Tech News
← Home  ·  All topics

2026

231 GoKawiil briefs on this topic

Acronis fixes actively exploited privilege escalation bug in cPanel/Plesk backup plugin

Acronis has patched a high-severity local privilege escalation flaw, tracked as CVE-2026-87886, in its backup add-ons for cPanel/WHM and Plesk. The company says it has seen limited, targeted exploitation attempts against affected deployments, based on a report from one potentially affected customer. Fixed versions are 1.9.3 HF3 for cPanel/WHM and 1.8.11 for Plesk.

TechCrunch Disrupt 2026 to host session on scaling AI prototypes into production

TechCrunch Disrupt 2026, running October 13–15 at Moscone West in San Francisco, will feature a session called 'From Prototype to Production: Can It Scale in Reality?' on its Real World AI Stage. The panel brings together founders from space communications, autonomous systems, and AI infrastructure to discuss how they moved their technologies from early prototypes to reliable, deployable products.

TIFF 2026: 'Vintage Violence' turns phone addiction into crime-thriller chaos

Director Eugene Kotlyarenko's new film, screened at TIFF 2026, follows a disgraced influencer played by Cole Sprouse who travels to Tokyo to sell rare vintage Levi's and gets tangled up with yakuza scammers. The movie stands out by constantly showing characters' phone screens and livestreams onscreen, mimicking the experience of being perpetually online while blending comedy with bloody, Miike-style violence.

WooCommerce Wholesale Lead Capture flaw exploited to plant PHP backdoors

Hackers are exploiting an unauthenticated file-upload vulnerability (CVE-2026-27540) in the WooCommerce Wholesale Lead Capture plugin for WordPress, versions 2.0.3.1 and earlier, to install PHP webshells. Wordfence says its firewall has blocked over 100,000 attack attempts, with spikes in June, July and August, and the shells allow attackers to gather site information and upload further malicious files.

PaperCut's August patch failures show zero-day response now measured in hours

PaperCut disclosed active exploitation of PaperCut NG/MF servers on August 27 with no CVE, no available exploit sample, and no patch. An emergency fix issued the next day was bypassed within hours, and a third patch only arrived on September 1, leaving customers exposed for roughly six days while attackers were already using the flaw in live attacks. A security researcher uses the episode to argue that the industry's old assumptions about response timelines no longer hold.

CISA confirms ransomware groups exploiting critical VMware vCenter flaw CVE-2026-59310

CISA has updated its Known Exploited Vulnerabilities catalog to flag ransomware gangs actively exploiting a critical VMware vCenter directory traversal flaw, CVE-2026-59310, patched by Broadcom in July. The bug had already been abused by a suspected APT group to compromise over 361 IP addresses across 47 countries, and Shadowserver now tracks more than 450 exposed vCenter servers online.

Cisco patches actively exploited zero-day in Secure Email Gateway software

Cisco released fixes for CVE-2026-76461, a critical flaw in AsyncOS Software for Secure Email Gateway that lets unauthenticated attackers run root-level commands by sending crafted emails with malicious SQL statements. The company confirmed it detected active exploitation of the bug in September 2026 and issued indicators of compromise for defenders to check mail logs and network traffic. CISA has added the flaw to its Known Exploited Vulnerabilities catalog, giving federal agencies until September 17 to patch.

Sandworm exploits two Cisco FMC bugs to deploy new Cyclops Blink malware

Security researchers at Sophos and Cisco report that a suspected Russian state actor, previously tied to the Sandworm group linked to Russia's GRU, is exploiting two vulnerabilities in Cisco's Secure Firewall Management Center software. The attackers chain a maximum-severity authentication bypass flaw with a lower-severity privilege escalation bug to install a reverse shell and then deploy an updated version of the Cyclops Blink implant, which can steal credentials, map internal networks, and intercept live traffic.

Attackers Actively Exploiting Critical GitLab Path Traversal Bug, CVE-2026-85706

A maximum-severity flaw in GitLab's Community and Enterprise editions, patched September 10, is being actively exploited to pull arbitrary files from self-hosted GitLab servers without authentication. WatchTowr researchers say attackers have moved from probing to full exploitation, extracting configuration files, secrets, and SSH settings from compromised systems. CISA has added the bug to its Known Exploited Vulnerabilities list, ordering federal agencies to patch or take affected instances offline.

Oracle Fires Employees via 6AM Emails in Latest Restructuring Round

Oracle has begun another round of layoffs, sending termination emails to staff as early as 6 a.m. Monday as part of its ongoing fiscal 2026 restructuring. The company's workforce already shrank by about 21,000 people this fiscal year, and Oracle has now increased its restructuring cost estimate by $700 million to roughly $2.8 billion, though the exact number of newly affected employees remains undisclosed.

Nintendo patches Switch QR code exploit letting nearby hackers hijack consoles

Nintendo disclosed a security flaw affecting original Switch consoles that exploits the QR codes used by the Send to Smartphone feature and Super Mario Kart: Home Circuit's wireless pairing. If someone scans the QR code before the owner does, they can connect to the console and run unauthorized code or steal stored account data. Nintendo fixed the issue, tracked as CVE-2026-82079, in firmware update 23.0.0 released September 9.

Blizzard Announces New Open-World StarCraft Shooter for 2030

Blizzard Entertainment revealed a new StarCraft game at BlizzCon 2026, marking the franchise's first mainline entry since 2015's Legacy of the Void. The open-world, story-driven shooter is directed by Dan Hay and takes place in the Koprulu Sector seventy years after the previous game's events, with a targeted 2030 release.