Jellyfin 12.0 Released With Security Fixes for Unauthorized File Access and XSS Flaws
Jellyfin has released version 12.0, a significant update to its open-source media server.
20 articles
Jellyfin has released version 12.0, a significant update to its open-source media server.
Dell has released security updates for the Secure Connect Gateway (SCG) Application and Appliance after discovering three critical vulnerabilities. These fla...
Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack. [.
Google warned that the rapid integration of AI-assisted coding tools has significantly expanded software supply chain risks
A municipal utility in Bavaria is recovering from a cyberattack that encrypted its internal IT systems but did not affect water and electricity services.
Microsoft warned customers last week that they may experience application crashes on some Windows Server 2025 due to recent memory management changes. [.
Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test...
In the last six months, Chainguard doubled its output from 500 million to more than 1 billion container build manifests. We also surpassed 3,000 unique conta...
Anthropic’s Claude Mythos Preview has demonstrated the ability to complete an end-to-end enterprise intrusion simulation, progressing from initial access thr...
Roughly 67,000 more customers of SatoshiLabs, the maker of hardware crypto-wallet Trezor, are at heightened risk of phishing attacks after their names, email...
A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators gro...
IT help-desk vishing calls, stolen session tokens, and sign-ins routed through residential proxies are behind a wave of data theft and extortion against Micr...
WhatsApp is developing a guest-call feature that would let people without a WhatsApp account join encrypted calls through a web link. This capability would e...
Dubbed MikroTrick, the bugs allow attackers to bypass authentication, overwrite configuration files, and take over devices. The post MikroTik Patches Critica...
THost9 hides its payload and uses ADB to spread across exposed Android devices and containers
An exposed Vietnam-linked APIS database contained 220.8 million passenger and crew records, including passport and flight data.
Hackers stole the information of students, teachers, staff, and parents/guardians from a self-hosted Metabase instance. The post Mathspace Data Breach Expose...
Administrators are advised to check their deployments for newly created user accounts they don’t recognize. The post N-able Patches Critical Zero-Day in N-ce...
ASUS has released a security update for the Control Center Express Agent to address CVE-2026-19397, a high-severity vulnerability related to missing authenti...
Best value overall: Microsoft Defender for Endpoint — if you hold Microsoft 365 E5, you already own competitive enterprise endpoint protection and the margin...