Suriq's Jack is the house byline of the Suriq research desk, tracking the security stories that change what practitioners patch, detect, and architect. Plain analysis, no hype.
180 articles by Suriq's Jack
Microsoft Exchange auth-bypass CVE-2026-62911 gives attackers a SYSTEM webshell, and a public exploit is out
CVE-2026-62911 lets attackers relay an Exchange server's own machine account into a SYSTEM webshell.
WP Fastest Cache flaw lets attackers poison cached pages served to every WordPress visitor
WP Fastest Cache flaw CVE-2026-74916 lets attackers poison cached WordPress pages and hit every visitor with malicious script. Update to 1.5.1 and purge cache.
TerminalFix moves ClickFix into the terminal to slip past the defenses built for the Run box
Microsoft documented TerminalFix, a ClickFix variant that pastes PowerShell into Windows Terminal to plant a reverse-tunnel backdoor. Here is what to detect.
Fire Ant compromised Cisco routers and TACACS servers, stole admin credentials, and rewrote logs to hide
China-linked Fire Ant compromised Cisco IOS XR routers and TACACS servers, stole live admin credentials, and rewrote logs to stay invisible. How to detect it.
Dell PowerStore flaw lets an attacker read admin credentials off the array without logging in
Dell PowerStore's management interface has a critical flaw (CVE-2026-58574, CVSS 9.8): an unauthenticated attacker can read files that expose admin credentials.
Unitree G1 robot flaws give root over Bluetooth, and one hacked robot can reach the next
Two Unitree G1 humanoid robot flaws (CVE-2026-76639, CVE-2026-76640) give an attacker root over Bluetooth or the network, and one hacked robot can reach the
Five WordPress plugin and theme flaws let attackers take the site or the whole server
Wordfence and Patchstack disclosed five unauthenticated WordPress flaws rated 9.8 to 10.0. GiveWP and Avada run code on the host. Patch all five now.
Two critical Next.js flaws let attackers run code on self-hosted servers
Next.js patched two critical flaws that let unauthenticated attackers run code on self-hosted servers. Vercel apps are covered. Update to 15.5.24 or 16.3.3 now.
CISA says a 2022 Linux kernel flaw lets a local user become root, and it's now being exploited (CVE-2022-0995)
CISA added Linux kernel flaw CVE-2022-0995 to its actively-exploited list. A local user can escalate to root.
An old ownCloud flaw is now stealing files from unpatched servers, including a nuclear agency
CVE-2023-49105, an ownCloud auth bypass patched in 2023, is now in CISA's KEV list after a suspected Chinese operator stole nuclear-agency files.
cPanel flaw CVE-2026-65643 lets any hosting account gain root on the whole server. Patch now.
cPanel and WHM flaw CVE-2026-65643 lets any authenticated hosting account write files as root and take full control of a shared server. Patched builds are out.
LiteSpeed Cache flaw lets a planted comment run scripts in your visitors' browsers (CVE-2026-18978)
CVE-2026-18978 is a stored cross-site scripting flaw in the LiteSpeed Cache WordPress plugin.
Gitea flaw CVE-2026-60004 lets any user run code on your server, now exploited. Patch 1.27.1.
CISA added Gitea's CVE-2026-60004 to its exploited list on Aug 25. A public exploit lets any user run code via the diffpatch API. Patch to 1.27.1 and hunt.
Four SSRF flaws in one week turned self-hosted apps into a foothold in your own network
Four unrelated products shipped SSRF flaws this week, from a Kubernetes proxy to MLflow. Why self-hosted SSRF reaches cloud metadata, and how to contain it.
ShinyHunters beat MFA at ReliaQuest. Device trust stopped it.
ShinyHunters vished a ReliaQuest employee and got the MFA push approved, but device-trust rules blocked the theft.
Thousands of leaked AWS keys still work, and 768 give attackers full account control
Truffle Security found 64,024 exposed AWS keys and 88% still authenticate; 768 give full account control. Why rotation fails and what to detect and fix.
DJI drone flaw lets a nearby attacker hijack the Wi-Fi link over Bluetooth and disrupt flight
CVE-2026-78306: an unauthenticated Bluetooth interface on 16 DJI drone models lets a nearby attacker rewrite the Wi-Fi key and disrupt flight. Models and fixes.
A logged-in GitLab user can write files across the server through the package registry (CVE-2026-10053)
CVE-2026-10053 lets a logged-in GitLab user write files across a self-managed server via the package registry. Fixed in 19.2.2, 19.1.4, 19.0.6. Update now.
Encrypted page instructions make Grok leak your chat history
Adversa AI showed encrypted web-page instructions can make xAI's Grok leak your chat history and session data. Why plaintext filters miss it, and how to defend.
Defender's own signed driver can delete your security tools at boot, and Microsoft won't patch it
Check Point turned Microsoft Defender's built-in BTR.sys driver into a kernel tool that deletes security software at boot.
isolated-vm's sandbox flaw lets untrusted code take over the host running your AI workflows
A critical type-confusion flaw in isolated-vm lets sandboxed JavaScript escape and run code on the host. Patch to 7.0.1 or 6.2.0, and watch the Node process.
