Website profile

Cyber Security News

  • 210articles · 30d
  • 4+ day agolatest article
  • Aug 18, 2026earliest in window
  • 1%with images
  • 353avg words
articles per day
Covers
People
Places
Organizations
Categories
  • Computers & Electronics 137
  • Science & Technology 136
  • Software 133
  • Conflict, War & Peace 61
  • Software Dev. 36
  • Internet & Telecom 30
  • News 30
  • Crime & Law 22

Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News


cyberpress.org > 12-year-old-postgresql-flaw

12-Year-Old PostgreSQL Flaw Lets Backup Accounts Execute Code and Take Over Databases

1+ week, 2+ day ago   (360+ words) Tracked as CVE-2026-6471, the flaw was discovered by Cyera Research and affects PostgreSQL versions dating back to 9.4, released in 2014. PostgreSQL addressed the issue in its August 22, 2026 security release, ending a vulnerability window that spanned roughly 12 years. The bug exists in…...


cyberpress.org > fake-coding-tests-deliver-backdoors

Hackers Use Fake Coding Job Tests to Infect Developers With New Backdoors

1+ week, 6+ day ago   (360+ words) Cybersecurity researchers have uncovered a targeted campaign in which hackers use fake software engineering tests to infect developers with previously undocumented remote access trojans (RATs). Victims are then directed to download coding challenges hosted on legitimate cloud infrastructure such as…...


cyberpress.org > hackers-exploit-critical-langflow-and-ruby-on-rails-flaws

Hackers Exploit Critical Langflow and Ruby on Rails Flaws in Active RCE Attacks

1+ week, 6+ day ago   (292+ words) Threat actors are actively exploiting two critical remote code execution vulnerabilities affecting Langflow and Ruby on Rails. The flaw lies in the code-validation path, where insufficient validation of a user-supplied parameter before it is used to execute Python can allow…...


cyberpress.org > npm-worm-steals-dev-credentials

Popular npm Package With 150K Weekly Downloads Hit by Credential-Stealing Worm

1+ week, 6+ day ago   (349+ words) The npm package @7nohe/openapi-react-query-codegen, which receives roughly 150,000 weekly downloads, has been compromised by a malicious campaign linked by researchers to the Mini Shai-Hulud activity. The Socket Threat Research Team found that attackers published 10 malicious versions of the package on August…...


cyberpress.org > shai-hulud-worm-hits-npm

Shai-Hulud Trinitite Supply-Chain Worm Hits npm Package With 150K+ Weekly Downloads

2+ week, 11+ hour ago   (333+ words) The malicious versions use a hidden binding.gyp execution path and a large obfuscated JavaScript loader to infect developer machines and CI environments. The campaign appears linked to the previously reported Shai-Hulud “Mini” worm family, including the Here We Go…...


cyberpress.org > composer-path-traversal-flaw

Composer Path Traversal Flaw Lets Malicious Packages Expose Sensitive Files

2+ week, 13+ hour ago   (417+ words) A newly disclosed vulnerability in Composer could allow malicious or compromised PHP packages to alter permissions on files located outside their intended installation directory, potentially exposing sensitive data on shared and multi-tenant systems. Tracked as CVE-2026-59944, the flaw affects Composer…...


cyberpress.org > critical-gogs-path-traversal-flaw

Critical Gogs Path Traversal Flaw Enables Remote Code Execution via Git Hooks

2+ week, 2+ day ago   (415+ words) A critical path traversal vulnerability in Gogs, the self-hosted Git service, could let authenticated attackers achieve remote code execution by planting malicious Git hooks outside the intended repository storage directory. Tracked as CVE-2026-52813, the flaw arises from an API endpoint…...


cyberpress.org > supply-chain-worm-hits-popular-tanstack-query-code

Supply Chain Worm Hits Popular TanStack Query Code Generator to Steal Developer Credentials

2+ week, 2+ day ago   (364+ words) Aikido Security said it identified 10 malicious versions published within 20 minutes. The package records more than 150,000 weekly downloads, making the incident consequential for developers installing JavaScript dependencies. The compromise reportedly affected both the npm package and its GitHub repository. Attackers are…...


cyberpress.org > git-repositories-leak-secrets

Researchers Find 28,000 Exposed Git Repositories Leaking API Keys, Bank Details and Corporate Secrets

2+ week, 5+ day ago   (419+ words) The findings came from a scan of 3.5 million internet-facing hosts using gitreaper, an open-source tool developed by Intruder. The research highlights how a simple server misconfiguration can expose credentials that provide attackers with access to cloud services, payment platforms, private…...


cyberpress.org > critical-spring-graphql-deserialization-flaw

Critical Spring GraphQL Deserialization Flaw Enables Remote Code Execution

2+ week, 6+ day ago   (317+ words) A critical unsafe deserialization vulnerability in Spring for GraphQL, tracked as CVE-2026-59285, could enable remote code execution in affected applications under specific conditions. The flaw was disclosed in Broadcom’s August 20 security release, which included 91 CVEs affecting Spring Framework and related…...