Security

RSS

Breaches, vulnerabilities, privacy and staying safe online.

Security

Burger King Russia breach: 3.2 million customer records added to Have I Been Pwned

No passwords, no card details – but names, birthdates and phone numbers for millions of customers have surfaced two years after the fact, with no word from the company itself.

NerdBite ·

Security

WSO2 flaw added to US 'actively exploited' list — but nobody's saying what it actually does

CVE-2026-5430 has landed on America's most-watched vulnerability list with a tight patch deadline, yet the public record is oddly silent on the technical details.

NerdBite ·

Security

CVSS 10 'critical' bug hits a door intercom you've probably never heard of

A maximum-severity flaw has been slapped on a Gigatech video door station - but before you panic, check whether you actually own one.

NerdBite ·

Security

F5 BIG-IP APM flaw added to US 'actively exploited' list — here's what's actually known

CISA says CVE-2026-94127 is being used in the wild against F5's BIG-IP Access Policy Manager, but the public record is short on the how and who.

NerdBite ·

Security

A maximum-severity router bug has a CVSS 10 score - but check who actually owns one

CVE-2026-94003 hits Comfast's CF-N1-S router with the highest possible severity rating, yet key questions about patching and real-world risk are still unanswered.

NerdBite ·

Security

US cyber agency confirms active attacks on Arista VeloCloud Orchestrator flaw

CVE-2026-93952 has made CISA's exploited-vulnerabilities list with a three-day patch deadline for US agencies — but the public record says almost nothing about how it's being abused.

NerdBite ·

Security

UK and Cambodia sign scam-centre pact - but no networks have actually been taken down yet

A Home Office minister's trip to Phnom Penh has been framed as a crackdown on scam gangs - the paperwork says otherwise.

NerdBite ·

Security

Router flaw rated a 'perfect 10' — but only if you own this one obscure TOTOLINK model

CVE-2026-93741 sounds terrifying on paper, but the fine print says it's a single ageing router model with no confirmed fix and no evidence anyone's actually exploiting it.

NerdBite ·

Security

Zyxel GS1900 switches hit by 'actively exploited' flaw — but the details are thin

CISA says CVE-2026-7273 is being used in the wild against Zyxel's GS1900 switches, yet the public record so far tells us almost nothing about how.

NerdBite ·

Security

vm2 sandbox had a hole big enough to drive a shell through - CVE-2026-93605 explained

A maximum-severity flaw in the vm2 NodeVM sandbox let attackers skip straight to running commands on the host - but only if you were using vm2 in the first place.

NerdBite ·

Security

Linux kernel flaw CVE-2026-53266 confirmed under active attack - but nobody's saying how

CISA has slapped a three-day patch deadline on a Linux kernel bug it says is being exploited right now, yet the public paperwork is oddly light on detail.

NerdBite ·

Security

Government unveils misogyny taskforce - but what will it actually do?

A new group will 'discuss' online abuse, workplaces and communities - just don't expect new laws, funding or deadlines just yet.

NerdBite ·

Security

Critical flaw lets sandboxed code break out of vm2 and run commands on the host

A maximum-severity bug in the vm2 sandboxing library sounds terrifying — but only a specific slice of Node.js apps actually leave the door open.

NerdBite ·

Security

Linux kernel bug CVE-2025-39964 is being actively exploited — but details are thin on the ground

CISA says the flaw is confirmed as exploited in the wild and has given US federal agencies days to patch, yet the public record says almost nothing about what the bug does or who it hits.

NerdBite ·

Security

GrapheneOS claims Android 17 breaks a 10-year AOSP habit - here's what's actually confirmed

The privacy-focused Android fork says Google shipped new APIs without open-sourcing them first, but the evidence so far is one project's word against Google's silence.

NerdBite ·

Security

The red team's own toolkit has a hole in it: critical bug found in Covenant C2 framework

A missing login check in the open-source Covenant framework lets anyone on the network mint themselves a valid access token - but only a narrow slice of users, mostly penetration testers, actually run the thing.

NerdBite ·

Security

Researchers chained a forum bug into OpenAI account takeover - and it's already fixed

Security firm Hacktron says it hijacked ChatGPT and Codex accounts via OpenAI's own help forum, but the hole was patched months ago and OpenAI paid up for the tip-off.

NerdBite ·

Security

Ghostscript's JPEG 2000 code gets a 9.8-rated fix - but check before you panic

A newly published flaw in the venerable PDF/PostScript engine sounds terrifying on paper, so here's what's actually confirmed versus what's just a number.

