🚨 CVE-2026-88771 & CVE-2026-88772: Citrix has patched two exploited NetScaler zero-days (CVSS 9.5). Update to 14.1-73.37 / 13.1-64.23 and check for compromise. www.cyberkendra.com/2026/09/cve-... #citrixvulnerability #netscaler #zeroday #infosec
Cyber Kendra
@cyberkendra.com
Best Source for Tech and Security News Updates. Visit - cyberkendra.com Follow US - t.me/cyberkendra | fb.com/cyberkendra
Cyber Kendra has a new look. ⚡ Cleaner layout, category hubs, dark mode, and a mobile-first design built for reading on the go. Same cybersecurity and tech news, now easier to read. 👉 cyberkendra.com Let us know your suggestions and feedback ☺️
Now it's confirmed as, watchTowr says two unpatched NetScaler RCE zero-days were found exploited during forensics. Citrix's advisory and patches are expected early next week. www.cyberkendra.com/2026/09/nets... #netscaler #citrix #zerodays #security #infosec
Unpatched NetScaler Zero-Days Exploited, watchTowr Says - Cyber Kendra
watchTowr says two unpatched Citrix NetScaler RCE zero-days have been exploited in the wild. Citrix patches are expected early next week.w
cyberkendra.com
NetScaler alert: watchTowr says reports of unpatched remote code execution flaws in Citrix NetScaler are verified, and organisations are shutting appliances down. There's no Citrix advisory, CVE or patch yet www.cyberkendra.com/2026/09/nets... #NetScaler #Citrix #ZeroDay #CyberSecurity #InfoSec
WordPress 7.1.2 fixes CVE-2026-87902, a critical no-login file inclusion flaw in core that can lead to code execution on some servers. www.cyberkendra.com/2026/09/cve-... #wordpress #webdev #security
WordPress 7.1.2 Patches CVE-2026-87902 File Inclusion Flaw - Cyber Kendra
WordPress has released version 7.1.2 to fix a critical vulnerability in its core software. The flaw lets unauthenticated attackers load local PHP files and,
cyberkendra.com
Microsoft disrupted EvilTokens, a device code phishing service that breached 12,000+ inboxes; UK police arrested two suspects. www.cyberkendra.com/2026/09/evil... #microsoft #eviltokens #phishing
Microsoft Disrupts EvilTokens Device Code Phishing Service - Cyber Kendra
Microsoft announced on Tuesday that it disrupted EvilTokens, an AI-powered phishing-as-a-service platform used to break into more than 12,000 email inboxes at
cyberkendra.com
ShinyHunters Claims FBI Hack, Theft of Employee Data The group says it stole 2–3 TB via an Oracle PeopleSoft zero-day and wants the FBI to retract a May threat report within a week. www.cyberkendra.com/2026/09/shin... #security #ShinyHunters #fbi #hack
ShinyHunters Claims FBI Hack, Theft of Employee Data - Cyber Kendra
ShinyHunters claims it hacked the FBI via a PeopleSoft zero-day and stole data on agents and applicants. The FBI is investigating.
cyberkendra.com
Comment2Shell (CVE-2026-93485) lets an anonymous WordPress comment reach RCE via an admin session. Fixed in 7.1.1 — update now. www.cyberkendra.com/2026/09/comm... #wordpress #security #comment2shell
WordPress Comment2Shell Flaw Turns Comments Into RCE - Cyber Kendra
A single anonymous comment is enough to plant a script on a WordPress site and, if an administrator later opens that post, run code on the server. The flaw,
cyberkendra.com
Meta Petal is the first 1 Pbps subsea cable, US ↔ France, due in 2029. It uses 2-core fiber to double transatlantic capacity and is being built by NEC, Sumitomo Electric and Orange. 👉 www.cyberkendra.com/2026/09/meta... #meta #facebook #internet #underwaterinternet
LG Denies Smart TV Spying Claims, Confirms Network Scan www.cyberkendra.com/2026/09/lg-d... #lgtv #iot #privacy
LG Denies Smart TV Spying Claims, Confirms Network Scan
LG denies Gamers Nexus claims its smart TVs record conversations, while confirming the sets scan home networks for other devices.
