Microsoft issues patches for SharePoint zero-day and 168 other new vulnerabilities

Microsoft on Tuesday released an update that addresses a record 169 security flaws across its product portfolio, including one vulnerability that is being exploited in the wild. Of these 169 vulnerabilities, 157 were rated as important, eight were rated as critical, three were rated as medium, and one was rated as low severity. 93 of […]
OpenAI announces GPT-5.4-Cyber with expanded access for security teams

Rabi LakshmananApril 15, 2026Vulnerability/Secure Coding OpenAI on Tuesday unveiled its latest flagship model, GPT-5.4-Cyber, a variant of GPT‑5.4 specifically optimized for defensive cybersecurity use cases, just days after rival Anthropic unveiled its own Frontier model, Mythos. “The progressive use of AI will accelerate defenders, those responsible for keeping systems, data, and users safe, so they […]
New flaw in PHP Composer allows arbitrary command execution – patch released

Ravi LakshmananApril 14, 2026Vulnerabilities / DevSecOps Two high-severity security vulnerabilities have been disclosed in Composer, a PHP package manager, that could allow arbitrary command execution if successfully exploited. The vulnerability is described as a command injection flaw affecting the Perforce VCS (version control software) driver. Details of the two defects are below. CVE-2026-40176 (CVSS Score: […]
AI-driven Pushpaganda scam exploits Google Discover to spread scareware and ad fraud

Cybersecurity researchers have uncovered a new ad fraud scheme that uses search engine poisoning (SEO) techniques and artificial intelligence (AI)-generated content to push deceptive news articles into Google’s Discover feed and trick users into enabling persistent browser notifications that lead to scareware and financial fraud. The campaign was found targeting Android and Chrome users’ personalized […]
Google adds Rust-based DNS parser to Pixel 10 modems for added security

Ravi LakshmananApril 14, 2026Mobile security / network security Google announced that it is integrating a Rust-based Domain Name System (DNS) parser into its modem firmware as part of its continued efforts to strengthen the security of Pixel devices and push memory-safe code at a more fundamental level. “The new Rust-based DNS parser significantly reduces security […]
Mirax Android RAT turns devices into SOCKS5 proxies and reaches 220,000 via meta ads

An earlier Android remote access Trojan called Mirax has been observed actively targeting Spanish-speaking countries, with campaigns reaching over 220,000 accounts on Facebook, Instagram, Messenger, and Threads through ads on Meta. Clafy, an Italian online fraud prevention company, said: “Mirax integrates advanced remote access Trojan (RAT) capabilities, allowing attackers full interaction with compromised devices in […]
Analysis of 216 million security findings reveals 4x increase in critical risks (2026 report)

hacker newsApril 14, 2026Application Security/DevSecOps OX Security recently analyzed 216 million security findings across 250 organizations over a 90-day period. The key takeaway is that outstanding alert volume increased by 52% year-over-year, while high-priority critical risks increased by nearly 400%. The proliferation of AI-assisted development is creating a “velocity gap” where the density of high-impact […]
108 malicious Chrome extensions steal Google and Telegram data, affecting 20,000 users

Ravi LakshmananApril 14, 2026Data theft / browser security Cybersecurity researchers have discovered a new campaign in which a cluster of 108 Google Chrome extensions were found to be communicating with the same command-and-control (C2) infrastructure with the goal of harvesting user data and enabling browser-level exploits by injecting ads and arbitrary JavaScript code into every […]
ShowDoc RCE flaw CVE-2025-0520 Actively exploited on unpatched servers

Ravi LakshmananApril 14, 2026Vulnerability/Network Security A critical security vulnerability affecting ShowDoc, a popular document management and collaboration service in China, is being exploited in the wild. The vulnerability in question is CVE-2025-0520 (also known as CNVD-2020-26585), which has a CVSS score of 9.4 out of 10.0. This is related to the unrestricted file upload case […]
Added 6 known flaws exploited in CISA, Fortinet, Microsoft, and Adobe software.

Ravi LakshmananApril 14, 2026Vulnerability/Network Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added six security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Here is the list of vulnerabilities: CVE-2026-21643 (CVSS Score: 9.1) – A SQL injection vulnerability in Fortinet FortiClient EMS could allow an unauthenticated attacker […]