Finds 16 Windows Bugs
Microsoft's new Autonomous Code Security team disclosed MDASH alongside its May 2026 Patch Tuesday, crediting the multi-model agentic scanner with 16 Windows vulnerabilities — four of them critical RCEs — and an 88.45 percent score on CyberGym.
Vercel Ships Coordinated Next.js Security Release Patching 13 Advisories Across DoS, Middleware Bypass, SSRF and Cache Poisoning
Next.js 15.5.18 and 16.2.6 land with a 13-advisory bundle covering a React Server Components DoS (CVE-2026-23870), middleware-bypass routes, SSRF, and cache poisoning; Vercel says the WAF cannot reliably block them.
SAP Issues 15 May Security Notes With Two 9.6 CVEs: a Read-Only SQL Injection in S/4HANA Enterprise Search and an Unauthenticated Commerce Cloud Bypass
SAP's May 12 Patch Day fixes CVE-2026-34260 in S/4HANA's Enterprise Search for ABAP and CVE-2026-34263 in Commerce Cloud, plus a high-severity OS command injection in Forecasting & Replenishment.
Checkmarx Jenkins AST Plugin Backdoored for 31 Hours as TeamPCP Returns Weeks After the KICS Compromise
A malicious build of Checkmarx's Jenkins AST plugin was live on the Jenkins Marketplace from May 9 at 01:25 UTC to May 10 at 08:47 UTC, the latest TeamPCP intrusion against Checkmarx weeks after the April KICS wave.
PgBouncer 1.25.2 Patches Four CVEs Including a Pre-Auth SCRAM Crash That Hits Every Currently Shipping Debian Release
An integer overflow in PgBouncer's SCRAM packet parser lets unauthenticated attackers crash the pooler, and three more flaws ship in the same release. Debian stable, testing, and pre-release archives are all still vulnerable.
RedAccess Finds More Than 5,000 Vibe-Coded Apps on Lovable, Replit, Base44 and Netlify Running With No Authentication
Israeli security firm RedAccess says vibe-coding platforms ship apps that default to public, exposing medical, financial and corporate data to anyone who can find them.
Dirty Frag: A Second Linux Kernel Zero-Day in Five Weeks Hands Root via Chained ESP and rxrpc Page-Cache Bugs
CVE-2026-43284 and CVE-2026-43500 chain two page-cache write primitives in IPsec ESP and rxrpc to give unprivileged users root on every major Linux distribution shipped in the last nine years.
Vim Patches CVE-2026-44656, a Modeline-Triggered Shell Injection in :find Completion Affecting All Versions Up Through 9.2.0435
Vim 9.2.0435 fixes an OS command injection in :find completion where backtick-enclosed shell commands inside the path option ran during Tab completion, with a modeline-set path enabling exploitation by simply opening a malicious file.