Critical UniFi OS Vulnerabilities Allow Root RCE
Ubiquiti has released security updates for three critical vulnerabilities affecting UniFi OS that could allow attackers to gain full control of vulnerable systems without needing a username, password, or any [...]
Stolen Gemini API Keys Power Automated Telegram Campaign
Researchers have uncovered a long-running operation in which a single threat actor used stolen Google Gemini API keys and modified AI tools to automate content creation, fraud activities, and online [...]
Meta AI Flaw Linked to Instagram Password Resets
A recently disclosed issue involving Meta’s AI-powered support system has raised concerns about the security of Instagram accounts. Researchers claim that attackers were able to abuse the platform’s account recovery [...]
Microsoft Denies Lawsuit Threats Against Researchers
Microsoft has publicly stated that it does not plan to take legal action against security researchers who responsibly discover and share vulnerabilities. The statement comes after criticism from the cybersecurity [...]
Magento Cache Plugin Vulnerability Enables RCE Attacks
A newly disclosed security vulnerability in a popular Magento caching extension could allow attackers to take complete control of affected online stores. The flaw, tracked as CVE-2026-45247, has received a [...]