Topic: information disclosure

  • Microsoft critical vulnerabilities double: Exposure to escalation

    Microsoft critical vulnerabilities double: Exposure to escalation

    Microsoft disclosed 1,273 vulnerabilities in 2025, a slight overall decrease from 2024, but critical vulnerabilities doubled from 78 to 157, reversing a multi-year downward trend. Elevation of Privilege flaws now account for 40% of all CVEs, Information Disclosure flaws jumped 73%, and Microsoft ...

    Read More »
  • Africa CDC Confirms Uganda Marburg Case Amid Ongoing Ebola Outbreak

    Africa CDC Confirms Uganda Marburg Case Amid Ongoing Ebola Outbreak

    A fatal Marburg virus disease case in a Ugandan child has been confirmed by Africa CDC, but Ugandan officials are reluctant to disclose full details, and a spokesperson denied awareness of any outbreak. The U.S. embassy issued a health alert on a potential case, and an anonymous source claimed tw...

    Read More »
  • CISA Warns of Active Attacks Exploiting Wing FTP Server Flaw

    CISA Warns of Active Attacks Exploiting Wing FTP Server Flaw

    CISA has issued an urgent alert for a vulnerability (CVE-2025-47813) in Wing FTP Server that is being actively exploited to leak sensitive system information and could be chained with a critical remote code execution flaw. The software's developer patched this and other vulnerabilities in May 202...

    Read More »
  • Microsoft Patches Critical Zero-Day and 63 Flaws

    Microsoft Patches Critical Zero-Day and 63 Flaws

    Microsoft's November 2025 Patch Tuesday addresses 63 vulnerabilities, including one actively exploited zero-day and four critical issues, requiring immediate deployment by system administrators. The update includes the first extended security update (ESU) for Windows 10, urging organizations to u...

    Read More »
  • Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flaws

    Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flaws

    Microsoft's June 2026 Patch Tuesday addresses 200 vulnerabilities, including six zero-day flaws, with five publicly disclosed and one actively exploited, featuring 33 Critical bugs primarily involving remote code execution. Key zero-day fixes include CVE-2026-45586 (CTFMON "GreenPlasma" privilege...

    Read More »
  • Google Patches Actively Exploited Android Security Flaws

    Google Patches Actively Exploited Android Security Flaws

    Google's December security update patches over 50 Android vulnerabilities, including two high-severity flaws in the Android Framework that are already being used in limited, targeted attacks. The two critical vulnerabilities (CVE-2025-48633 and CVE-2025-48572) could allow unauthorized access to s...

    Read More »
  • Critical Vulnerability in All In One SEO Plugin Impacts 3M+ WordPress Sites

    Critical Vulnerability in All In One SEO Plugin Impacts 3M+ WordPress Sites

    A critical vulnerability in the All in One SEO plugin exposed its global AI access token to any logged-in user with Contributor-level permissions, risking unauthorized AI usage and service credit depletion. The flaw, stemming from a missing permission check on an API endpoint, is part of a trend,...

    Read More »
  • Google Patches Actively Exploited Zero-Day Vulnerabilities

    Google Patches Actively Exploited Zero-Day Vulnerabilities

    Google has released a critical Android security update patching over 100 vulnerabilities, including three severe flaws that are under active, targeted exploitation. Two high-severity information disclosure vulnerabilities (CVE-2025-48633 & CVE-2025-48572) can expose sensitive data or grant elevat...

    Read More »
  • Microsoft Patches 6 Zero-Day Exploits in Critical October Update

    Microsoft Patches 6 Zero-Day Exploits in Critical October Update

    Microsoft's October 2025 Patch Tuesday addresses 172 vulnerabilities, including six actively exploited zero-days and eight critical-rated flaws, with a focus on remote code execution and privilege escalation risks. Windows 10 has reached its end of support, requiring users to enroll in Extended S...

    Read More »
  • Cisco Patches Actively Exploited SD-WAN vManage Zero-Day Flaw

    Cisco Patches Actively Exploited SD-WAN vManage Zero-Day Flaw

    Cisco released emergency patches for a critical zero-day vulnerability (CVE-2026-20262) in Catalyst SD-WAN Manager, which is actively exploited in the wild to allow attackers with low-level privileges to escalate to root access. The flaw stems from insufficient input validation during file upload...