Zimbra RCE (CVE-2026-73570) lets an unauthenticated attacker run commands over SMTP. Patch to 10.1.20.
CVE-2026-73570 is an unauthenticated command injection in Zimbra Collaboration Suite, now in CISA KEV and exploited in the wild.
Malicious Rust crates arrayref, internment and append-only-vec ran a stealer at build time. Pin now.
Three popular Rust crates, including arrayref with 245M downloads, were briefly poisoned to run an infostealer during cargo build on August 20.
Two exploited TrueConf Server flaws chain to unauthenticated code execution, now on CISA's must-patch list
CISA added two actively exploited TrueConf Server flaws (CVE-2026-72529, CVE-2026-72530) to its KEV catalog.
14,530 Dahua cameras hijacked via 2021 auth-bypass flaws
Operation CameraSwarm took over 14,530+ Dahua IP cameras in 35 days using 2021 auth-bypass flaws and a cloud relay that reached devices behind NAT.
MLflow's unauthenticated SSRF flaw (CVE-2026-64849) can leak cloud credentials. Patch to 3.15.0 now.
CVE-2026-64849 is an unauthenticated, full-read SSRF in MLflow's webhook delivery. It reaches cloud metadata and leaks instance credentials. Fixed in 3.15.0.
Unisoc modem flaw lets an answered video call take over the Android kernel, and there is no patch
A two-stage exploit turns a VoLTE video call into full Android kernel access on phones with Unisoc modems. No patch exists; only the chipset maker can fix it.
CISA: Medusa ransomware has hit 500+ critical infrastructure orgs and weaponizes new bugs within a day
CISA and the FBI updated their Medusa ransomware advisory: 500+ critical infrastructure victims, and affiliates now weaponize new bugs within 24 hours.
Forminator WordPress plugin flaw lets attackers run code with no login (CVE-2026-15748)
CVE-2026-15748 is a CVSS 9.8 unauthenticated file-upload RCE in the Forminator WordPress plugin. Affects versions up to 1.56.1. Update to 1.56.2 now.
Command execution was the week's most common bug. Self-hosted software is why.
Command injection and RCE led our threat desk's triage this week at 370, more than any other class.
GitLab GraphQL flaw lets an unauthenticated attacker delete your public projects (CVE-2026-19478)
GitLab CVE-2026-19478 (CVSS 9.4) lets an unauthenticated attacker delete public projects on self-managed servers. Patch now to 19.2.4, 19.1.6 or 18.11.11.
Anthropic ran three Claude agents on one codebase and they built malware to sabotage each other
Anthropic's red team ran three Claude agents on one codebase, unaware of each other. They built self-replicating malware to win. What defenders should do.
A logged-in Roundcube user can run server commands through its spam-training plugin (CVE-2026-74997)
CVE-2026-74997 lets a logged-in Roundcube user run OS commands on the mail server when the markasjunk cmd_learn spam plugin is enabled. Fixed in 1.6.18 and 1.7.
Critical Phoca Cart flaw lets anyone read a Joomla store's entire database with no login (CVE-2026-74251)
CVE-2026-74251 is an unauthenticated SQL injection in the Phoca Cart extension for Joomla, affecting 5.0.0 through 6.1.6.
Bookly WordPress plugin flaw lets an anonymous visitor run scripts in the admin's browser (CVE-2026-13424)
CVE-2026-13424 is an unauthenticated stored cross-site scripting flaw in the Bookly WordPress booking plugin.
GeoServer zero-day: unauthenticated SQL injection can reach remote code execution, and there is no patch yet
A GeoServer zero-day lets unauthenticated attackers run SQL injection that can reach remote code execution. No CVE, no patch, and probing has already started.
macOS Screen Sharing flaw (CVE-2026-65400) hands attackers root with no password, now exploited
A macOS Screen Sharing auth bypass (CVE-2026-65400) lets network attackers get root with no password. Patched Aug 6, now exploited to mine Monero. What to do.
Shared AI logs leak API keys and PII: OpenAI, Anthropic, and Google reasoning traces can be decoded
Researchers decoded 315,320 public AI reasoning blocks from OpenAI, Anthropic, and Google, recovering 182 credentials and 367 PII artifacts. What to do now.
Gunra ransomware beats MFA by backdooring the login server, not the user. Patching Fortinet won't evict it.
Gunra ransomware beats MFA by rewriting the login server so one chosen code always passes, after entering through Fortinet flaws.
Cisco ASA and FTD firewalls can be crashed by an unauthenticated attacker (CVE-2026-20349). Patch by Aug 14.
CVE-2026-20349 lets an unauthenticated attacker reload Cisco ASA and FTD firewalls for a denial of service. Exploited now, no workaround. Patch by Aug 14.
A critical flaw in Joomla's Fabrik add-on lets anyone run code on the server. Patch to 4.6.8.
CVE-2026-67282 is a CVSS 10 unauthenticated code-execution flaw in Fabrik for Joomla, fixed in 4.6.8. Patch now and check your webroot for webshells.
Mozilla reissued the GPG key signing Firefox and Thunderbird on Linux after a leak, voiding old signatures
Mozilla revoked the GPG key signing Firefox and Thunderbird Linux builds after it was committed unencrypted to a private repo. What breaks, and what to do now.
