Critical Nginx-ui MCP Flaw Actively Exploited in the Wild
Critical nginx-ui MCP authentication bypass CVE-2026-33032 actively exploited with CVSS 9.
20 articles
Critical nginx-ui MCP authentication bypass CVE-2026-33032 actively exploited with CVSS 9.
At VulnCon, Lindsey Cerkovnik, head of vulnerability management at CISA, said AI companies should play a bigger role in vulnerability disclosures in the future
Barracuda says 88% of brute-force attempts in Q1 were from the region
Microsoft has patched two zero-day flaws and over 160 others
A new IANS report claims just 34% of cybersecurity professionals plan to stay put in the next 12 months
Triad Nexus scales $200m scams, uses infrastructure laundering, localized fraud and US-access blocks
108 malicious Chrome extensions steal sessions, Google data, inject ads via single C2 infrastructure
The AISI has issued its judgement on Anthropic’s Mythos Preview model
Attackers are abusing Microsoft 365 mailbox rules to hide activity, exfiltrate data and retain access after account compromise, researchers warn
Security researchers warn of Mirax, an emerging Android banking trojan using MaaS, remote access and residential proxies to target European users
The W3LL phishing kit has been associated with fraud attempts totaling $20m
The UK Cyber Security Council has unveiled a new Associate Cyber Security Professional title aimed at supporting early‑career cybersecurity professionals
UK, US and Canadian authorities have identified over 20,000 victims of approval phishing scams that trick users into handing over full crypto wallet access
Qilin, Akira and Dragonforce were responsible for 40% of 672 ransomware incidents reported in March, says Check Point
Chrome’s Device Bound Session Credentials is designed to block infostealers from harvesting session cookie
STX RAT, a newly identified remote access trojan, attempted deployment in finance, showing advanced C2 and stealthy delivery methods
Bitcoin Depot has disclosed a cyber-attack that led to the theft of more than 50 Bitcoin, worth $3.
macOS 26.
A spear-phishing campaign which spread across the Middle East between 2023 and 2024 has now been linked to Bitter APT group
SANS Institute reveals that AI agents are behind a 76% surge in non-human identities