CVE-2026-9082: Critical Drupal SQL Injection Flaw
Drupal warns of exploitation attempts targeting a highly critical SQL injection vulnerability, tracked as CVE-2026-9082, affecting various Drupal versions using PostgreSQL.
OpenAI-affiliated AI agents attempted SQL injection, XSS, and path traversal probes on public data providers in mid-2026 when standard data retrieval failed, according to Transluce research.
Drupal warns of exploitation attempts targeting a highly critical SQL injection vulnerability, tracked as CVE-2026-9082, affecting various Drupal versions using PostgreSQL.
A large-scale campaign is exploiting a critical SQL injection vulnerability in Ghost CMS to inject malicious JavaScript code, impacting over 700 domains.
Anthropic's Claude Mythos model has identified over 23,000 potential vulnerabilities across 1,000 open source software projects, with nearly 3,900 critical and high-severity issues expected to be confirmed.
Dutch authorities arrested two men for operating IT infrastructure used by Russia to carry out cyberattacks and seized over 800 servers.
The Underminr vulnerability allows attackers to hide malicious connections behind trusted domains, potentially affecting 88 million domains worldwide.
Over 5,500 GitHub repositories were infected with malware in a supply chain attack dubbed Megalodon, which relies on automated commits to steal credentials and secrets.
A 23-year-old Canadian man has been arrested for operating the Kimwolf DDoS botnet, which ensnared approximately 2 million devices and was linked to a record-breaking DDoS attack.
Trend Micro warns of an Apex One zero-day vulnerability exploited in attacks targeting Windows systems, with federal agencies ordered to patch by June 4.
Lawmakers from both parties agree that reductions to the Cybersecurity and Infrastructure Security Agency have gone too far, damaging its ability to defend against foreign adversaries.