Home/ Blog/ Noam Alum
Senior Platform Engineer
Noam Alum

Noam Alum

Noam Alum is a Senior Platform Engineer specializing in developer infrastructure, release engineering, and cyber platform resilience. He designs and builds the platforms that power software delivery, infrastructure automation, and disaster recovery at Suriq. His work spans software supply chain management, internal developer platforms, and operational resilience, helping Suriq deliver secure, scalable, and maintainable solutions.

developer infrastructurerelease engineeringsoftware supply chaininternal developer platformsinfrastructure automationoperational resilience

Connect with Noam

Follow Noam Alum on LinkedIn for threat analysis, incident breakdowns, and field notes from the Suriq desk, straight to your feed.

205 articles by Noam Alum

Security news

Check Point CVE-2026-93616 & 85102: 9.8 Pre-Auth RCEs Exploited

Check Point CVE-2026-93616 and CVE-2026-85102 are two 9.8 pre-auth flaws exploited in the wild and on CISA's KEV list. Patch, then hunt for compromise.

Security news

The gatekeeper was the target: identity appliances got bypassed

This week's exploited flaws were in the access-control layer itself: Cisco ISE (two CVSS 10.0, in CISA KEV) and Kong Gateway's SAML bypass.

Security news

Brevo Hack Injected Malware at the CDN Edge, Evading Site Checks

Attackers abused Brevo (formerly Sendinblue) to inject malware into up to 100,000 sites at the CDN edge, so origin files never changed and checks missed it.

Security news

Cisco ISE CVE-2026-76460: Exploited Auth-Bypass Zero-Day, Patch

CVE-2026-76460 is an unauthenticated API auth bypass in Cisco ISE, CVSS 10.0, actively exploited and in CISA KEV. Patch ISE 3.1-3.5 to the fixed build now.

Security news

Cisco ISE CVE-2026-20192: Exploited Access-Control Flaw, Patch Now

Cisco's September 2026 ISE hardening release fixes six flaws, two rated CVSS 10.0. One access-control bug (CVE-2026-20192) is being exploited.

Security news

Kong Gateway CVE-2026-14917: SAML Auth Bypass, Check Config

Kong Gateway's SAML plugin (CVE-2026-14917) can accept unsigned responses and impersonate admins when signature validation is off. Audit the flag, then patch.

Security news

BioStar 2 CVE-2026-31278: Active Directory Password Leak, Patch Now

Suprema BioStar 2 exposes its Active Directory bind password in cleartext via an API endpoint (CVE-2026-31278). Patch to 2.9.12 and rotate the account.

Security news

JFrog Artifactory CVE-2026-42016: Auth Chain to Admin, Patch Fast

CISA added JFrog Artifactory CVE-2026-42016 and CVE-2026-42018 to KEV. Chained, they turn an unauthenticated request into admin.

Security news

Omada Controller CVE-2026-84941: SAML XXE File Read, Patch

TP-Link patched CVE-2026-84941, an XXE in Omada Controller's SAML SSO that lets an admin read files off the host. Update to 6.2.14.11 or the 20260711 build.

Security news

Keycloak CVE-2026-88770: Device Flow Bypasses Account Lockout

CVE-2026-88770 lets a held Keycloak session mint fresh tokens through the device grant flow while the account is brute-force-locked.

Security news

N-able N-central CVE-2026-86218: CVSS 10 Unauth RCE, Patch Now

N-able shipped its fourth N-central hotfix in five weeks: CVE-2026-86218, a CVSS 10 unauthenticated RCE on the on-prem console. Patch to 2026.3.1.14 and hunt.

Security news

LiteLLM CVE-2026-59822: MCP Auth Bypass, Exploited, Patch Now

CVE-2026-59822 is an actively exploited MCP auth bypass in the LiteLLM gateway. Patch to 1.84.0 and rotate every stored provider and virtual key now.

Security news

A rogue member cluster can run code as root on Red Hat's cross-cluster gateway (CVE-2026-66786)

CVE-2026-66786 (CVSS 9.1): in cert-auth mode a malicious member cluster can inject IPsec config into Red Hat Submariner and run code as root on the gateway.

