#public


Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

Jul 21, 2026 // 18:00

A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. […]

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

Jul 21, 2026 // 12:29

Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable […]

WordPress Core “wp2shell” RCE flaws get public exploits, patch now

Jul 19, 2026 // 00:58

Public exploits have been released for the critical “wp2shell” remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately. […]

Meta’s New AI Image Tool Lets Others Use Your Public Instagram Photos in AI Images

Jul 9, 2026 // 14:32

Meta has announced that its new artificial intelligence (AI) model Muse Image lets people use public Instagram posts and reels to generate AI content, and […]

Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data

Jul 7, 2026 // 18:21

A public issue can trick GitHub Agentic Workflows into leaking the contents of an organization’s private repositories, researchers at Noma Security have shown. The attacker […]

NAIC says public data stolen in ShinyHunters’ PeopleSoft breach

Jun 29, 2026 // 23:57

The National Association of Insurance Commissioners (NAIC) says the ShinyHunters extortion group stole only publicly available data, outdated logs, and configuration files after breaching its […]

Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw

Jun 29, 2026 // 13:25

A public proof-of-concept is now out for CVE-2026-55200, a critical flaw in libssh2 that lets a malicious or compromised SSH server trigger memory corruption on […]

One-Character Linux Kernel Flaw Enables Local Root Access, Exploits Now Public

Jun 9, 2026 // 00:51

Security researchers have published a detailed, working exploit for a Linux kernel use-after-free that lets an unprivileged local user escalate to root and break out […]

Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public

Jun 4, 2026 // 20:05

Cisco has patched a bug in Unified Communications Manager that lets an unauthenticated attacker on the network write files to the box and, from there, […]

Android Apps Get Public Verification System to Stop Supply Chain Attacks

May 6, 2026 // 12:14

Google has announced expanded Binary Transparency for Android as a way to safeguard the ecosystem from supply chain attacks. “This new public ledger ensures the […]