Critical Next.js Bug Puts Applications at Risk
A serious security issue in Next.js could allow attackers to run code on a server by sending specially crafted SVG content. Tracked as CVE-2026-94545, the vulnerability affects the Node.js version [...]
GitLab Flaw Lets Attackers Push Code to Private Repos
GitLab’s “Email work item to this project” feature could create a security risk when its private email address becomes exposed, according to research from Aikido Security researcher Joe Leon. The [...]
SharePoint Vulnerability Enables Remote Code Execution
Microsoft has disclosed a high-severity security flaw in its on-premises SharePoint Server products that could allow an authenticated attacker with low-level access to execute malicious code remotely. The vulnerability is [...]
Active Attacks Target Check Point 0-Day
Check Point has released emergency security updates for a critical zero-day vulnerability affecting its Security Management products. The flaw, tracked as CVE-2026-93616, has a CVSS score of 9.8 and is [...]
Malicious npm Package with 2M Downloads Exposed
A malicious npm package has been discovered hiding behind the name of a legitimate developer tool. Security researchers say the package, indexed-btree, was designed to look like the popular sorted-btree [...]