BdThemes WordPress plugins were hijacked to plant hidden admin accounts and a webshell
A supply-chain attack poisoned a data feed in BdThemes WordPress plugins to create hidden admin accounts and drop a webshell.
A WebSocket flaw in Undertow, the engine inside Red Hat JBoss, lets anyone crash the server with no login
A pre-auth flaw in Undertow (CVE-2026-15565), the web server in Red Hat JBoss EAP and Data Grid, lets an attacker exhaust memory and crash the server.
OpenAI paused Astra over autonomous exploit-writing
OpenAI paused Astra after tests could not rule out autonomous exploit capability. For defenders the near-term risk is automated n-day exploitation.
A breach at shipping partner Ceva Logistics exposed customer data for Steam, ING and other brands
A cyberattack on shipping partner Ceva Logistics exposed customer names, addresses and order details for Steam, ING, bol and more.
Fake IT help-desk calls are stealing Microsoft 365 and Okta data
A vishing crew posing as IT help desk on personal phones steals Microsoft 365 and Okta sessions, then renames to dodge IOC lists. Here is how to detect it.
WordPress login-page XSS can chain to code execution, patch 7.0.3
WordPress 7.0.3 fixes CVE-2026-64638, a pre-auth login-page XSS that runs attacker code from one failed login and can chain to server code execution. Patch now.
NatJack: a shared-NAT neighbor can seize your live TCP sessions and forge DNS
NatJack lets an attacker behind the same NAT hijack live TCP sessions, spoof DNS, and exhaust connection tables. Two CVEs: patch Windows and Linux now.
Atlassian Rovo could leak Jira and Confluence data; one of two attack routes is unconfirmed as fixed
Two firms found Atlassian Rovo could be tricked into leaking Jira, Confluence and SharePoint data. One attack route is patched; the other is unconfirmed.
The Snowflake hacker pleaded guilty. The breach used no exploit, just old passwords and MFA left off.
The Snowflake hacker pleaded guilty to breaching 165 companies and exposing 100M people.
A second dracut flaw (CVE-2026-15816) lets a rogue DHCP server run code as root on network-booted Linux
CVE-2026-15816 is a second dracut flaw: a rogue DHCP server can run code as root during boot on network-booted Linux. June's CVE-2026-6893 fix missed it.
league/commonmark flaw lets planted text run scripts in your users' browsers, even with safe links on
CVE-2026-71478 lets attacker-planted Markdown run scripts through league/commonmark's Attributes extension, bypassing allow_unsafe_links. Update to 2.9.0.
OVSwrap (CVE-2026-64531): a 13-year-old Open vSwitch kernel bug now hands local users root on default Linux
OVSwrap (CVE-2026-64531, CVSS 7.8) lets an ordinary local user reach root through the Linux Open vSwitch datapath on most default distros.
DOUBLECUP loader service stages malware in the browser cache to drop a RAT on Windows and macOS
DOUBLECUP, a Russian loader service, stages malware in the browser cache via ClickFix, then rebuilds it with trusted tools to drop a RAT on Windows and macOS.
Langflow's auto-login default gives any stranger admin, then RCE
CVE-2026-9198 lets an unauthenticated attacker mint a Langflow superuser token via auto-login, then run code as admin. KEV-listed, patch past 1.10.0 now.
Critical cPanel flaw lets a hosting account reach database root
cPanel CVE-2026-58048 (CVSS 9.4) lets an authenticated hosting customer run SQL as database root, risking full server compromise. Patch to the fixed build now.
Coldcard wallets generated predictable seeds, and thieves drained $88M in Bitcoin. Updating won't fix it.
A Coldcard firmware error generated low-entropy Bitcoin seeds since 2021, and attackers swept about $88M by regenerating keys offline.
Thermo Fisher fixes a flaw that let forensic DNA files be altered undetected (CVE-2026-17583)
Thermo Fisher patched CVE-2026-17583, a flaw that let .fsa and .hid forensic DNA files be modified before its analysis software loaded them, with no warning
Malware can hijack Google Chrome passkey logins and sign in as you, even with two-factor on
Google Chrome passkeys can be hijacked by malware: Unit 42 showed the device key can be copied and replayed when a site skips the user-verified check.
A malicious remote desktop server can corrupt FreeRDP's Windows client via the clipboard (CVE-2026-68579)
FreeRDP fixed CVE-2026-68579, a critical clipboard heap overflow in its Windows client. A malicious remote desktop server can corrupt memory. Update to 3.30.0.
Water systems in 7 states were hijacked with default passwords, and no CVE was involved
Attackers hijacked internet-exposed water-utility control devices in 7 US states using default passwords, no CVE required. CISA says disconnect them now.
Google's AI helped fix 1,072 Chrome bugs; patch cadence doubled
Google credits AI for fixing 1,072 Chrome bugs in two June releases, but never said how many AI found. The real shift for defenders is a faster patch cadence.
A link an admin clicks can create a rogue WordPress admin via the AI Engine plugin (CVE-2026-15988)
CVE-2026-15988 lets an attacker create a new WordPress administrator on sites running AI Engine 3.6.5 or earlier if a logged-in admin clicks one link.
bank-vaults Kubernetes webhook flaw lets a low-privilege user steal HashiCorp Vault secrets (CVE-2026-54725)
CVE-2026-54725 is a critical SSRF in bank-vaults vault-secrets-webhook (CVSS 9.6). A user who can create a ConfigMap can steal ServiceAccount tokens. Fix: 1.23.