Security news

SonicWall SMA1000 zero-days chain a pre-login SSRF into remote code execution, exploited now

SonicWall SMA1000 zero-days CVE-2026-83548 and CVE-2026-83549 chain a pre-login SSRF into admin command injection for RCE. Exploited now. Patch and hunt.

Security news

Critical Predis flaw lets attacker-controlled data smuggle extra Redis commands (CVE-2026-84372)

CVE-2026-84372 is a CVSS 9.8 command-injection flaw in the Predis PHP client. It hits 3.0 to 3.2 on cluster and replication connections. Upgrade to 3.3.0.

Security news

A BGP hijack pushed a malicious Virtualizor update that ran as root. Check for one systemd service.

A 33-hour BGP hijack redirected Softaculous update traffic and pushed a malicious Virtualizor package that ran as root. Check a systemd service, patch 3.2.9.9.

Security news

A public exploit turns Kaspersky's endpoint agent into a privilege-escalation tool on fully patched Windows 11

A public exploit, HardBreacher, coerces Kaspersky Endpoint Security into a privileged write on fully patched Windows 11. Vendor says fixed, no CVE yet.

Security news

Manchester Airports breach: a marketing API key exposed in client-side JavaScript

An extortion group says it pulled 86GB from Manchester Airports Group using a marketing API key exposed in client-side JavaScript.

Security news

Trusted browser extensions turned into crypto-wallet drainers after silent updates

Browser extensions in the Superior campaign shipped clean, then a silent update drained crypto wallets and stole logins. How to detect it and respond.

Security news

AJCloud camera firmware flaw lets anyone read your Wi-Fi password and camera logins

A path traversal bug in AJCloud AJY IPC camera firmware (CVE-2026-56718) lets unauthenticated attackers read Wi-Fi passwords and camera credentials as root.

Security news

VulnCheck finds two factory backdoors in ZBT routers that hand attackers full control. No fix exists.

VulnCheck found two more factory implants in ZBT router firmware, SPEAKINGSTONE and DARKLANTERN (CVE-2026-74232/74233), that grant remote root access.

Security news

Three ServiceNow AI Platform flaws (CVSS 10.0) let an unauthenticated attacker run code. Patch now.

ServiceNow patched three CVSS 10.0 AI Platform flaws an unauthenticated attacker can chain for code execution, SQL injection, and privilege escalation.

Security news

Linux kernel IPv6 flaw (CVE-2026-53362) lets a container break out to host root, now exploited

CVE-2026-53362 is an actively exploited Linux kernel IPv6 flaw that lets a low-privilege user escape a container to host root.

Security news

One logged-in Langflow user can run any command on the server, and its code lockdown doesn't stop it

A critical Langflow flaw (CVE-2026-19295, CVSS 9.9) lets any authenticated user run OS commands on the server and bypasses the

Security news

A logged-in user can write files outside JFrog Artifactory's cache, and it's now on CISA's must-patch list

CISA added a JFrog Artifactory path-traversal flaw (CVE-2026-66384) to its must-patch list. A logged-in user can write files outside the Docker cache path.

Security news

CISA red team breached two critical infrastructure networks. Only one SOC noticed.

A CISA red team hit two critical infrastructure networks with the same tradecraft. One SOC contained it in minutes, the other never noticed. Here is the gap.

Security news

PaperCut print servers are under active attack through a login-free code-execution flaw

Attackers are exploiting an unauthenticated flaw in PaperCut NG and MF print servers to run code as the host account. Restrict access and patch now.

Security news

Weedhack stealer survives takedown by hiding servers on Ethereum, still spreading via fake Minecraft sites

Weedhack, an infostealer spread through fake Minecraft sites, survived a C2 takedown by reading server addresses from the Ethereum blockchain. How to detect it.

Security news

Iran-linked hackers took a UK power plant offline for four days

Iran-linked hackers reportedly kept a small UK power plant offline for four days, as water systems across 12 US states were hit. What defenders should do.

Security news

A max-severity Oracle WebLogic proxy flaw lets attackers reach protected data, and it is under active attack

CVE-2026-21962 is a CVSS 10 access-control bypass in Oracle's WebLogic proxy plug-in, now in CISA KEV with a three-day deadline.

Security news

A phpIPAM flaw lets an unauthenticated attacker read and delete every network record (CVE-2026-67602)

CVE-2026-67602 is a critical unauthenticated flaw in phpIPAM before 1.8.2 that lets anyone read, change, or delete every IP record through the REST API.

