#server


HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload

Jul 18, 2026 // 00:37

A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes. The […]

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

Jul 18, 2026 // 00:23

Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc […]

Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365

Jul 13, 2026 // 12:54

An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing switched on. The […]

Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites

Jul 10, 2026 // 16:46

A cybercrime crew left one of its own servers wide open on the internet for three weeks, and it exposed the operation’s inner workings: the […]

Microsoft extends Windows Server 2022 hotpatching until October 2027

Jun 29, 2026 // 20:17

Microsoft has extended Windows Server 2022 hotpatching until October 2027, one year after the mainstream end date of October 2026. This comes with the following caveat: […]

Microsoft fixes Windows Server 2016 security update failures

Jun 18, 2026 // 13:16

Microsoft has fixed a known issue causing the June 2026 security updates to fail on Windows Server 2016 systems that weren’t up to date. The […]

Microsoft patches Exchange Server zero-day exploited in attacks

Jun 10, 2026 // 16:56

Microsoft has patched an actively exploited Exchange Server vulnerability that allows threat actors to execute arbitrary JavaScript code in cross-site scripting (XSS) attacks targeting Outlook […]

Max-severity flaw in ChromaDB for AI apps allows server hijacking

May 20, 2026 // 01:36

A max-severity vulnerability in the latest Python FastAPI version of the ChromaDB project allows unauthenticated attackers to run arbitrary code on exposed servers. The flaw […]

On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email

May 15, 2026 // 13:15

Microsoft has disclosed a new security vulnerability impacting on-premise versions of Exchange Server that it said has come under active exploitation in the wild. The […]

On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email

May 15, 2026 // 12:21

Microsoft has disclosed a new security vulnerability impacting on-premise versions of Exchange Server that it said has come under active exploitation in the wild. The […]