MariaDB Patches CVSS 10.0 Remote Code Execution Vulnerability in Galera Cluster Feature

CVE-2026-49261 scores CVSS 10.0 and allows unauthenticated RCE in MariaDB Galera Cluster deployments. Standalone installations are not affected. Patches shipped May 27.

HTTP/2 Bomb: One Connection Crashes Web Servers. nginx Is Patched, Apache Is Not.

Single-connection HTTP/2 attack crashes web servers. nginx is patched today; Apache's fix has not reached distribution package managers.

A Database Allegedly From Home.pl Is Being Advertised on a Cybercrime Forum.

A dataset allegedly from Home.pl, Poland's largest hosting provider, is being advertised on a cybercrime forum. We analyze the schema and what it means for 300,000+ customers.

The Exploit Record: How Government Networks Keep Getting Breached

A cPanel zero-day hit Guam. CISA got breached through Ivanti. Salt Typhoon accessed US wiretap systems. The case file of government breaches.

CVE-2026-48172: LiteSpeed cPanel Plugin Root Privilege Escalation, CVSS 10.0, Actively Exploited

LiteSpeed cPanel Plugin CVE-2026-48172 (CVSS 10.0) lets any cPanel user execute scripts as root. Actively exploited. Patch to 2.4.7 now.

FunnelKit Plugin Flaw Actively Exploited to Skim Credit Cards From WooCommerce Checkout Pages

A FunnelKit vulnerability is being actively exploited to steal card data from WooCommerce checkouts. Every customer who paid on a compromised store is affected. Patch to 3.15.0.3 now.

A Ransomware Group’s Backend Was Leaked Because Their Hosting Provider Got Hacked First.

4VPS was breached on May 2. Two days later, The Gentlemen ransomware group's backend was leaked, exposing victim lists, ransom negotiations, and attack tooling

Skynethosting Took Its Entire cPanel Fleet Offline on May 1. Two Weeks Later, Some Are Still Down.

Skynethosting took its entire cPanel fleet offline on May 1 in response to CVE-2026-41940, and as of May 14 some customer servers had been down for nearly two weeks, with one reseller publicly reporting a 30 percent client loss during the outage.

Fragnesia: A New Linux Kernel Privilege Escalation That Emerged From Prior Kernel Patches

William Bowling of V12 Security disclosed Fragnesia on May 13, 2026, a Linux kernel privilege escalation that allows an unprivileged local attacker to reach root by corrupting the kernel page cache through the XFRM ESP-in-TCP subsystem.

Nginx Just Patched old Rewrite Module Flaw. RCE Was Possible With a Single HTTP Request.

A flaw sitting in nginx since 2008 was patched on May 13, 2026. CVSS 9.2, unauthenticated, and present in the default rewrite module.