critical

13 stories and discussions about critical, aggregated from every source we track.

1.
626 points•pieterr•7 days ago•379 comments•
3.

The Domain Name System is one of the most invisible technologies that powers almost every online...

5 points•scofieldidehen•10 days ago•0 comments
4.
4 points•kamaraju•8 days ago•0 comments•
5.

There is growing concern that AI can blunt memory and reasoning. But science shows ways to keep the brain sharp.

3 points•digital55•6 days ago•0 comments•
6.

Wiz launches Scan for Good, using AI to help critical infrastructure, public services, and nonprofits find and remediate critical internet exposure.

2 points•galnagli•6 days ago•0 comments•
7.

The September 22, 2026 out-of-band security update for Next.js is now available

2 points•joshcsimmons•8 days ago•1 comment•
8.

Google's security team developed a method to replace legacy C code in the giflib image-processing library with Rust, targeting inherent memory vulnerabilities. They utilised an automated migration process, ensuring…

1 points•ndesaulniers•2 days ago•0 comments•
9.

Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed.

1 points•duck•7 days ago•0 comments•
10.
1 points•pelcg•7 days ago•0 comments•
11.
1 points•flyingfisch•over 10 years ago•0 comments
13.

Hackers have been exploiting a critical vulnerability in the Zimbra Collaboration Suite in an attempt to obtain email backups and authentication credentials of vulnerable organzations, Microsoft has warned . The vulnerability, tracked as CVE-2026-73570, lets attackers remotely issue operating system commands without authentication. Zimbra maintainer Synacor issued a patch on July 20, but didn’t disclose the vulnerability for more than three weeks after that. The security-focused Shadowserver Foundation said last week that its scans found that 274 separate instances of the Zimbra Collaboration Suite had been compromised. The number of servers running the software has fluctuated from 19,000 in the week following the patch to about 12,000 in the weeks following that. Currently, Shadowserver is tracking about 10,000 instances. Look, ma, no authorization From July 28 to August 7, Microsoft said Wednesday, the company detected two distinct scanning tools probing the Internet for vulnerable endpoints. The attackers first validated their exploit worked by sending HTTP, requests and DNS, ICMP, and out-of-band identity checks to domains hosted on public services. The probes allowed the attackers to confirm the exploit successfully executed commands on vulnerable servers without actually compromising them. Eventually, the attackers began using their command injection capability to install malicious payloads. Microsoft wrote: Read full article Comments

0 points•Dan Goodin•about 5 hours ago•0 comments

Related topics