#servers


GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

Oct 2, 2026 // 23:15

A critical flaw in GitLab’s AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, […]

Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers

Oct 1, 2026 // 20:00

Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and […]

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

Sep 29, 2026 // 13:10

A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log […]

F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

Sep 23, 2026 // 11:27

Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, […]

WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

Sep 22, 2026 // 23:58

WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from […]

Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers

Sep 15, 2026 // 14:20

Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort aimed at […]

Hackers target exposed Vite dev servers to steal AWS, Azure secrets

Sep 14, 2026 // 19:16

A mass-scanning campaign targeting internet-exposed Vite development servers is attempting to steal cloud credentials and configurations from AWS and Azure deployments. The operation leverages an […]

OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers

Sep 12, 2026 // 12:17

The “major malicious attack” that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published […]

Surfshark VPN says hackers breached internal testing, proxy servers

Sep 10, 2026 // 23:37

Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet. The VPN service provider said […]

Over 36,000 exposed Plex servers vulnerable to recent flaws

Sep 9, 2026 // 15:36

Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks. Plex urged users a week ago to […]

1 2 3 … 10 Next