Skip to content
category — security

ls ./category/security --page 3

Security

Breaches, vulnerabilities, malware and the patches that matter.

page 3 of 7147 articles

8,393 Gitea servers are exposed, and the flaw needs an account anyone can make

2026-08-31

CVE-2026-60004 lets a user with ordinary write access to a repository run shell commands as the Gitea system user. That reads as an authenticated flaw until you notice that Gitea ships with open registration, so a visitor can sign up, create a repository, and qualify. The fix has been out since 27 July. Miners are already running.

A 2023 flaw with a 2023 fix was used to take nuclear-material records this year

2026-08-31

CVE-2023-49105 lets anyone read, change or delete files on an ownCloud server without authenticating, if they know a username and the default configuration is in place. It was fixed in November 2023. It has now been used against a Philippine nuclear research body, and CISA added it to its exploited-vulnerabilities list on 27 August.

The ATF says it was a standalone system. Senior officials called it a major incident

2026-08-30

Qilin listed the Bureau of Alcohol, Tobacco, Firearms and Explosives on its leak site on 26 August. The ATF confirmed an intrusion into a standalone system it disconnected, and says its mission is unaffected. It also confirmed that senior Justice Department officials designated the event a major incident — a federal threshold with a definition.

This backdoor never phones home — it waits for a packet, and everything hunting for beacons misses it

2026-08-26

Sleepwalker is a Windows backdoor with a 23-instruction custom bytecode language, AES-256-CCM, and no outbound connections at all. It sits dormant until a specially crafted packet arrives. It loads by side-loading through a security vendor's own management agent while pretending to be Microsoft's dpapi.dll — and the researcher who found it says plainly that he cannot name a single victim.

The fake GTA VI download is 113GB of nothing wrapped around a 50KB payload

2026-08-26

Days after the leak, an ISO began circulating claiming to be the leaked build. Testers report it is 99.99% empty zeroes padded around roughly 50KB of malware, and that the installer whitelists the entire C: drive in Windows Defender before it runs. The file size was the disguise: 113GB is what a real game looks like.

They phoned a security company, used real employees' names, and got in

2026-08-25

ShinyHunters registered a fake ReliaQuest SSO page and rang staff one by one, each time impersonating a named colleague from the security team. One person typed their password and approved the push. ReliaQuest says the attackers got view-only access to an Okta dashboard and nothing else — and the interesting part is which controls held.