Security news

fast-uri, the URL parser in many Node.js apps, can be tricked into calling internal systems (CVE-2026-75899)

CVE-2026-75899 lets a double-encoded hostname bypass fast-uri's URL checks and resolve to localhost or a cloud metadata endpoint. Fixed in 2.4.5, 3.1.6, 4.1.3.

Security news

Malware turns Android car head units into a proxy botnet that hides attacks behind trusted home IPs

Kaspersky found the first malware built for Android car head units. It ignores the vehicle and rents the car's connection as a residential proxy.

Security news

Citrix NetScaler flaw CVE-2026-19490 lets an attacker bypass login on Gateway and AAA servers. Patch now.

A critical NetScaler auth bypass (CVE-2026-19490, CVSS 9.3) lets a remote attacker skip login on Gateway and AAA servers.

Security news

NASA AIT-GUI console has no login (CVSS 9.4), and the 2.5.2 patch still adds no authentication

AIT-GUI, NASA/JPL open-source operator console, binds to every interface with no login (CVSS 9.4). A browser can send commands, and the 2.5.2 fix adds no auth.

Security news

Elementor Pro flaw (CVE-2026-32475) lets an unauthenticated attacker upload PHP and run code. Patch to 4.2.2.

Elementor Pro before 4.2.2 has a critical file upload flaw (CVE-2026-32475, CVSS 9.0) letting an unauthenticated attacker plant a PHP webshell. Patch now.

Security news

A flaw in the Mailgun for WordPress plugin lets a stranger take over the admin account (CVE-2026-78003)

A critical Mailgun for WordPress plugin flaw (CVE-2026-78003) lets unauthenticated attackers reroute password-reset emails and seize admin accounts. Fix: 2.2.1.

Security news

A single web request can hijack SPIP websites with no login, and the first patch missed it (CVE-2026-77806)

SPIP before 4.4.21 has a critical unauthenticated code-execution flaw (CVE-2026-77806, CVSS 9.8) exploited in the wild. The 4.4.20 patch fell short; update now.

Security news

A rigged threat-intel record can trick MISP's STIX converter into reading local files (CVE-2026-77751)

A path traversal flaw (CVE-2026-77751, CVSS 8.8) in MISP's misp-stix converter lets crafted STIX content read files outside the template folder. Patch it.

Security news

A critical Keycloak flaw lets a stranger reset any user's password and take over the account (CVE-2026-18963)

CVE-2026-18963 is a critical Keycloak flaw (CVSS 9.1) that lets an unauthenticated attacker reset any user's password and take over the account.

Security news

Red Hat Multicluster CVE-2026-66794: Pre-Auth SSRF, No Patch Yet

CVE-2026-66794 (CVSS 9.3): an unauthenticated attacker can reach internal services on any Red Hat managed cluster through the cluster-proxy route. No patch yet.

Security news

A ransomware crew hijacked about 2,000 WordPress sites to spread its malware. Your site could be one of them.

Check Point unmasked StopAndProtect, a ransomware operation running on about 2,000 hacked WordPress sites.

Security news

TWINLOOT runs its command channel inside Microsoft 365 and steals passwords with a fake Windows lock screen

TWINLOOT hides its command channel in SharePoint, Teams, and Edge and steals passwords with a fake Windows lock screen. No CVE. Here is how to detect it.

Security news

Windows Task Host flaw CVE-2025-60710 gives a local user SYSTEM, and ransomware gangs now exploit it

CISA confirms ransomware crews are exploiting CVE-2025-60710, a Windows Task Host flaw that elevates a local user to SYSTEM on Windows 11 and Server 2025.

Security news

Red Hat Advanced Cluster Management flaw lets a user run a rogue container as admin on managed clusters

CVE-2026-66793 (CVSS 8.8): a low-privilege user in Red Hat Advanced Cluster Management can swap in a rogue container and gain full admin on managed Kubernetes

Security news

A single phpIPAM share link can leak your whole network inventory (CVE-2026-75105). Update to 1.8.2.

CVE-2026-75105 lets anyone holding one phpIPAM temporary share link read every IP record across all subnets, including notes that often hold credentials.