NerdBite ·

Security

MikroTik RouterOS flaw added to US 'actively exploited' list — but details are thin

CISA says CVE-2026-67277 is being exploited right now, yet the public record so far tells you almost nothing about how it works or who's actually being hit.

NerdBite ·

Security

Apple patches a 9.1-rated Mac flaw that could crash your machine remotely

A newly listed 'critical' bug sounds terrifying until you notice Apple fixed it the same day it appeared - and there's no sign anyone's actually used it.

NerdBite ·

Security

Google Pixel bug flagged as 'actively exploited' by US cyber agency — but nobody's saying how

CISA says a Pixel vulnerability is being exploited right now and has given US agencies days to patch it, yet the public record is almost entirely blank on what the flaw actually does.

NerdBite ·

Security

A critical 9.9-rated bug just landed in a Totolink router - here's who should actually care

A newly published flaw in a budget router's web interface scores near the top of the CVSS scale, but the scary number hides a much narrower story.

NerdBite ·

Security

GitLab flaw added to US 'actively exploited' list — but nobody's saying what it actually does

CVE-2026-85706 has landed on America's must-patch list with a tight deadline, yet the public record is oddly quiet on the details.

NerdBite ·

Security

Critical 9.9-rated bug found in Totolink router firmware - but check if it even affects you first

A newly listed flaw in a niche router's web interface scores near the top of the severity scale, though the real-world exposure looks a lot smaller than the number suggests.

NerdBite ·

Security

Cisco Secure Email Gateway flaw added to US 'actively exploited' list — but the how stays murky

CISA says CVE-2026-76461 is being used in real attacks and wants federal agencies patched within three days — here's what's actually confirmed and what isn't.

NerdBite ·

Security

Passwords are dying on GOV.UK - but only if you opt in to passkeys

The government says millions can now ditch passwords for GOV.UK One Login, but it's a choice, not a mandate, and the security upside depends on your device already having biometrics set up.

NerdBite ·

Security

WAVLINK mesh routers can be hijacked with zero login needed - here's what's actually confirmed

A critical flaw lets anyone on the network overwrite files and potentially seize root on two WAVLINK router models - but only if you're running old firmware with mesh mode switched on.

NerdBite ·

Security

CISA confirms active exploitation of JFrog Artifactory flaw, but details stay vague

A newly catalogued bug in the popular software repository tool is being exploited right now, according to US cyber officials — though exactly how it's being abused isn't spelled out.

NerdBite ·

Security

Critical SQL injection flaw hits niche lab management software - but who's actually running it?

A 9.8-rated vulnerability sounds terrifying until you ask how many machines are actually exposed.

NerdBite ·

Security

JFrog Artifactory flaw is being actively exploited, CISA confirms — here's what's actually known

A vulnerability in the software repository tool used by countless dev teams has made America's most-watched exploited-bugs list, but the technical detail on how it's being abused is still thin on the ground.

NerdBite ·

Security

Dell patches Secure Connect Gateway flaws - but is CVE-2026-79941 really 'critical'?

A newly listed Dell bug is tagged critical severity despite carrying a CVSS score that normally means 'medium' - here's what's actually confirmed.

NerdBite ·

Security

ConnectWise ScreenConnect flaw is being actively exploited, says CISA — but details are thin

A newly catalogued bug in the popular remote-access tool has US federal agencies scrambling to patch by Monday, though who's behind the attacks and how remains unclear.

NerdBite ·

Security

Netis router bug hands out the admin password to anyone who asks

A newly disclosed flaw in the Netis NX10 lets unauthenticated attackers read the admin password straight off the web interface - but the headline 9.8 score doesn't match what the researcher's own advisory says.

NerdBite ·

Security

MikroTik RouterOS flaw added to US 'actively exploited' list — but details are thin on the ground

CISA says CVE-2026-86060 is being used in real attacks against MikroTik routers, yet neither the agency nor NVD has published what the bug actually does.

NerdBite ·

Security

Critical bug in Linksys RE7000 Wi-Fi extender lets attackers hijack the ping test tool

A newly catalogued flaw scores a near-maximum 9.9 for severity, but the fine print matters more than the number.

NerdBite ·

Security

Citrix NetScaler flaw now on CISA's exploited list — but the details are strangely thin

A new NetScaler bug has made the US government's most urgent watchlist, yet nobody outside CISA seems to know exactly how it's being abused.

