Dell’s Container Storage Modules (CSM) were found to contain multiple critical vulnerabilities that can allow unauthenticated remote attackers to gain full administrative control of affected storage environments. The most severe issues — two CVSS 10.0 flaws — permit attackers to bypass authentication and escalate to administrator privileges, while other high-severity flaws enable privilege escalation inside Kubernetes clusters or token forgery.
Latest Articles

Paramount and Warner Become Skydance: What the $111B Merger Means for Media
Paramount has completed its $111 billion merger with Warner Bros. Discovery, forming a new media giant called Skydance. The merger — finalized after a last-ditch legal effort to block the deal was denied — combines two of Hollywood’s largest studios and their streaming platforms, Paramount+ and HBO Max, along with broadcast and cable assets such as CBS, CNN, CBS Sports and TNT Sports. The consolidation marks one of the biggest restructurings in the entertainment landscape and raises questions about competition…
Continue readingCritical GitLab AI Gateway Flaw: What Administrators Need to Do Now
GitLab has pushed an urgent set of security updates after disclosing a critical vulnerability in its AI Gateway that could allow authenticated users to run arbitrary commands on the gateway. Tracked as CVE-2026-90970 and rated CVSS 9.9, the flaw affects self-hosted AI Gateway deployments that support GitLab Duo AI features. While GitLab’s hosted gateways have already been patched, organizations running
Citrix NetScaler Reboots After Emergency 0-Day Patch: What Teams Need to Know
Citrix released emergency builds to address two actively exploited zero-day vulnerabilities in NetScaler appliances, but some organizations report that the patched appliances are repeatedly rebooting. What began as a rapid mitigation effort to stop remote command execution and DTLS-related attacks has morphed into an availability problem for some deployments—raising the difficult question defenders must balance: is this an operational outage
Debian Patches 1,313 Kernel Flaws: What Administrators Need to Know
Debian has just released a major kernel security update that aggregates fixes for 1,313 CVE entries, a headline figure that has drawn attention across the Linux community. The update — published as DSA-6528-1 and delivered for the Trixie stable release as Linux source package 6.12.111-1 — addresses a range of vulnerabilities that could, in different contexts, lead to privilege escalation,
Antino: A Stealthy Backdoor That Hides in Outlook and OneDrive
A new espionage campaign tracked by Cisco Talos has exposed a sophisticated Windows backdoor, nicknamed Antino, that uses Microsoft 365 services as its covert communications channel. Targeting government and policy organizations across Asia — including Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar — the activity centers on highly tailored spear‑phishing lures and a multi-stage infection chain that culminates
Apple tightens Full Disk Access controls to block potential AI agent abuse
When an AI assistant began referencing private iMessage threads without a clear explanation of how it accessed them, it set off a rapid chain of scrutiny and vendor responses. Apple has moved to tighten macOS’s Full Disk Access (FDA) permissions after concerns that some third-party apps could misuse that powerful system-level privilege to read private files, messages, and browsing histories.