Security news

A malicious web page can run code on developers' Ray AI servers, and CISA confirms active exploitation

CISA flagged CVE-2025-62593 in Ray as actively exploited. A malicious web page can reach a developer's local Ray dashboard and run code. Patch to Ray 2.52.0.

Security news

Mustang Panda's kernel rootkit hides its backdoor from host tools

Mustang Panda's CoolClient backdoor now uses a signed kernel rootkit to hide from host tools. Why it is a hide not a kill, and where to still detect it.

Security news

Apache Struts flaw: one crafted JSON request can exhaust memory and crash the app (CVE-2026-73633)

CVE-2026-73633 (S2-072) lets one oversized JSON request exhaust memory in Apache Struts and crash the app. A public PoC is out. Patch to 7.3.0 or 6.11.0.

Security news

Evooo1Bot botnet turns exposed Linux servers into credential-stealing proxies

Evooo1Bot is a new Linux botnet exploiting Confluence, WSO2 and ingress-nginx, then stealing credentials and turning servers into proxies. Detect it now.

Security news

A flaw in Adobe Commerce and Magento lets a stranger take over customer accounts with no login. Patch now.

CVE-2026-71362 is a critical, unauthenticated account takeover in Adobe Commerce and Magento (CVSS 9.1).

Security news

AmnesiaStealer hijacks live macOS browser sessions, not just saved passwords

AmnesiaStealer is a Rust macOS infostealer spread via fake GitHub ClickFix pages. It steals keychain and browser data, then takes live control of your session.

Security news

Akira ransomware reboots Windows into Safe Mode to shut off security tools

An Akira ransomware affiliate rebooted a Windows host into Safe Mode to disable EDR, stole the data, then fumbled the encryption.

Security news

A malicious code repository can run commands when opened in editors built on Eclipse Theia. Update to 1.70.

Opening a malicious repository in an editor built on Eclipse Theia could run attacker commands via a crafted git config.

Security news

A poisoned Trivy scanner, not LiteLLM, exposed 2,500 organizations' CI/CD secrets

CloudSEK maps 2,500+ organizations exposed by the TeamPCP (UNC6780) supply-chain campaign.

Security news

North Korea's Lazarus used fake job offers and a Windows zero-day to hijack defense firms' PCs

North Korea's Lazarus group used fake job offers and a Windows zero-day (CVE-2026-68820) to seize SYSTEM control of defense and aerospace PCs. Patch now.

Security news

Ivanti Endpoint Manager patch: leaked database passwords, editable session recordings, crashable agents

Ivanti's August 2026 Endpoint Manager advisory fixes three high-severity flaws (CVE-2026-18129, -18127, -18125), all resolved in 2024 SU7.

Security news

Critical Commvault flaw lets attackers run blocked commands on the backup control server

Commvault patched CVE-2026-13737, a critical CVSS 9.2 allowlist bypass in CommServe that lets attackers run commands the backup control server should block.

Security news

Unauthenticated SAP NetWeaver flaw can leak server memory or crash it (CVE-2026-34265). Patch now.

SAP's August 2026 patch day fixes CVE-2026-34265, a critical (CVSS 9.8) flaw letting an unauthenticated attacker crash SAP NetWeaver AS ABAP or leak its memory.

Security news

China-linked Storm-1175 turns N-able N-central into a ransomware launchpad with new StormEncryptor

Microsoft ties China-linked Storm-1175 to StormEncryptor ransomware deployed through the N-able N-central auth bypass (CVE-2026-18577). Patch, then hunt.

Security news

Malicious npm packages skip install scripts and hide their C2 in DNS to drop a cross-platform stealer

Flooding Dropper seeded close to 800 malicious npm packages that run on require() and fall back to DNS TXT records for C2. How to detect it and clean up.

Security news

A Linux kernel SCTP flaw (CVE-2026-64564) escalates to root and breaks out of default-seccomp containers

SCTPhantom (CVE-2026-64564) is a use-after-free in Linux SCTP that reaches host root and escaped default-seccomp containers in 6 of 8 tests.

Security news

Malware can use Windows Hello keys to sign into Entra ID as you

Malware in a signed-in Windows session can use the Windows Hello key to log into Microsoft Entra ID and hold a 90-day token. How to detect and mitigate it.