NerdBite ·

Security

Charity Commission clears four charities of theft - but not of reckless chequebook habits

No money went missing at these four charities, the regulator says, but blank cheques and weak oversight were enough to earn a formal finding of mismanagement - and the bigger 105-charity inquiry grinds on.

NerdBite ·

Security

Critical flaw in Advantech industrial gateways lets attackers become root over the network

A near-maximum severity score sounds terrifying, but the catch is who actually owns one of these boxes - and whether Advantech has fixed it yet.

NerdBite ·

Security

CISA confirms active attacks on Adobe Commerce and Magento flaw — but details are scarce

A newly catalogued Adobe Commerce and Magento bug is already being exploited, says CISA, though it's telling us very little about how.

NerdBite ·

Security

Researcher cracks a 1999 CA's 512-bit keys - but the only victim is his own VM

A hobby project spent 61 hours of desktop compute breaking encryption that Netscape itself gave up on in 2002 - here's why nobody today should lose sleep over it.

NerdBite ·

Security

Critical flaw in open-source 'Cua' AI agent server lets anyone skip the login screen

A missing environment variable is all it takes to bypass authentication entirely — but only if you've actually installed the thing.

NerdBite ·

Security

JFrog Artifactory flaw added to US 'actively exploited' list — here's what we actually know

CISA says attackers are already using CVE-2026-82329 in the wild, but the public record is short on detail about how it works and who exactly is exposed.

NerdBite ·

Security

Critical flaw in a popular Excel AI tool could let attackers read and write any file

A newly disclosed bug in excel-mcp-server scores a maximum-alarm 9.8 out of 10 - but the danger depends entirely on a setting most people won't have touched.

NerdBite ·

Security

Kestra OSS flaw added to US 'actively exploited' list — but the details are thin

CVE-2026-49869 has landed on America's known-exploited-vulnerabilities list with a three-day patch deadline for federal agencies, yet neither CISA nor NVD have published what the bug actually does.

NerdBite ·

Security

Critical flaw in Taipy's web server config lets any website hijack your session, CVE says

A newly disclosed bug in the Python framework Taipy scores a near-maximum severity rating - but whether it's actually being exploited, or even patched, is still an open question.

NerdBite ·

Security

US cyber agency confirms Starlette bug is being exploited, but won't say how

A vulnerability in a widely used Python web framework has made America's most-watched vulnerability list, yet the public record is oddly thin on what the bug actually does.

NerdBite ·

Security

Chromium's newest RCE is already being used against people, and Google paid £790 for it

A sandbox-escaping bug in every version of Chromium is under active attack, but the size of the bounty is raising more eyebrows than the bug itself.

NerdBite ·

Security

Critical flaw found in obscure TOTOLINK router model, but check before you panic

A newly logged bug scores a maximum-alarm 9.9 out of 10, but the fine print matters more than the number.

NerdBite ·

Security

Chromium's V8 engine has a bug under active attack, but the details are suspiciously thin

CISA says CVE-2026-85046 is being exploited right now, yet the public record barely tells us what the bug does or which Chrome version fixes it.

NerdBite ·

Security

A 'critical' Firefox Focus bug just got a CVSS 9.8 - but the details are oddly thin

A newly listed flaw in Firefox Focus for Android carries a maximum-alarm score, yet Mozilla's own paperwork barely says what it actually does.

NerdBite ·

Security

US cyber agency confirms active exploitation of bug in AI proxy tool LiteLLM

CISA says the flaw is being exploited right now, but its own listing is oddly light on what the bug actually does or who's behind the attacks.

NerdBite ·

Security

Critical bug in obscure npm tool could let wildcard logins sneak past AWS security checks

A flaw in a niche policy-checking package let attackers hide dangerous wildcard rules from GitHub's cloud login guardrails, but only a small slice of DevOps setups will ever encounter it.

NerdBite ·

Security

PaperCut NG/MF flaw added to US exploited-bugs list - but the details are thin

CISA says CVE-2026-81578 is being actively exploited in the wild, yet the public record offers almost nothing on how the attack actually works.

NerdBite ·

Security

Critical flaw in Argo CD's AI helper let anyone with network access hijack deployments

A maximum-severity bug in the argocd-mcp server skipped login checks entirely - but only if you'd switched it on and pointed it at the open network in the first place.

NerdBite ·

Security

PaperCut NG/MF flaw added to US 'actively exploited' list, but details are thin

CISA says CVE-2026-82078 is being exploited right now, yet the public record says almost nothing about how, by whom, or whether a fix even exists.