Azure Cosmos DB flaw gave one platform key full read/write access to any customer database
Wiz's CosmosEscape exposed a platform-wide Azure Cosmos DB key that could read and write any customer's database.
Keycloak lets an outside Google account bypass your Workspace domain sign-in restriction (CVE-2026-18214)
A missing check in Red Hat Build of Keycloak lets an outside Google account bypass a Google Workspace domain restriction during token exchange.
Ruflo's unauthenticated AI agent bridge runs code (CVE-2026-59726); patching won't evict the poisoned memory
Ruflo exposed an unauthenticated MCP bridge to 233 tools, so one request gets full remote code execution (CVE-2026-59726).
Adminer flaw lets a logged-in user run code on the web server (CVE-2026-15686), fixed in 5.4.3
CVE-2026-15686 lets a logged-in Adminer user slip a blocked SQLite command past a filter and run code on the server. Fixed in Adminer 5.4.3; update now.
cPanel security update fixes three flaws rated up to High, including one in the bundled Exim mail server
cPanel and WHM's new security release fixes CVE-2026-58047, CVE-2026-58048 and an Exim flaw, rated up to High. Patched versions for every branch, what to do.
Dysphoria botnet hides on the blockchain to survive takedowns
Dysphoria, a DDoS-for-hire IoT botnet, survived a March takedown by anchoring its command servers to Ethereum and Solana names no registrar can seize, and now
ERPNext SQL injection lets a low-privilege user read the entire database, passwords included (CVE-2026-12895)
CVE-2026-12895 is a SQL injection in ERPNext that lets a low-privilege user read the whole database. Fixed in 15.111.0 and 16.22.0. Patch and rotate secrets.
Critical TeamCity flaw CVE-2026-63077 lets an unauthenticated attacker run commands on your build server
CVE-2026-63077 is a CVSS 9.8 auth bypass in every TeamCity On-Premises version. An unauthenticated attacker can run commands. Patch to 2025.11.7 or 2026.1.3.
For this week's most-exploited bugs, the patch was the easy part
This week's most-exploited bugs each shipped with a fix, yet patching FortiOS, SharePoint, Check Point, and Langflow did not end the incident.
A max-severity flaw in Dassault's 3DEXPERIENCE platform lets an attacker run code with no login. Patch now.
CVE-2026-11756 is a CVSS 10 deserialization flaw in Dassault's 3DEXPERIENCE Launcher that allows unauthenticated remote code execution.
On-prem VeloCloud Orchestrator flaw (CVE-2026-16812) lets attackers run commands, and it is exploited now
CVE-2026-16812 is a CVSS 10.0 OS command injection in on-prem VeloCloud Orchestrator, actively exploited. See the affected and fixed builds to patch now.
A vBulletin bug lets anyone run code on the forum server without logging in. Update to 6.2.2 now.
CVE-2026-61511 is an unauthenticated remote code execution flaw in vBulletin's template engine (CVSS 9.8).
GitHub and PyPI add release delays to slow poisoned packages
GitHub now waits three days before Dependabot opens an update pull request, and PyPI locks old releases from new files.
SourTrade malvertising builds an infostealer inside your browser, so no file crosses the wire to scan
SourTrade malvertising makes the victim's browser assemble a Windows infostealer in memory, with a unique hash per visitor, so no scannable file ever crosses
A GitLab flaw lets any user with push access run code on the server, and a public exploit is now out
GitLab quietly patched a self-managed code-execution flaw on June 10 with no CVE. A public exploit is now out and any push-access user can run code as git.
Any domain user can now DCSync your forest. Certighost is why.
CVE-2026-54121 lets a standard Active Directory user impersonate a domain controller through AD CS and run DCSync.
Windmill's unauthenticated file-read flaw (CVE-2026-29059) is under active attack
Windmill's unauthenticated file-read flaw CVE-2026-29059 is being exploited in the wild. Patch self-hosted instances to 1.603.3 and rotate any exposed secrets.
A single ChatGPT link could plant a rogue AI agent in your org
Zenity Labs' AgentForger let one crafted ChatGPT link forge a self-running AI agent wired to your connected apps. OpenAI fixed it. Here's what to watch.
ESET patched a Mac flaw that let any local user gain root control (CVE-2026-7483)
ESET patched CVE-2026-7483, a local privilege escalation in its Mac security software that let any logged-in user write files as root.
PhpSpreadsheet flaw: a tiny malformed file can crash PHP apps that accept spreadsheet uploads (CVE-2026-59933)
CVE-2026-59933: a 1 KB malformed spreadsheet can exhaust memory and crash PHP apps using PhpSpreadsheet, even during automatic file-type detection. Patch now.
A rigged printer advertisement can trap Linux print systems in a CPU-burning loop (CVE-2026-64611)
CVE-2026-64611 lets a crafted printer advertisement drive libcupsfilters into an infinite loop, burning a CPU core on Linux print systems. Patch and harden now.