Security news

Attackers turn unpatched TrueConf servers into backdoor delivery, pushing trojanized client installers

Head Mare exploited unpatched TrueConf servers (before 5.3.9, 5.4.9, 5.5.5) to swap client installers for unsigned backdoors.

Security news

Metabase zero-day (CVSS 10.0): unauthenticated SQL injection hands attackers admin and data. Patch now.

Metabase's SQL injection zero-day (CVSS 10.0) gives unauthenticated attackers admin access and stored database credentials. Exploited now: patch and rotate.

Security news

TONTOU beats Spectre v2 fixes to read kernel memory on AMD chips, but only from local code

TONTOU, a new MIT attack, re-poisons the branch predictor after Spectre v2 defenses run to leak kernel memory. It needs local code. AMD patched, Intel did not.

Security news

VulnCheck: Zbtlink routers ship a factory root shell with no fix. The model list is not where you start.

VulnCheck found a factory-shipped remote-access implant in 20 Zbtlink router models that calls home and hands a remote root shell. There is no patched firmware.

Security news

A signed ScreenConnect installer becomes a backdoor after malware turns Defender off

The SMOKE#SCREEN campaign disables Windows Defender, then installs a legitimately signed ScreenConnect agent your allowlist trusts.

Security news

A Keycloak flaw lets attackers forge a single sign-on login and hijack accounts (CVE-2026-16443)

CVE-2026-16443 is a Keycloak flaw where importing SAML identity-provider metadata can leave signature checks off, letting an attacker forge a login.

Security news

SUSE Rancher stored cluster join tokens in plaintext, and one leaked token can take over the whole cluster

SUSE Rancher stored long-lived Kubernetes registration tokens in plaintext (CVE-2026-55997, CVSS 8.8). Upgrade to 2.14.4 or 2.13.8, then rotate every token.

Security news

A self-spreading npm worm poisoned hundreds of packages to steal cloud and GitHub tokens

A self-propagating npm worm that began in keyv 6.0.0 poisoned hundreds of packages on August 4, steals GitHub, npm, cloud, Vault and Kubernetes credentials

Security news

An AI system found 14,090 new bugs across open-source software. Attackers can run the same scan.

Palo Alto's Unit 42 says its NOVA system found 14,090 unreported bugs across 3,915 open-source projects. The count is not the story.

Security news

Device-code phishing jumped 1,500% in 2026: attackers take over Microsoft 365 accounts with no password or MFA

Device-code phishing rose 1,500% in 2026, letting attackers mint Microsoft 365 tokens with no password or MFA. Here is how to detect and block the OAuth flow.

Security news

N-able N-central auth bypass grants admin; first fix failed

N-able N-central RMM has an actively exploited authentication bypass (CVE-2026-18577). The first patch failed; upgrade to 2026.3.1.7 and hunt your endpoints.

Security news

Sharp and Toshiba office copiers shipped with the login turned off, exposing saved scans

Sharp and Toshiba Tec copiers sold outside Japan shipped with authentication off, exposing the address book and stored scans (CVE-2026-63563).

Security news

Amazon ties the debug, chalk, and axios npm hijacks to North Korea

npm supply-chain attacks on debug, chalk, and axios are tied to one North Korean crew, Sapphire Sleet. Why signing missed it, and how to detect it.

Security news

Adform's shared ad-tracking script was hijacked to swap crypto wallet addresses in visitors' browsers

Attackers trojanized Adform's shared trackpoint-async.js to swap Bitcoin, Ethereum, and Tron wallet addresses in visitors' browsers. Why SRI can't stop it.

Security news

An AI agent hit 460 servers on its own, but known CVEs did the breaking

A China-linked operator wired DeepSeek into an autonomous agent that swept 460+ exposed servers.

Security news

Anthropic's own AI models breached three real companies in tests

Anthropic says three of its AI models breached real companies during security tests after a sandbox misconfiguration. Two of three victims never noticed.

Security news

Unauthenticated attacker can read any file on a Ruby on Rails server via a crafted image (CVE-2026-66066)

CVE-2026-66066 lets an unauthenticated attacker upload a crafted image to a Rails app and read any server file, including its signing key. Patch now.

