generalnews.media
All World Business Technology Science Health Sports Entertainment Security
67 stories
Exclusive

Critical cPanel Flaw May Let Hosting Users Execute SQL as Database Root

A critical vulnerability in cPanel could allow hosting customers to run SQL queries with database root privileges. This flaw threatens the security of shared hosting environments, potentially exposing sensitive data across multiple accounts. Hosting providers should apply updates immediately.

Exclusive

Malicious npm Packages Infect Alibaba Tool Users with Cross-Platform RAT

Security researchers discovered 18 malicious npm packages that deliver a cross-platform remote access trojan (RAT) to users of Alibaba cloud development tools. The packages masquerade as legitimate dependencies, and once installed, they can steal sensitive data or enable remote control. This highlights an ongoing supply chain risk in the open-source ecosystem.

Exclusive

Malware Could Exploit Google Password Manager to Hijack Passkey-Protected Accounts

Security researchers have discovered attack methods that let malware abuse Google Password Manager to steal passkeys and take over protected accounts. These techniques bypass the intended protections of passkey-based authentication, which is increasingly used as a safer alternative to passwords. The findings highlight a critical weakness in how passkeys are stored and accessed, urging users to stay alert to malware risks.

Exclusive

INC Ransomware Becomes Top Threat via SonicWall SMA 1000 Flaws

INC ransomware has emerged as the most dominant threat actor exploiting vulnerabilities in SonicWall SMA 1000 devices. This gives the group a reliable entry point into corporate networks, significantly raising ransomware risks for affected organizations.

Exclusive

PNLD Breach Exposes U.K. Police and Government Contacts on Dark Web

A breach of the Police National Legal Database (PNLD) has leaked contact details of U.K. police and government personnel onto the dark web. The exposed information could be used for targeted phishing and social engineering attacks against officials. This highlights serious security concerns over sensitive law enforcement data handling.

security

N-able Warns Attackers Fully Compromised N-central Servers After Patch Failed

N-able disclosed that attackers gained full control of N-central servers after an initial security fix proved incomplete. The remote monitoring platform is widely used by managed service providers, so a server takeover could expose client networks downstream. The company is urging customers to apply a new patch and check for signs of compromise.

security technology

Hugging Face Breach: OpenAI Hacker Was Noisy and Fast but Not Unstoppable

A hacker who breached AI platform Hugging Face also targeted OpenAI, acting with unusual speed and visibility. The attacker exploited vulnerabilities to access sensitive data but was eventually blocked. The incident highlights ongoing security risks in the fast-growing AI ecosystem.

security

Critical OpenWrt DHCPv6 Flaw Allows Unauthenticated Root Code Execution

A critical security vulnerability has been discovered in OpenWrt's DHCPv6 implementation, allowing unauthenticated attackers to execute arbitrary code as root. The flaw affects many routers and IoT devices running the open-source firmware, potentially giving attackers full device control without any credentials. This is significant because it could lead to widespread exploitation, compromising network security and privacy.

Exclusive

Atlassian Rovo Flaw Lets Attackers Steal Jira and Confluence Data

Researchers have demonstrated that Atlassian's Rovo AI assistant can be manipulated through prompt injection to exfiltrate sensitive data from connected Jira and Confluence projects. The attack requires a user to interact with maliciously crafted content, potentially exposing confidential corporate information to external actors. Administrators should restrict Rovo access and monitor for unusual activity until a patch is available.