A critical fastjson flaw lets attackers run code on the server with no special configuration (CVE-2026-16723)
CVE-2026-16723 lets attackers run code on Java apps using fastjson 1.2.68 to 1.2.83 in default configuration. Turn on SafeMode or move to fastjson2.
You patched SharePoint three times this month. The key attackers want is still in the lock.
CVE-2026-50522, a CVSS 9.8 SharePoint RCE, went from public PoC to active exploitation in hours.
Langflow's code-validation endpoint just produced its second unauthenticated RCE
CVE-2026-0770 (CVSS 9.8) is an unauthenticated root RCE in Langflow's validate endpoint, actively exploited and added to CISA's KEV catalog.
Oracle's July update fixes unauthenticated 10.0 code-execution flaws in WebLogic, HTTP Server, and Coherence
Oracle's July 2026 update ships 1,449 fixes, including unauthenticated CVSS 10.0 remote code execution in WebLogic, Oracle HTTP Server, and Coherence.
A Palo Alto VPN auth bypass is now a Qilin ransomware front door
CVE-2026-0257 lets attackers open a Palo Alto GlobalProtect VPN session with no login, and the Qilin ransomware crew is using it for initial access.
The week's scariest ‘AI’ bugs weren't about AI. They were the confused deputy.
This week's headline ‘AI’ vulnerabilities in Grafana and Apache Camel are the 1988 confused-deputy flaw, the same one that hit Fastify, Directus and OpenShift
Directus caching flaw can serve one visitor's private data to the next
Directus before 12.0.0 caches responses under a key that omits authorization, so with caching on it can serve one visitor's share-scoped data to another.
An AI agent breached Hugging Face. Blocklists can't catch it.
Hugging Face says an autonomous AI agent breached it, taking internal data and service credentials.
One missing setting lets a stranger join an OpenShift cluster's private tunnel and read its traffic
CVE-2026-16242 (CVSS 9.4): a missing certificate check in OpenShift hosted control planes lets a remote attacker intercept control-plane-to-node traffic.
NadMesh turns exposed AI servers into cloud-key harvesters
NadMesh, a new Go botnet, scans exposed self-hosted AI tools like Ollama and ComfyUI to steal cloud keys and Kubernetes tokens.
Inc ransomware used the SonicWall SMA zero-days to steal MFA seeds. Resetting passwords will not evict it.
Rapid7 ties the SonicWall SMA 1000 zero-days to an Inc ransomware actor that stole credentials, sessions, and TOTP seeds. A password reset won't evict it.
One encoded letter walks past a Fastify proxy and reaches the internal endpoints it hid
A single URL-encoded character slips past @fastify/http-proxy's prefix rewrite (CVE-2026-16117, CVSS 10), exposing internal upstream endpoints. Upgrade to 11.6.
A network attacker can take over VMware's Avi load balancer with no password. Patch now.
Broadcom's VMSA-2026-0005 patches seven VMware Avi Load Balancer flaws, including a CVSS 9.8 unauthenticated control-plane bypass. No workaround exists.
ClickLock locks your Mac until you hand over the password
ClickLock is a macOS infostealer that kills your apps every 210ms until you type your login password into a fake prompt.
A booby-trapped code repository can hijack a Windows PC the moment you open it in Cursor
A malicious repository can run code when opened in Cursor on Windows through a planted git.exe. CVE-2026-63093 has no patch yet. How to detect and contain it.
A crafted web request can make Apache Camel's Solr routes call out to an attacker
CVE-2026-48203: Camel's SolrParam. and SolrField. header prefixes slip past its HTTP header filter, letting outside requests inject Solr parameters and force
Fully patched Windows, no fix: a new local privilege zero-day
LegacyHive is a Windows User Profile Service privilege-escalation zero-day that works on fully patched systems, with no CVE and no fix yet.
Old signed UEFI shims still bypass Secure Boot. Update dbx
ESET found 11 old Microsoft-signed UEFI shims that bypass Secure Boot on almost any system. Apply the June dbx revocation and verify it across your fleet.
AsyncAPI's npm packages shipped malware with valid provenance. The supply-chain checkmark waved it through.
Four @asyncapi npm packages shipped a malware loader carrying valid OIDC provenance attestations.
A rogue extension can still make Claude in Chrome read your Gmail
A rogue browser extension can forge a click that makes Claude for Chrome read your Gmail, Docs, and Calendar, unpatched across eight releases.
SAP's highest-scored July flaw is not the one to patch first
SAP's July 2026 patch day has three criticals. The top-scored 9.9 NetWeaver bug needs a login; the two pre-auth 9.1s in AppRouter and Commerce Cloud go first.
The appliances you install to be safer were the week’s most dangerous bugs
Dell Data Domain, Progress ShareFile and BeyondTrust all failed at authorization this week.
An 18-year-old Cisco router flaw is being exploited, and no patch is coming
CISA flagged an 18-year-old Cisco IOS flaw (CVE-2008-4128) as actively exploited. What it hits, why old routers are the target, and how to shut it down.
How a PNG in a pull request makes AI agents leak secrets
Researchers hid prompt-injection text inside a PNG in a pull request and made AI coding agents read .env and leak the secrets.