Security news

Silver Fox's new kit hot-swaps vulnerable drivers to kill EDR and plant ValleyRAT

Silver Fox now runs a modular bring-your-own-vulnerable-driver kit with three interchangeable drivers, killing EDR from the kernel to deploy ValleyRAT.

Security news

FCC adds networked robots and inverters to its Covered List. The installed base is still yours to secure.

The FCC added networked power inverters and mobile robots to its Covered List over remote-control risk.

Security news

Russian OWAReaper implant exploits an Outlook Web Access flaw, and a password reset won't evict it

Russian group Void Blizzard is exploiting Outlook Web Access flaw CVE-2026-42897 to plant OWAReaper, a backdoor whose server-side mailbox access survives

Security news

Cisco's firewall management software has a hardcoded password, and attackers are already using it

Cisco Secure Firewall Management Center ships a static password (CVE-2026-20316) that lets unauthenticated attackers log in. Now in CISA KEV. Patch and hunt.

Security news

New VMware flaws let a network attacker run code on vCenter with no login, and escape a VM onto the host

VMware's VMSA-2026-0006 patches two 9.8 vCenter flaws that add up to unauthenticated code execution, plus a 9.3 ESXi VM escape. Patch vCenter first.

Security news

30+ Minnesota water utilities hit in a coordinated attack, and the timing is the real warning

More than 30 Minnesota water systems were hit in a coordinated two-day attack. The simultaneity points to shared exposure; the signal sits on the IT side.

Security news

Apache Traffic Server flaw lets attackers slip hidden requests past security checks and forge internal data

Apache Traffic Server has a critical flaw, CVE-2026-33267 (CVSS 10), that lets attackers smuggle requests and spoof internal metadata.

Security news

Fastjson RCE (CVE-2026-16723) now exploited on Spring Boot apps

CVE-2026-16723, a fastjson 1.x remote code execution flaw, is now exploited against US firms. Only Spring Boot fat-JAR apps are hit, and no 1.x patch is coming.

Security news

24,650 exposed server BMCs leak crackable IPMI password hashes, and no patch can fix it

A scan found 24,650 internet-exposed server BMCs leaking IPMI password hashes to anyone via CVE-2013-4786. There is no patch. Here is how to close the exposure.

Explainers

Public DNS servers with filtering: a verified list of what each IP really blocks

Public DNS servers with filtering, verified against official docs: what the Cloudflare, Quad9, AdGuard, CleanBrowsing, ControlD, Mullvad and OpenDNS IPs block.

Security news

Attackers can slip past Fortinet's fix and keep reading a hacked firewall's files, CISA warns

CISA added CVE-2025-68686 to its exploited catalog: a bypass of Fortinet's FortiOS symlink fix lets attackers who already breached a FortiGate keep reading its

Security news

n8n flaw lets any workflow editor run OS commands on your server (GHSA-gv7g-jm28-cr3m)

n8n patched a CVSS 8.7 expression sandbox escape (GHSA-gv7g-jm28-cr3m) that lets any workflow editor run OS commands on the host. Update to 2.32.1 now.

Security news

A 'read-only' role in Red Hat OpenShift Virtualization lets one tenant copy another tenant's data

CVE-2026-17527 lets a low-privileged OpenShift Virtualization tenant copy other tenants' data across namespaces through a read-only role. No fix yet; audit now.

Security news

Hotel Wi-Fi hijacks steal Microsoft 365 accounts past MFA

A campaign is hijacking hotel and conference Wi-Fi to steal Microsoft 365 accounts. A VPN closes most of it, but not the device-code trick that beats MFA.

Security news

A public exploit lets a stranger log in as WordPress admin through miniOrange's single sign-on plugin

A public exploit for CVE-2026-15981 lets unauthenticated attackers log in as any WordPress admin via the miniOrange SAML SSO plugin. Update to 5.4.5 now.

Security news

Public exploit hits a critical Oracle WebLogic flaw that forges a login to take over the server

A public proof-of-concept exploit now targets CVE-2026-60206, a CVSS 9.9 Oracle WebLogic flaw that forges a login to take over the server. Patch and hunt now.

Security news

WPForms Pro flaw lets a stranger upload a file and run code on your WordPress site. Patch now.

A flaw in WPForms Pro (CVE-2026-10818) lets unauthenticated attackers upload executable files to WordPress sites on versions up to 1.10.1.1 and run code.

