A critical security flaw has emerged in Drupal Core, potentially allowing unauthenticated attackers to execute arbitrary code on servers using PostgreSQL databases. Tracked as CVE-2026-9082, the vulnerability is a high-severity SQL injection within Drupal’s database abstraction …
Month: May 2026
The Ethereum Foundation is weathering its most significant exodus of talent since the organization’s inception. In May 2026 alone, five senior researchers departed—including two high-profile resignations announced this week: Julian Ma, a cryptoeconomics researcher with four …
Rathnakishore Giri, a 31-year-old Ohio man, has been sentenced to nine years in federal prison for orchestrating a $10 million Bitcoin Ponzi scheme. The sentencing, handed down on May 18, 2026, marks one of the most …
The volunteer development team behind RPCS3, the leading open-source PlayStation 3 emulator, has issued a stark warning to contributors: stop submitting AI-generated “slop code” or face bans from the project. The announcement marks one of the …
NVIDIA has confirmed a data breach affecting GFN.AM, a regional Alliance partner operating GeForce NOW cloud gaming services in Armenia and surrounding territories. The breach, which occurred between March 20-26, 2026, was detected on May 2, …
The gaming industry is currently weathering a storm of high-profile security breaches, with one of the most notorious threat actors, ShinyHunters, leading a coordinated “pay or leak” extortion campaign. Among the primary targets is Rockstar Games, …
A series of critical security vulnerabilities in the SEPPMail Secure E-Mail Gateway have recently been disclosed, which could allow unauthenticated remote attackers to achieve full Remote Code Execution (RCE) and intercept all mail traffic flowing through …
Universal Robots has patched a critical vulnerability affecting its PolyScope 5 operating system that could allow attackers to remotely execute arbitrary commands on industrial cobots. The flaw, rated 9.8 out of 10 on the CVSS scale, …
Proof-of-concept (PoC) exploit code has been released for “DirtyDecrypt” (also known as DirtyCBC), a Linux kernel vulnerability that allows local privilege escalation to root. The release marks the latest in a series of copy-on-write (COW) bypass …
A sophisticated supply chain attack has compromised the popular actions-cool/issues-helper GitHub Action, redirecting all existing tags to imposter commits designed to steal CI/CD credentials. The attack represents a new evolution in software supply chain exploitation, bypassing …
A compromised version of the Nx Console extension for VS Code has been discovered stealing credentials from over 2.2 million developers. Version 18.95.0 of the popular extension (rwl.angular-console) contained a multi-stage credential stealer that silently harvested …
Artificial intelligence is no longer a futuristic concept in healthcare—it’s transforming medicine today. From ambient AI scribes that automatically document patient visits to predictive analytics that identify disease risks before symptoms appear, 2026 marks a pivotal …