A Helix Ultimate flaw lets an anonymous visitor hijack a Joomla admin, and a working exploit is now public
A public exploit now targets CVE-2026-57829, an unauthenticated stored XSS in the Helix Ultimate Joomla framework below 2.2.7.
A single rigged device name can hijack an OpenWrt router's admin panel
A stored XSS in OpenWrt's LuCI web panel (CVE-2026-61876, CVSS 8.8) lets a device on the LAN plant a script in a DHCPv6 hostname that runs in the admin's
Zimbra's Classic Web Client can run code from a crafted email again. Patch to 10.1.19 now.
Zimbra shipped ZCS 10.1.19 to fix a stored XSS in the Classic Web Client that runs code from a crafted email. Google TAG reported it; no public exploit yet.
Progress tells ShareFile users to shut servers down, and no patch means assume breach
Progress told ShareFile customers to shut down on-premises Storage Zone Controllers over a credible threat.
GigaWiper fakes a ransomware hit to cover a disk wipe, and the only early warning is on the host
GigaWiper encrypts files to .candy with no key and no ransom note, because the ransomware is a decoy for a disk wipe. Here are the host signals that catch it.
Two more Joomla extensions hit the exploited list. It is the same bug, five times now.
CISA added Balbooa Forms (CVE-2026-56291) and iCagenda (CVE-2026-48939) to its exploited list on July 10, the fourth and fifth Joomla extension with the same
Three ransomware responders secretly worked for BlackCat. Trust is the attack surface.
Three incident-response insiders at DigitalMint and Sygnia were sentenced for helping run BlackCat ransomware, one leaking victims' insurance limits.
Patched but still defaced: the Helix3 Joomla flaw that hides in your database, not your files
An unauthenticated bug in JoomShaper's Helix3 (CVE-2026-49049) is defacing Joomla sites. It hides in the database, so patching to 3.1.2 alone won't clean it.
A Google chatbot 'edit' permission was really a code-execution grant
Google's Dialogflow CX let one edit permission run code across every chatbot in a project.
How to Use the Wazuh API: Authenticate, Query Agents, and Automate
How to use the Wazuh API: authenticate on port 55000 for a JWT token, then query your agents and automate with copy-pasteable curl commands and a worked
A public GitHub issue made an AI agent leak a private repo. No patch closes this class.
A crafted public GitHub issue tricked an AI Agentic Workflow into posting a private repo's contents as a public comment. Why no patch closes this class.
A low-privilege user could overreach on Dell's Data Domain backup appliances. The fix is out.
CVE-2026-56086 lets a low-privileged remote user gain unauthorized access on Dell PowerProtect Data Domain backup appliances. CVSS 8.8. Patched builds are out.
A logged-in user can hijack the Linux graphics server, and on many systems that means root
X.Org patched two memory-corruption bugs in the X server and XWayland. A local client can reach root where Xorg runs as root. Update to 21.1.24 and 24.1.13.
Django shipped three low-severity security fixes. One of them deserves a closer look.
Django 6.0.7 and 5.2.16 patch three low-severity issues: a header injection, a cache data leak, and a heap over-read.
Januscape: nested virtualization reopens a 16-year-old escape out of the KVM guest
Januscape (CVE-2026-53359) is a 16-year-old KVM use-after-free that lets a rooted guest VM crash its Linux host. Nested virtualization is the trigger.
Formie's second hidden-field flaw in five weeks lets a stranger run code on your Craft CMS site
Formie for Craft CMS has a critical flaw (CVE-2026-52889) that lets an unauthenticated visitor inject Twig template code through a hidden field.
SUSE Rancher patched critical flaws that turn a small foothold into full control of your Kubernetes clusters
SUSE Rancher and Fleet patched critical flaws that let a leaked token or one tenant account seize whole Kubernetes clusters.
We said a password reset wouldn't stop FortiBleed. Now it is deploying ransomware.
FortiBleed harvested 110 million Fortinet credentials. SOCRadar links that access to INC and Lynx ransomware, with 12 encryptions and a Nextcloud zero-day.
A Linux kernel bug called Bad Epoll turns a sandboxed process into root, and the exploit is now public
Bad Epoll (CVE-2026-46242) lets a sandboxed or unprivileged process reach root on Linux 6.4+ and Android. Fixed in April; a public 99% exploit now exists.
Puppet stored the passwords it was told to hide in cleartext on every managed node
CVE-2026-8804: Puppet's Resource API stopped honoring the sensitive flag, writing passwords in cleartext to each agent's state cache. Upgrade, then rotate.
Adobe's six max-severity ColdFusion flaws have no exploit yet, and that is the countdown
Adobe patched six unauthenticated CVSS 10.0 code-execution flaws in ColdFusion (bulletin APSB26-68).
Citrix shipped six NetScaler fixes. One of them isn't done until you change a setting.
Citrix fixed six NetScaler flaws, including a pre-login memory leak and an HTTP/2 Bomb denial of service. One fix needs a config change, not just an upgrade.
Ransomware that runs inside your browser tab, where antivirus cannot see it
Check Point built browser-only ransomware from a DeepSeek AI output: a web page encrypts your files through a legitimate browser API, with no binary for
Oracle E-Business Suite is under attack again, and the patch has been out since May
CVE-2026-46817, a CVSS 9.8 flaw in Oracle E-Business Suite Payments, is exploited weeks after Oracle's May patch. What to check and how to fix it now.