cyberkendra.com
Facebook ads are showing in HDR and looking brighter than normal posts. Screenshot one and it looks normal — that's the tell. We explain the cause and every way to disable it on Android and iPhone: www.cyberkendra.com/2026/09/face... #facebook #facebookads #meta #MetaPlatforms
cPanel Patches CVE-2026-65643 Root Code Execution Flaw www.cyberkendra.com/2026/08/cpan... #security #cpanel #update #infosec #webhosting
cPanel Patches CVE-2026-65643 Root Code Execution Flaw
cPanel patched CVE-2026-65643, a domain parking flaw letting any account holder write files and run code as root. Patched builds inside.
cyberkendra.com
Next.js Patches Two Critical RCE Flaws in 15.5.24, 16.3.3 www.cyberkendra.com/2026/08/next... #security #nextjs #Vercel
Next.js Patches Two Critical RCE Flaws in 15.5.24, 16.3.3
Next.js patches CVE-2026-75604 and a critical AVIF libheif RCE in 15.5.24 and 16.3.3. Windows hosts have no workaround.
cyberkendra.com
Log4j Deserialization Bypass Is Real but Not Log4Shell www.cyberkendra.com/2026/08/log4... #infosec #apache #log4j
Log4j Deserialization Bypass Is Real but Not Log4Shell
cyberkendra.com
BGMI Lite Pre-Registration Starts August 25 www.cyberkendra.com/2026/08/bgmi... #bgmi #bgmilite #gaming
🔴 GitHub is DOWN Major Outage on Actions, API Requests, Issues, Pull Requests and Copilot. ~20% of web and API requests, 50% of raw file and archive downloads are failing SSO login (SAML/OIDC) affected Git www.cyberkendra.com/2026/08/gith... #Github #devops #developer #copilot #internet
🔴 Apple sent mercenary spyware threat notifications to users in 110 countries, and the alert now appears on the iPhone Lock Screen. Read Details- www.cyberkendra.com/2026/08/appl... #Apple #iphone #lockdown #Mercenary #spyware #security
Trezor Says ShipMonk Breach Exposed 13,689 Customers www.cyberkendra.com/2026/08/trez... #Trezor #Crypto #cryptography #hacked #databreach
Trezor Says ShipMonk Breach Exposed 13,689 Customers
cyberkendra.com
Namecheap Outage Hits Hosting, DNS and Private Email www.cyberkendra.com/2026/08/name... #namecheap #dns #email
Cloudflare Wallets. They will allow you to store stablecoins, purchase services, and receive funds across the web. Read Details- www.cyberkendra.com/2026/08/clou... #cloudflare #AI
Cloudflare Gives AI Agents a Wallet and a Spending Cap
Cloudflare Wallets let AI agents pay for APIs with stablecoins, while spending caps, allow lists and cloudflare.pay handles keep them in check.
cyberkendra.com
The internal code stolen from GitHub in May is reportedly being offered again for $65,000, negotiable — this time with samples attached. Read it - www.cyberkendra.com/2026/08/gith... #github #hack
GitHub Source Code Allegedly Up for Sale Again
GitHub's stolen internal code is allegedly back on sale for $65,000. What the samples show, and what developers should do now.
cyberkendra.com
KindaRails2Shell - Critical Rails Flaw Leaks Secrets — Patching Isn't Enough www.cyberkendra.com/2026/07/kind... #rails #security #vulnerability #kindarail2shell
KindaRails2Shell - Critical Rails Flaw Leaks Secrets — Patching Isn't Enough
Critical Rails Active Storage bug CVE-2026-66066 lets unauthenticated attackers read server secrets. Upgrading alone won't close the door.
cyberkendra.com
🚨 Hugging Face Breached by Autonomous AI Agent Swarm An AI agent system — no human operator — compromised Hugging Face's production infrastructure over a weekend: Action: Rotate your HF access tokens + review recent account activity. Read more: www.cyberkendra.com/2026/07/hugg... #hacked #ai
🔴 WordPress pre-auth RCE — patch now WordPress force-pushed updates on July 17 to close wp2shell — a pre-authentication RCE in core. No login, no plugins, stock install. An anonymous HTTP request reaches code execution. www.cyberkendra.com/2026/07/wp2s... #wp2shell #wordpress
Telegram's iconic t.me short links went dark across the entire internet today. WHOIS records show the domain was hit with a "serverHold" — a status only the .me registry itself can apply. www.cyberkendra.com/2026/07/tele... #Telegram #DNS #TechNews #CyberSecurity
🚨 Linux Kernel Alert A 19-year-old bug (CVE-2026-43456) in Linux's let attackers get full root access in under 1 second, Full Details 👇 www.cyberkendra.com/2026/07/19-y... #cybersecurity #linux #bugbounty #security #hack