Cyber Security
Google has revealed an internal AI security agent that found more than 500 verified cross-site scripting, or XSS, flaws across its own web applications. The system, called PageBreak, searches for weaknesses that could let an attacker run unwanted code in a visitor’s...
Cyber Security
Vercel has confirmed a KVM zero-day vulnerability after security researcher Paulos Yibelo reported a full virtual machine escape that, he says, allows code inside a guest to gain root access on the host. The discovery came through the Vercel Sandbox bug bounty...
Cyber Security
GitLab has released urgent security updates for a critical AI Gateway vulnerability that could allow authenticated attackers to execute commands remotely. Tracked as CVE-2026-90970, the flaw carries a CVSS score of 9.9 and affects self-hosted deployments used to...
Cyber Security
Kiteworks has released a major security update that addresses 126 vulnerabilities across its secure data transfer platform and associated applications. The update includes fixes for critical account takeover flaws, high-severity code execution bugs, security bypass...
Cyber Security
A critical vulnerability in MikroTik RouterOS could allow unauthenticated remote attackers to execute arbitrary code with root-level privileges or trigger a denial-of-service condition. The flaw, tracked as CVE-2026-84411, affects MikroTik RouterOS versions before...