DirtyClone (CVE-2026-43503): Dropped Packet-Clone Flag Gives Local Users Root
DirtyClone (CVE-2026-43503) is a CVSS 8.8 Linux kernel LPE. __pskb_copy_fclone() drops the SKBFL_SHARED_FRAG flag during packet cloning, letting an attacker…
Technical writing on Claude AI MCP connectors, PHP development, WooCommerce, storage billing systems, reverse engineering, and cybersecurity. 148 articles and counting.
DirtyClone (CVE-2026-43503) is a CVSS 8.8 Linux kernel LPE. __pskb_copy_fclone() drops the SKBFL_SHARED_FRAG flag during packet cloning, letting an attacker…
Google's June 2026 spam update finished rolling out on June 26 after two days — the second spam update of 2026. If your traffic dropped since June 24, this is…
CVE-2026-41940 is a CVSS 9.8 authentication bypass in cPanel & WHM exploited as a zero-day for 65 days before patching. 44,000+ IPs confirmed compromised,…
A critical use-after-free in PHP's SOAP extension (CVE-2026-6722) allows unauthenticated RCE via crafted apache:Map SOAP requests. Affects PHP 8.1–8.3. Patch…
Attackers breached ShapedPlugin's distribution pipeline and injected credential-stealing backdoor code into three Pro plugin updates (May 21–June 10, 2026).…
CVE-2026-3300 in Everest Forms Pro (≤1.9.12) lets any unauthenticated visitor execute arbitrary PHP via the Complex Calculation eval() feature. 29,300+ attacks…
Google stopped showing FAQ rich results on May 7, 2026, and is removing the Search Console report, Rich Results Test support, and API access through August.…
Google published its first official guide to optimizing for generative AI features in Search — and the message is that AI search is still just SEO. It also…
Google's May 2026 core update finished rolling out June 2 after about 12 days — the second of 2026 and heavier than March. Here's an honest recovery plan: how…
A Google patent — "Data extraction using LLMs" — describes AI building a holistic profile of your business from your website, reviews, directories, and public…
A single attacker on a home connection can exhaust 32 GB of server RAM in under 20 seconds by chaining HPACK compression amplification with HTTP/2 flow-control…
The Gravity SMTP WordPress plugin (≤2.1.4) has been hit with 17 million+ attack attempts — including 4 million in a single day. An unauthenticated info…