News
SP Page Builder for Joomla Hit by 4 New Flaws (CVE-2026-65766 and More): Data-Leak Risk, Update to 6.7.1
SecurityDevelopment
Two popular page-building tools for Joomla let anyone take over a server without a password. Both SP Page Builder (CVE-2026-48908) and Page Builder CK (CVE-2026-56290) are rated the maximum 10.0, are under active attack worldwide, and plant secret admin accounts. Update SP Page Builder to 6.6.2 and Page Builder CK to 3.6.0 now.
2026.07.0842 views
News
A Hidden Admin Password (Backdoor) in Tenda Wi-Fi Routers: CVE-2026-11405, and There's No Patch
InfrastructureSecurity
Multiple Tenda Wi-Fi routers ship with a hidden admin password (a backdoor): anyone who can reach the admin page can take the router over with no login (CVE-2026-11405). There is no vendor fix — here's how to check your model and protect yourself.
2026.07.0798 views
News
Self-hosted Git "Gitea" hit by admin-takeover flaw: CVE-2026-20896 and 8 more, update to 1.26.4
DevelopmentSecurityInfrastructure
Gitea, the self-hosted source-code tool, was patched for nine security flaws in version 1.26.4. The worst lets an attacker impersonate the admin with no password on Docker instances using a specific setting. If you self-host Gitea, update now.
2026.07.0496 views
Lab
Claude Desktop Comes to Linux: Cowork Runs a Real VM Inside Your PC
DevelopmentLinuxAI
Claude's desktop app now runs on Linux (Ubuntu/Debian). Cowork boots a VM inside your own PC, but Linux trips over a 'kvm' permission. Here's why, and the fix.
2026.07.03223 views
News
On-Prem SharePoint Takeover With No Login — CVE-2026-50522 & More, Patch Now
SecurityInfrastructure
Microsoft's on-premises SharePoint Server has a flaw (CVE-2026-45659) that lets even a low-privilege user run code on the server. CISA confirms exploitation. Editions 2016/2019/Subscription are affected; SharePoint Online is not. The fix is out — patch unpatched servers now.
2026.07.0244 views
News
CVE-2025-62593: One Web Page Can Hijack a Ray Developer's Laptop
SecurityAI
Ray, the AI distributed-computing framework used by OpenAI and Uber, has a flaw (CVE-2026-57516): loading a crafted dataset (.tar) runs arbitrary code on the server. Ingesting public data and models becomes dangerous. Severity 8.8 — update to 2.56.0.
2026.07.0233 views
News
CWP takeover flaw CVE-2026-57517: exploit code is public
SecurityInfrastructure
Control Web Panel (CWP, formerly CentOS Web Panel), a free Linux server management panel, has a flaw (CVE-2026-57517) that lets an unauthenticated attacker manipulate the database and take over the server. 150,000+ instances are exposed — update to 0.9.8.1225.
2026.07.0248 views
News
Fastify middie flaw CVE-2026-14198 lets a crafted URL bypass auth; update to 9.3.3
DevelopmentSecurity
middie, a popular plugin for the Node.js web framework Fastify, has a flaw (CVE-2026-14198): a crafted URL bypasses auth and other middleware. No login needed, severity 9.1 — update to 9.3.3.
2026.07.0123 views
News
LatePoint CVE-2026-13228: 5.6.9 is no longer enough, update to 5.6.10
DevelopmentSecurity
A flaw in the WordPress booking plugin LatePoint (CVE-2026-13228) lets a staff-level account take over the whole site. 100,000+ sites are affected — update to version 5.6.4 now.
2026.07.0127 views
News
Critical Flaw in BMC Control-M (CVE-2026-10539): Server Takeover With No Password — Update to 9.0.21.300
SecurityInfrastructure
BMC Control-M, which runs companies' core batch jobs, has a critical flaw: a passwordless attacker can take over the server (CVE-2026-10539, CVSS 9.0). Update to 9.0.21.300.
2026.07.0180 views
News
Aflac Japan Leaks Data on 4.38 Million Customers: What Policyholders Should Do, and the 'Instant Withdrawal' Myth
Japanese CompaniesSecurityPrivacy
Aflac Japan leaked ~4.38M customers' data via unauthorized access, incl. bank accounts for ~230,000. Does that mean instant withdrawal, and what should policyholders do?
2026.07.0190 views
News
JR Ticket Machines and Ekinet Go Down Nationwide at Once: Why One Fault Stops All of JR — Inside the MARS System
Japanese CompaniesInfrastructure
On July 1, 2026, JR ticket machines, Ekinet and e5489 failed nationwide. The cause: MARS, the system running all JR reservations. Why one fault stops every JR, and what travelers can do.
2026.07.0156 views