SharePoint RCE, Muse AI Backdoor, KVM Guest Escape, Comment2Shell and More

THN Daily Updates
Newsletter
cover

Cybersecurity Blue Team Operations: Principles and Practices for Building Robust Defensive Operations ($118.95 Value) FREE for a Limited Time

Build resilient defensive operations aligned with strategic business objectives

Download Now Sponsored
LATEST NEWS Sep 22, 2026

DORA Year Two: Can Your SOC Actually See the Attack?

When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025, it triggered an administrative sprint. Financial entities spent the first year establishing risk governanc...

Read More
Twitter Facebook LinkedIn

New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory

A new flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled. The bug, tracked as&n...

Read More
Twitter Facebook LinkedIn

1Password Survey: 71% of Technical Roles Use Unsecure Methods to Handle Secrets

Give developers a program to discover, secure, govern, and audit credentials, without slowing their work.

Read More
Twitter Facebook LinkedIn

SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE

A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details publi...

Read More
Twitter Facebook LinkedIn

One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor

Malware already running on a Mac can quietly take over Meta's Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on S...

Read More
Twitter Facebook LinkedIn

Why Deepfake Legislation Won't Save the 2026 Elections

More than 30 states have introduced or passed political deepfake rules as campaigns turn to faster detection and content verification.

Read More
Twitter Facebook LinkedIn

WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session

A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site's server. WordP...

Read More
Twitter Facebook LinkedIn

Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence...

Read More
Twitter Facebook LinkedIn
cover

Cybersecurity Blue Team Operations: Principles and Practices for Building Robust Defensive Operations ($118.95 Value) FREE for a Limited Time

Build resilient defensive operations aligned with strategic business objectives

Download Now Sponsored

This email was sent to sikubaycom.s3cr3tz@blogger.com. You are receiving this newsletter because you opted-in to receive relevant communications from THN. To manage your email newsletter preferences, please click here.

Contact THN: info@thehackernews.com
Unsubscribe

THN | K.P BLock, Pitampura, Delhi