NerdBite ·

Security

Redpanda's Admin API defaults to 'trust everyone' - here's what that actually means

A critical-rated flaw in the Kafka-alternative streaming platform boils down to an insecure default, not some exotic exploit - but that doesn't make it harmless.

NerdBite ·

Security

That 'critical' OpenSSL CVE isn't OpenSSL - it's a two-star Python package

A 9.8-rated bug can forge fingerprint checks in a niche identity tool called openssl_encrypt - which, despite the name, has nothing to do with the actual OpenSSL library.

NerdBite ·

Security

JFrog Artifactory bug added to US 'actively exploited' list, but details are thin

CISA says CVE-2026-66384 is being exploited in the wild right now, yet the public record barely says what it actually does.

NerdBite ·

Security

Critical-rated bug in obscure Python encryption tool lets attackers swap in their own keys

A flaw in the little-used openssl_encrypt package could let an attacker fake a trusted contact's key - but the 'critical' label needs a reality check.

NerdBite ·

Security

Linux kernel bug added to US 'actively exploited' list, but nobody's saying much else

CISA says CVE-2026-53362 is being used in real attacks right now, yet the public record is almost entirely blank on what the bug actually does.

NerdBite ·

Security

Critical flaw in obscure Turkish repository software scores 9.8 - but almost nobody outside Turkey will care

CVE-2026-16286 lets attackers upload dangerous files to TRtek's Software Repository Management tool, yet the advisory says nothing about a fix, active abuse, or how many people actually run it.

NerdBite ·

Security

US cyber agency confirms an ownCloud flaw is being actively exploited

CISA has flagged CVE-2023-49105 as under real-world attack, but the small print matters: this is a federal-agency deadline, not a nationwide emergency.

NerdBite ·

Security

US cyber agency flags old Ajax.NET Professional bug as actively exploited, but details are thin on the ground

CVE-2021-23758 has just landed on America's most-watched vulnerability list, five years after it was first catalogued, and the public record explains almost nothing about how it's being abused.

NerdBite ·

Security

That 'critical' 9.8 bug in justhtml? GitHub itself only calls it 'Moderate'

A Python HTML-sanitiser has patched several sanitisation bypasses - but the severity score depends entirely on who you ask, and mostly on how you've configured it.

NerdBite ·

Security

Gitea flaw added to US 'actively exploited' list, but the technical details are still a mystery

America's cyber-security agency says a bug in the popular self-hosted Git platform Gitea is already being used in real attacks, yet the public record barely explains what it actually does.

NerdBite ·

Security

TRENDnet router bug gets a 'perfect' CVSS 10 - but the score comes from the bug hunter, not NIST

A stack overflow in a niche WiFi access point has been rated maximum severity, though the number attached to it deserves more scrutiny than the bug itself.

NerdBite ·

Security

Oracle server bug hits maximum severity score as US cyber agency confirms active attacks

CVE-2026-21962 scores a perfect 10 out of 10 and is already being exploited in the wild - but this is squarely an enterprise problem, not one for home users.

NerdBite ·

Security

A developer used an AI coding agent to hack his own webcam, mic and desk light, here's the catch

One person's viral blog post shows how far AI-assisted reverse engineering has come, but this is a personal experiment, not a security alert for the rest of us.

NerdBite ·

Security

Critical flaw in Mailgun for WordPress plugin could let attackers hijack admin accounts

A newly published CVE rates 9.8 out of 10, but before anyone panics it's worth asking who actually runs this plugin, and whether it's even fixed yet.

NerdBite ·

Security

VMware vCenter flaw added to US 'actively exploited' list, here's what's actually confirmed

A critical bug in vCenter's Syslog server has earned a place on America's most-wanted vulnerability list, but the scarier detail, Chinese hackers, hundreds of victims, comes from a blog post, not CISA.

NerdBite ·

Security

IBM patches critical AIX and PowerVM flaw letting attackers overwrite files remotely

A 9.1-rated bug sounds terrifying, but check who's actually running this before you panic - it's not your laptop.

NerdBite ·

Security

TrueConf Server bug now on CISA's exploited-in-the-wild list, should you care?

A critical flaw in a Russian videoconferencing platform is being actively abused, but unless you're running TrueConf's server software yourself, this one passes you by.

NerdBite ·

Security

A 9.9-rated flaw in Red Hat's Kubernetes management tool isn't as apocalyptic as the score implies

CVE-2026-70496 hands a helper component cluster-admin-level powers on paper, but Red Hat's own rating and the fine print tell a calmer story.

