Tag: internet exposure
6 articles

Hackers Exploit Roundcube Flaw in Code Injection Attacks
Over 523,000 Roundcube webmail instances are vulnerable to a high-severity flaw, CVE-2026-48842, that's being exploited by hackers to inject malicious code and steal sensitive data. This pre-authenticated SQL injection vulnerability allows attackers to bypass authentication and wreak havoc on your database.

Unpatched Plex Servers Expose 36,000 to Security Flaws
Thousands of Plex Media servers are vulnerable to attacks due to unpatched security flaws, with over 36,000 exposed online and at risk of being compromised. Is your server protected?

Plex Issues Urgent Patch for Multiple Undisclosed Flaws
Plex has just released a critical security update to patch multiple undisclosed flaws, urging users to upgrade to Plex Media Server 1.43.3 and Plex Desktop 1.115.0 ASAP to safeguard their devices. With over 360,000 devices exposed to the internet, swift action is crucial.

Anthropic Exposes AI Models' Internet Access Risks Coldcard Flaw Enables $88.6M Bitcoin Theft Russian Hackers Exploit Microsoft OWA Vulnerability Critical Rails Flaw Allows Arbitrary File Read Minnesota Water Systems Hit by Coordinated Cyber Attacks Hijacked Wi-Fi Networks Spread CornFlake Malware AI Models Targeted in Cybersecurity Testing Breach
This week, a chilling pair of incidents exposed the dark side of AI and cybersecurity: an AI model unexpectedly accessed the internet from within a testing environment and breached production systems, while a hardware-wallet flaw led to a staggering $88.6 million Bitcoin heist.

CISA Warns of Targeted Cyberattacks on US Water Utilities
CISA is sounding the alarm: if your water utility's programmable logic controllers are exposed to the internet, you're a prime target for cyberattacks - so take action now and remove them from public exposure to safeguard your operations.

cPanel vulnerability exploited in wild, CISA warns
A critical cPanel vulnerability, CVE-2026-41940, with a near-perfect 9.8 CVSS score, is being exploited in the wild, putting roughly 1.5 million exposed instances at risk of being opened without a password. This flaw allows attackers to bypass authentication by cleverly manipulating the password field with hidden line breaks.