TeamPCP is the likely cyber threat actor behind attacks on Trivy, Checkmarx's KICS and VS Code plug-ins, and the LiteLLM AI library — and all signs point to more attacks to come.
A vulnerability was found in Oracle MySQL Server up to 8.0.44/8.4.7/9.5.0. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component Optimizer. This manipulation causes denial of service.
This vulnerability is tracked as CVE-2026-21948. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability was found in Oracle MySQL Server up to 9.5.0. It has been declared as problematic. Affected by this issue is some unknown functionality of the component Optimizer. Such manipulation leads to denial of service.
This vulnerability is listed as CVE-2026-21949. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in Oracle MySQL Server up to 8.0.44/8.4.7/9.5.0. This affects an unknown function of the component Optimizer. Executing a manipulation can lead to denial of service.
The identification of this vulnerability is CVE-2026-21941. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
A vulnerability classified as problematic was found in Oracle MySQL Server up to 8.0.44/8.4.7/9.5.0. The affected element is an unknown function of the component DDL. Such manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2026-21937. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
A vulnerability classified as problematic has been found in Oracle MySQL Cluster and MySQL Server. Impacted is an unknown function of the component InnoDB. This manipulation causes denial of service.
This vulnerability is handled as CVE-2026-21936. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability described as problematic has been identified in Oracle MySQL Server up to 9.5.0. This issue affects some unknown processing of the component Parser. The manipulation results in denial of service.
This vulnerability is known as CVE-2026-21929. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.
AI is compressing cyberattack timelines from months to minutes. While segmentation has been a gold standard security practice for years, many organizations are still operating with outdated, static approaches.
An OnDemand Webinar from Rubrik As federal agencies expand their cloud footprint, managing both risk and cost becomes more complex. This session explores how to close operational gaps, strengthen resilience, and take a more strategic approach to cloud protection.
Is AI Exposing a Growing Vulnerability Risk Mitigation Gap? AI-fueled tools can help to identify medical device vulnerabilities much faster and at a higher volume than more traditional tools. But can device manufacturers and healthcare delivery organizations keep up with prioritizing and addressing a tidal wave of newly discovered flaws?
7AI's Lior Div on Building Knowledge Graphs, Human Oversight to Drive AI Accuracy Security teams face an AI reality check as tools require deep organizational context to deliver value. Lior Div, co-founder and CEO of 7AI, explains how knowledge graphs, human oversight and phased adoption can help teams improve accuracy, build trust and scale AI-driven security operations.
New Rule Blocks Approval of Foreign Routers Without Federal Clearance The FCC acted on a White House security determination and announced a block on new foreign-made routers from entering U.S. markets - unless vendors meet strict national security reviews, citing their role in state-linked cyber campaigns and risks to U.S. network edge infrastructure.
Britain’s National Cyber Security Centre warned that a rise in so-called “vibe coding” could reshape the software-as-a-service industry while introducing new cybersecurity risks if organizations fail to adapt.
A vulnerability has been found in parse-community parse-server up to 8.6.50/9.6.0-alpha.39 and classified as problematic. This impacts an unknown function of the component Configuration Options Handler. Performing a manipulation results in observable response discrepancy.
This vulnerability is known as CVE-2026-33323. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
A vulnerability was found in Zabbix up to 7.0.21/7.2.14/7.4.5. It has been classified as critical. This affects an unknown function of the file include/classes/api/CApiService.php. Performing a manipulation of the argument sortfield results in sql injection.
This vulnerability was named CVE-2026-23921. The attack may be initiated remotely. There is no available exploit.
A vulnerability categorized as problematic has been discovered in parse-community parse-server up to 8.6.55/9.6.0-alpha.44. Affected by this vulnerability is an unknown functionality of the component LiveQuery. The manipulation results in uncontrolled recursion.
This vulnerability is identified as CVE-2026-33508. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability identified as critical has been detected in parse-community parse-server up to 8.6.58/9.6.0-alpha.52. Affected by this issue is some unknown functionality of the component PostgreSQL Database. This manipulation of the argument group causes sql injection.
This vulnerability is tracked as CVE-2026-33539. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
A vulnerability classified as critical was found in Zabbix up to 7.0.21/7.2.14/7.4.5. This impacts an unknown function of the component Shell Command Handler. Such manipulation leads to os command injection.
This vulnerability is documented as CVE-2026-23920. The attack can be executed remotely. There is not any exploit available.