NerdBite ·

Security

Zimbra email servers under active attack via obscure SNMP flaw

A serious, unauthenticated bug in Zimbra Collaboration Suite is already being exploited, but only a specific, non-default setup is actually exposed.

NerdBite ·

Security

SIA marks first 'National Day for Victims and Survivors of Terrorism', but don't mistake it for new law

The security regulator has issued a solidarity statement, not a policy change, here's what's actually new and what isn't.

NerdBite ·

Security

Firefox patches a critical use-after-free bug - but is it really a 9.8?

A newly disclosed WebAssembly flaw in Firefox scores near the top of the danger scale, though Mozilla's own rating and the lack of any known attacks tell a calmer story.

NerdBite ·

Security

TrueConf Server flaw let attackers break out of its sandbox, CISA says it's already being exploited

A critical bug in the self-hosted video conferencing platform is now on the US government's confirmed-exploited list, but this is an enterprise problem, not a household one.

NerdBite ·

Security

'Perfect 10' bug in an old TRENDnet Wi-Fi controller's nginx binary - but check who actually owns one

A stack overflow in a bundled nginx binary has earned the maximum CVSS score, but the affected device is a niche, ageing wireless controller rather than anything on your desk.

NerdBite ·

Security

MLflow webhook bug now under active attack, CISA confirms

A validation gap in MLflow's webhook testing feature can be abused to sneak past security checks and reach internal systems, and someone is already doing it.

NerdBite ·

Security

Critical flaw in Red Hat's cluster management tool needs a privileged account to matter

A 9.1-rated bug sounds terrifying, but check the small print: you need admin-level access to abuse it in the first place.

NerdBite ·

Security

Critical Windows networking flaw is being actively exploited, CISA confirms

A 9.8-rated bug in Microsoft's IKE service lets attackers run code with no clicks and no credentials, and it's already being used in the wild, not just theorised.

NerdBite ·

Security

Charity Commission flags rising abuse of charitable status, but the numbers need context

The regulator's own risk assessment shows a real rise in cases, but that's likely as much about better detection as it is about scarier criminals.

NerdBite ·

Security

Another Tenda router flaw scores 9.8 - but check your firmware before panicking

A critical authentication bypass has been logged against a single Tenda AC10 firmware build - here's what's actually confirmed and what's still guesswork.

NerdBite ·

Security

US cyber agency flags actively exploited flaw in Ray, the AI developer tool

A browser trick and some old-fashioned DNS trickery can apparently hijack machines running Ray in dev mode, but only if you're the kind of person running Ray in dev mode.

NerdBite ·

Security

Critical Grav CMS plugin bug let low-privilege API keys mint themselves 'super' access

A scoring of 9.8 sounds terrifying, but the flaw only bites sites running Grav's API plugin with super-user API keys already in play - here's what actually happened and who needs to patch.

NerdBite ·

Security

Progress LoadMaster flaw is being actively exploited, here's who needs to care

A critical bug lets attackers run commands on LoadMaster boxes with no login required, but this is an enterprise networking story, not one for home routers.

NerdBite ·

Security

Windows has a zero-day that hands attackers full control - and it is already being used

CVE-2026-68820, a use-after-free bug in the WinSock driver, lets someone already on your PC escalate to SYSTEM. CISA has told federal agencies to patch by 25 August. Here is who is actually at risk, and who is not.

NerdBite ·

Security

The Windows flaw added to CISA's exploited list this week is one of the few that reaches home machines

CVE-2026-68820 is a privilege escalation in a Windows networking driver. It cannot get an attacker in, which is the point: it is what they use once they are already there.

NerdBite ·

Security

Federal agencies had until today to patch a Cisco firewall flaw that is already being exploited

CVE-2026-20349 lets an unauthenticated attacker reboot a Cisco firewall from the internet. It does not steal anything, which is exactly why it is easy to underrate.

NerdBite ·

Security

CISA gives federal agencies three days to patch a Cisco firewall flaw already being exploited

Two Cisco Secure Firewall products were added to the US catalogue of actively exploited vulnerabilities on 11 August, with a deadline of 14 August. The short clock is the tell.

NerdBite ·

Security

Signicat certified under the UK digital identity framework - but the policy backdrop is not what the announcement says

The identity firm has passed a Kantara audit covering Right to Work, Right to Rent and DBS checks. Its announcement also claims the government has ended its digital ID scheme, which is not what happened.

NerdBite ·