Aggregator
Microsoft Edge, Windows 11 and LiteLLM Hacked in Pwn2Own Berlin 2026
Pwn2Own Berlin 2026 opened with a surge of zero-day exploits targeting modern browsers, operating systems, and emerging AI platforms. On Day One alone, security researchers successfully hacked Microsoft Edge, Windows 11, and LiteLLM, earning a total of $523,000 for 24 unique vulnerabilities. The results highlight a growing reality that AI ecosystems and core enterprise technologies […]
The post Microsoft Edge, Windows 11 and LiteLLM Hacked in Pwn2Own Berlin 2026 appeared first on Cyber Security News.
CISA orders all federal agencies to patch exploited bug in Cisco SD-WAN systems by Sunday
Hackers Use OrBit Rootkit to Harvest SSH and Sudo Credentials From Linux Systems
A dangerous rootkit called OrBit has been quietly targeting Linux systems for years, stealing login credentials and hiding deep inside infected machines without triggering most security tools. New research reveals that what was once believed to be a custom-built threat is actually a modified version of a publicly available rootkit, spreading across the globe through […]
The post Hackers Use OrBit Rootkit to Harvest SSH and Sudo Credentials From Linux Systems appeared first on Cyber Security News.
CVE-2026-8520 | Google Chrome up to 148.0.7778.96 Payments race condition (ID 503619 / Nessus ID 314863)
CVE-2026-8528 | Google Chrome up to 148.0.7778.96 SiteIsolation input validation (ID 487795 / Nessus ID 314860)
CVE-2026-8529 | Google Chrome up to 148.0.7778.96 Codecs heap-based overflow (ID 490222 / Nessus ID 314861)
AL26-012 - Critical vulnerability affecting Cisco Catalyst SD-WAN - CVE-2026-20182
Living Off the Pipeline: Defending Against CI/CD Subversion
В стандартных функциях PHP для JPEG нашли раскрытие данных из памяти и переполнение буфера
The Good, the Bad and the Ugly in Cybersecurity – Week 20
Defending Against DDoS Attacks at Scale
Google lets Workspace admins apply one policy across all SAML apps
Google has updated Context-Aware Access (CAA) in Google Workspace to introduce a default policy assignment for SAML applications. SAML applications are third-party or internal applications that use the Security Assertion Markup Language (SAML) protocol to enable single sign-on (SSO) with Google Workspace credentials. Google says this update introduces a default assignment that serves as a universal security baseline, automatically protecting any SAML-based application that does not have a specific policy already assigned. By establishing this … More →
The post Google lets Workspace admins apply one policy across all SAML apps appeared first on Help Net Security.
Cisco patches another actively exploited SD-WAN zero-day (CVE-2026-20182)
Cisco has patched yet another Catalyst SD-WAN Controller authentication bypass vulnerability (CVE-2026-20182) that has been exploited as a zero-day by “a highly sophisticated cyber threat actor”. About CVE-2026-20182 CVE-2026-20182 – affecting both Cisco Catalyst SD-WAN Controller (the “brain” of the Cisco Catalyst SD-WAN solution) and Cisco Catalyst SD-WAN Manager (the management plane for the entire SD-WAN fabric) – stems from a flawed peering authentication mechanism. It affects both on-prem and cloud deployments. CVE-2026-20182 was reported … More →
The post Cisco patches another actively exploited SD-WAN zero-day (CVE-2026-20182) appeared first on Help Net Security.