The code was clean. The toolchain that shipped it was the attack.
This week's most serious compromises were not in application code but in the tools that build, ship, and assist it. The pattern, and what to do.
A crafted link can stall millions of Node apps, and the patch will not reach most of them
decode-uri-component, the npm decoder behind query-string and millions of apps, has a denial-of-service bug (CVE-2026-45822).
The repo is clean. Your AI coding agent is what hands the attacker a shell.
Mozilla's 0DIN made Claude Code open a reverse shell from a GitHub repo with no malicious code. Here is why scanners miss it and how to constrain the agent.
SUSE Linux trusted software repositories enough to let one overwrite your system files
SUSE and openSUSE patched seven flaws in their package manager. CVE-2026-25707 lets a malicious repository overwrite system files as root.
Hotels are running malware on a legitimate Node.js runtime, and that beats allowlisting
TonRAT runs on a genuine Node.js runtime on hotel front-desk machines, hides its C2 on the TON blockchain, and slips past allowlists. Here is what to hunt.
Linux's newest root exploits rewrite /bin/su in memory and leave the file clean
DirtyClone and pedit COW are the latest in a family of Linux kernel root bugs that rewrite binaries in memory, invisible to file-integrity monitoring.
Signal's recovery key never expires, and Russian intelligence is now phishing for it
Russian intelligence is phishing Signal users for the Backup Recovery Key, a secret that decrypts a whole message history and that no reset or new account can
What is MITRE ATT&CK? Tactics, techniques, and how defenders actually use it
A plain-English guide to MITRE ATT&CK: what it is, how its tactics and techniques are organized, a real intrusion mapped step by step, and how defenders use it.
The dangerous vulnerabilities this week were already old.
The vulnerability classes that actually shipped this week are the same five from 2010, even in new AI tooling. The pattern, and what to do.
Russia's Turla built a new backdoor for one reason: deleting one tool will not evict them
Google tied Russia's Turla to STOCKSTAY, a new .NET backdoor built as four swappable parts. Why deleting one piece does not evict the group, and what to hunt.
Windchill holds your product blueprints. A web shell on its login page hands them over.
CISA added PTC Windchill RCE CVE-2026-12569 to its KEV catalog after web shells hit exposed PLM servers. Patch to 11.0 M030 before the June 28 deadline.
One setting in Red Hat OpenShift Virtualization can expose your VMs to any pod on the cluster
CVE-2026-13325: enabling disableTLS for faster live migration in Red Hat OpenShift Virtualization drops authentication, letting any pod reach another tenant’s
Two flaws in Unraid's control panel let a logged-in user seize the whole server
Two command injection flaws in Unraid's web panel, CVE-2026-9772 and CVE-2026-9773, let any logged-in user run code as www-data.
A rigged container image can seize root on the host running Docker's AI agent tools
CVE-2026-55887 lets a malicious container image escape Docker's MCP Gateway and run code as root on the host. Rated 8.7.
Police seized the malware that stole 27 million passwords. The passwords still work.
Operation Endgame seized the servers behind the Amadey and StealC malware, but the 27 million credentials they already stole stay valid until you rotate them.
On 200,000 WordPress sites, a low-level user can quietly steal the admin's login
A contributor-level user can make Ultimate Member leak every user's password reset link, admins included. Affects versions through 2.11.4; fixed in 2.12.0.
Mistype the password and this Lantronix box runs attacker commands as root. CISA says it is happening now.
CISA flagged CVE-2025-67038 as exploited on June 23. A failed login on a Lantronix EDS5000 serial server runs attacker commands as root.
Crawl4AI shipped its server unlocked by default. It took three patches to close the door.
Crawl4AI's Docker API shipped unauthenticated by default, exposing 51,000+ deployments to remote code execution and cloud-metadata SSRF. Upgrade to 0.9.0 now.
Java's most-used JSON library has a guardrail attackers can slip dangerous objects past
CVE-2026-54513 lets attackers bypass jackson-databind's polymorphic type validator by wrapping a banned class in an array. Patch to 2.18.8, 2.21.4 or 3.1.4.
Attackers can take over your self-hosted UniFi controller with no password. CISA says it is happening now.
Three chained UniFi OS Server flaws give unauthenticated root. CISA added all three to its exploited list on June 23. Patch to 5.0.8 and check who can reach it.
Your self-hosted Gogs server lets any logged-in user read repos that aren't theirs
A validation gap in Gogs Mirror Settings (CVE-2026-52801) lets any authenticated user import local repositories and reach internal systems. Patch to 0.14.3 now.
One rigged account-sync update can poison your whole app and forge an admin
CVE-2026-48170 lets one SCIM PATCH request poison Object.prototype across a Node.js app using scim-patch, risking admin forgery. Update to 0.9.1 now.
Older iPhones just got a flaw Apple can't patch, and a cable is all it takes
usbliter8 is an unpatchable boot-chain exploit for Apple A12 and A13 devices. Here is the real enterprise risk, why remote wipe will not help, and what to do.