    Read More »
  • Starbucks Employee Data Breach Impacts Hundreds

    Starbucks Employee Data Breach Impacts Hundreds

    A security breach at Starbucks compromised the personal data of several hundred employees by targeting the internal **Starbucks Partner Central** platform, which manages work schedules and payroll. The exposed data likely includes sensitive information like names and Social Security numbers, prom...

    Read More »
  • Popular Game Servers Shutting Down Soon, Will Be Delisted

    Popular Game Servers Shutting Down Soon, Will Be Delisted

    WWE 2K24's online servers will permanently shut down on March 31, 2026, disabling all online features, though offline modes will remain playable. The game will be delisted from digital stores on January 31, 2026, halting all purchases of virtual currency and downloadable content. This follows a c...

    Read More »
  • Nintendo 2026 Switch 2 Games Leak: 3D Mario, Direct Plans

    Nintendo 2026 Switch 2 Games Leak: 3D Mario, Direct Plans

    A significant leak suggests Nintendo's Switch successor will have a strong first-year lineup, potentially launching with a new 3D Mario game and followed by a new Mario Kart. The leaked roadmap also indicates plans for major franchise revivals and new entries, including Donkey Kong, Pokémon Gen 1...

    Read More »
  • Oracle Issues Urgent Patch for Critical E-Business Suite Flaw

    Oracle Issues Urgent Patch for Critical E-Business Suite Flaw

    Oracle has released an urgent security patch for a critical vulnerability (CVE-2025-61884) in its E-Business Suite, which can be exploited remotely without authentication to access confidential information. The vulnerability, with a CVSS score of 7.5, affects EBS versions 12.2.3 to 12.2.14, and O...

    Read More »
  • US to Survey Data Center Energy Consumption

    US to Survey Data Center Energy Consumption

    The US government is launching a mandatory survey to collect comprehensive data on electricity usage from data center operators, addressing a lack of precise public information. This initiative responds to concerns about surging power demand from AI, cloud computing, and cryptocurrency, which is ...

    Read More »
  • Healthcare Sector: 58 Days to Patch Critical Security Flaws

    Healthcare Sector: 58 Days to Patch Critical Security Flaws

    Healthcare organizations are slow to patch serious security vulnerabilities, leaving sensitive systems and patient data exposed for extended periods. The sector remediates only 57% of serious findings, with a median resolution time of 58 days and an average of 244 days to address half of all issu...

    Read More »
  • Windows Zero-Day "BlueHammer" Leaked by Researcher

    Windows Zero-Day "BlueHammer" Leaked by Researcher

    A security researcher has publicly released exploit code for a new, unpatched privilege escalation vulnerability in Windows. The flaw allows attackers to gain the highest system-level permissions, turning a limited breach into a full system takeover. The disclosure before a Microsoft patch is ava...

    Read More »
  • FEMA Shadow Admin Paid by DOGE Member's Startup for Months

    FEMA Shadow Admin Paid by DOGE Member's Startup for Months

    A shadow administrator at FEMA received paychecks from a startup tied to a senior DOGE figure for months, while holding access to sensitive agency systems and workflows, according to newly unsealed court records. The arrangement raises conflict-of-interest concerns, as the administrator’s duties ...

    Read More »
  • Google Pixel 11 base model drops HiLight but gains ample RAM

    Google Pixel 11 base model drops HiLight but gains ample RAM

    The base Pixel 11 will reportedly drop the previously expected HiLight photo enhancement feature, a notable cut to its camera software. In compensation, the device will ship with 12GB of RAM, a significant upgrade over its predecessor for smoother multitasking and performance. The trade-off appea...

    Read More »
  • Galaxy S26 FE specs leak reveals higher price

    Galaxy S26 FE specs leak reveals higher price

    The Galaxy S26 FE is expected to launch next month with a 6.7-inch 120Hz AMOLED display, Exynos 2400 chipset, up to 12GB RAM, and 512GB storage, plus a 50MP main camera and 4,500mAh battery with 45W charging. The base model will reportedly cost $649, a $50 increase over the S25 FE, with the top-t...

    Read More »