Security news

Attackers ran an AI agent unattended to do the hands-on hacking inside Thailand's finance ministry

An attacker ran an unattended AI agent to hack Thailand's finance ministry. It used no new exploit, and defenders catch it by watching host actions.

Security news

A Keycloak flaw lets a view-only admin read live client secrets from the vault (CVE-2026-17048)

CVE-2026-17048 lets a view-only Keycloak admin read resolved client secrets from the vault instead of the placeholder.

Security news

Fake Notepad++ plugin drops a Windows loader that slips past sandboxes and app allowlists

CERT-UA ties UAC-0099 to a campaign hiding a Windows loader in a genuine Notepad++ via DLL sideloading.

Security news

Zimbra webmail zero-day (CVE-2025-66376) let Russian spies steal mail and mint MFA-bypass passwords

Russian group Void Blizzard exploited Zimbra webmail flaw CVE-2025-66376 as a zero-day to steal 90 days of mail and mint app passwords that survive resets.

Security news

RefluXFS: a Linux XFS flaw gives any local user root access

RefluXFS (CVE-2026-64600) lets any local user get root on default RHEL, Rocky, Alma and Amazon Linux via an XFS race. No workaround: patch and reboot.

Security news

Adobe's Acrobat Chrome extension let any website read WhatsApp Web chats (CVE-2026-48294). Update now.

A cross-origin flaw in Adobe's Acrobat Chrome extension (CVE-2026-48294) let any website read WhatsApp Web chats. Update to 26.5.2.3 and govern extensions.

Security news

Check Point's SmartConsole flaw lets an unauthenticated attacker become full admin, and it is being exploited

Check Point SmartConsole flaw CVE-2026-16232 is exploited and in CISA KEV, letting an unauthenticated attacker log in as full admin.

Security news

A Jackson library flaw lets low-privilege users write fields meant only for admins

CVE-2026-59889 lets a low-privilege user bypass jackson-databind's @JsonView write guard and set admin-only fields. Patched in 2.18.9, 2.21.5, 3.1.5.

Security news

HollowGraph turns Microsoft 365 into a C2 channel with no patch

HollowGraph runs its command channel through a hijacked Microsoft 365 calendar over the Graph API. No CVE, no patch: here is how to detect it.

Security news

nginx CVE-2026-42533: Heap Overflow in a Common map Regex Config

CVE-2026-42533 is a CVSS 9.2 heap overflow in nginx's string engine, patched July 15. Unlike June's flaws it fires on a common regex map config.

Security news

ServiceNow is under active attack through a route the public exploit does not show. Patch, don't block.

ServiceNow's pre-auth sandbox-escape flaw CVE-2026-6875 (CVSS 9.5) is under active exploitation.

Security news

In Apache Camel, a manipulated AI reply can quietly redirect what the server does next

CVE-2026-49042 lets a prompt-injected AI model set hidden Apache Camel headers via tool-call arguments, reaching code execution or SSRF on exposed routes.

Security news

EY's breach came through the help desk, not the audit floor

EY says client tax data leaked from a third-party IT support platform, not its audit systems. Why help-desk tooling is a crown-jewel store, and how to watch it.

Security news

wp2shell went from patch to public exploit in a day. Patching is no longer enough.

Public proof-of-concept exploits for the wp2shell WordPress Core RCE (CVE-2026-63030) are live and the mechanism is disclosed.

Security news

ACR Stealer steals live sessions. A password reset won't help.

ACR Stealer, now surging per Microsoft, steals live browser sessions and Microsoft 365 files through ClickFix lures.

Security news

OpenSSL's HollowByte flaw freezes servers, and no CVE flags it

OpenSSL patched HollowByte, an 11-byte flaw that strands server memory, quietly in June with no CVE.

Security news

A stranger with no login can take over WordPress sites on 6.9 and 7.0. Patch now.

WordPress Core 6.9 and 7.0 carry wp2shell (CVE-2026-63030), an unauthenticated remote code execution flaw. Update to 6.9.5 or 7.0.2 right away, then hunt.

Security news

AI wrote most of this IoT botnet, badly. That helps defenders.

Unit 42 found TuxBot v3, an IoT botnet largely written with an AI. The build is 70% broken, the working core is plain Mirai, and your defenses still hold.