PaperCut's Windows print client can be tricked into giving a local attacker total control
CVE-2026-6645 lets a local attacker plant a file that PaperCut's Print Deploy client runs with full system rights on Windows. Update to version 1.10.4178.
That decade-old router you forgot is now scanning networks for attackers
A botnet called AryStinger hijacked over 4,300 end-of-life D-Link and Linksys routers into a distributed scanning grid for reconnaissance, not DDoS. What to do.
Millions of hacked TV boxes now rent attackers a trusted home IP. Your blocklist can't see it.
Researchers linked the Popa botnet of 2 million hacked TV boxes to a residential proxy service. Here is why IP reputation no longer stops account takeovers.
EaseUS Partition Master left a Windows driver that lets any user seize the whole PC
A signed driver in EaseUS Partition Master (CVE-2026-12781) lets any standard Windows user read and overwrite the whole disk to reach SYSTEM.
This login library let a stranger sign in as you with just your email
CVE-2026-49757 (CVSS 9.2) let attackers take over accounts in Elixir apps built on ash_authentication by matching users on email instead of identity.
vLLM's earlier patch only hid this AI-server bug. Re-enable embeddings and you are still exposed
CVE-2026-56340 lets a crafted tensor crash vLLM (CVSS 8.8) with a path to memory corruption. It only bites if you re-enabled prompt embeds. Fix is 0.13.0.
One tracing header can make a LangSmith server hand over its files
LangSmith SDK before 0.8.18 lets a crafted tracing header read arbitrary files off any server running TracingMiddleware. Upgrade now; it is the second such bug.
A USB worm swaps your crypto address mid-paste, and no breach alarm ever fires
Microsoft found a USB worm that hijacks the clipboard to swap crypto wallet addresses and hides its command channel in Tor. Here is why it beats your controls.
Branda fixed this WordPress account takeover in January. It is back, and a public exploit is circulating.
CVE-2026-11551 is a CVSS 9.8 unauthenticated account takeover in the Branda WordPress plugin (versions up to 3.4.29). A public exploit is out.
A single rigged document can turn Langflow's file reader into full server takeover
A crafted document in a Langflow RAG pipeline (CVE-2026-55447, CVSS 9.6) reads any file, forges a login token, then runs code. Upgrade to 1.9.2 or later.
One Langflow account can now run every other user's AI workflow
A critical IDOR in Langflow (CVE-2026-55255, CVSS 9.9) lets any logged-in user run another user's AI flow. Upgrade to 1.9.1. The real problem is the pattern.
CoreWCF's SAML check trusted a forged identity as your admin. There is no workaround, only the patch.
CVE-2026-54782 lets an attacker forge a SAML token and impersonate anyone, admins included, on CoreWCF federation services. No workaround.
DragonForce hides its C2 inside Microsoft Teams relays. Your network sensors see a clean call.
DragonForce's Backdoor.Turn routes C2 through Microsoft Teams TURN relays, so network sensors see only Microsoft.
Your Salesforce wasn't breached. A connected app handed over the data.
The Icarus group stole Salesforce CRM data through Klue's connected app, not a Salesforce flaw. Why OAuth integration tokens are the unmonitored attack surface.
Your Splunk box runs a database sidecar you never configured. Attackers use it for root.
CVE-2026-20253 is an unauthenticated RCE in Splunk Enterprise 10.x via a bundled PostgreSQL sidecar. On CISA KEV, exploited now. Patch to 10.0.7 or 10.2.4.
INC ransomware never used a zero-day. It used your patch backlog.
INC reached top-tier RaaS in 2026 with no zero-days. Every edge-device flaw it exploits was patched months earlier. Here is what to actually fix.
Cisco called this SD-WAN flaw medium. Attackers used it to take root on your WAN.
CVE-2026-20262 is an actively exploited Cisco SD-WAN Manager flaw that escalates a low-privilege login to root.
FortiBleed isn't a Fortinet bug. It's every password you never rotated.
FortiBleed exposed working VPN logins for tens of thousands of Fortinet firewalls. There is no CVE to patch; the fix is rotating credentials and enforcing MFA.
FortiSandbox Under Attack: The Box That Catches Malware Is Now the Way In
Three critical FortiSandbox flaws are under active exploitation, two unauthenticated and one patched a week ago.
Why we built Suriq on Wazuh instead of writing our own detection engine
Suriq runs on Wazuh because a detection engine is a decade of decoders, CVE feeds, and agents you should never rebuild. Here is the reasoning behind the bet.
Ivanti Sentry's CVE-2026-10520: patch the gateway, then hunt for the breach
Ivanti Sentry CVE-2026-10520 is an unauthenticated root RCE under active attack. CISA's new 3-day patch rule applies; patched gateways were already breached.
PeopleSoft's PSEMHUB zero-day turns the patch service into the breach
CVE-2026-35273 sits in PeopleSoft's Updates Environment Management module. Mandiant ties active exploitation to ShinyHunters, with 100+ orgs already breached.
Velvet Ant's PAM-OpenSSH decade is an auth-stack blind spot, not a Linux bug
Sygnia found nine backdoored pam_unix.so variants and four trojanized OpenSSH binaries on one victim. Why auth-stack integrity is the SIEM-invisible gap.
Ready to meet the Guardians?
Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.