Security news

SharePoint's new RCE is live, and patching alone won't clean it

CVE-2026-58644, a SharePoint deserialization RCE, is in CISA's KEV catalog and exploited as a zero-day. Patching alone won't evict an attacker who stole keys.

Security news

A single Envoy Gateway policy can hand a user the keys to your Kubernetes cluster

CVE-2026-53713 (CVSS 9.1): a path check in Envoy Gateway misses double slashes, letting a submitted Lua policy read the controller's Kubernetes token and TLS

Security news

A booby-trapped Linux app can escape its sandbox through the audio server and run on your system

CVE-2026-5674 lets a sandboxed Linux app abuse PipeWire's PulseAudio layer to load a malicious library and run code outside the sandbox.

Security news

A WatchGuard firewall can be taken over through its single sign-on agent, no login required

CVE-2026-8247 lets a network-adjacent attacker run code as root on WatchGuard Firebox firewalls with no login.

Security news

RabbitMQ's takeover flaw is conditional. The quiet one isn't.

RabbitMQ patched CVE-2026-57219 and CVE-2026-57221. The severe OAuth secret leak needs OAuth configured; the quiet metadata bug hits every shared virtual host.

Security news

Grafana's AI connector can leak its access token to a stranger and reach into your cloud

A high-severity flaw (CVSS 8.6) in Grafana's MCP server lets an unauthenticated attacker steal its Grafana service-account token and relay requests into

Security news

Two SonicWall remote-access zero-days are under attack, and patching alone will not clean the box

SonicWall patched two actively exploited SMA 1000 zero-days, CVE-2026-15409 and CVE-2026-15410.

Security news

Two Microsoft zero-days were exploited before the fix shipped

Microsoft's July 2026 Patch Tuesday fixes two zero-days already exploited in the wild: an ADFS and a SharePoint Server privilege bug.

Security news

Notarized by Apple, still malware: the CrashStealer Mac stealer

CrashStealer is a macOS info-stealer that Apple notarized, so Gatekeeper cleared it on launch before it drained keychains, browser logins and crypto wallets.

Security news

Mass CMS campaign turns unpatched plugins into webshells

Australia's cyber agency warns of a global campaign mass-exploiting 16 known CMS and plugin flaws to drop webshells on WordPress, Joomla and Craft sites.

Security news

A cache-plugin flaw backdoored 17,000 WordPress sites. A max-severity bug got 77.

An exposed server revealed WP-SHELLSTORM, a WordPress and Joomla webshell operation. Its own logs show CVE severity barely predicted which sites got hacked.

Security news

Ghost accounts are mapping your GitHub org. The recon is invisible; the stolen token is not.

Datadog found 50+ dormant GitHub accounts enumerating corporate orgs through the public API, some escalating to private-repo clones with stolen tokens.

Security news

npm just killed install-script malware by default. This week's other attack walks right past it.

npm 12 disables install scripts by default, which would have stopped this week's jscrambler infostealer.

Security news

Super Forms flaw lets anyone take over a WordPress site, and a working exploit is now public

A critical flaw (CVSS 9.8) in the Super Forms WordPress plugin lets unauthenticated attackers run code on the server.

Security news

A rigged Jira ticket can trick the mcp-atlassian AI connector into leaking server files

mcp-atlassian before 0.22.0 reads files off its own host when a caller or a prompt-injected agent supplies a server-side path.

Security news

Three attacks in one week turned AI coding agents into an unmonitored way onto your network

HalluSquatting and Friendly Fire show AI coding agents running attacker code with a developer's privileges. No CVE, no patch. Here is the detection posture.

Security news

A fake 7-Zip installer rents your server out as a residential proxy, and file scans miss it

A trojanized 7-Zip and VPN campaign called Lurking Lizard turns servers and PCs into residential proxy nodes.

Security news

GhostLock turns any Linux foothold into host root, and containers don't stop it

GhostLock (CVE-2026-43499) is a 15-year-old Linux kernel flaw that turns any local foothold into host root and escapes containers. Who is exposed, how to patch.

Security news

GodDamn ransomware blinds EDR with a signed kernel driver. Detect the load, not the file.

GodDamn ransomware uses PoisonX, a kernel driver carrying a valid Microsoft signature, to disable EDR.

Security news

Five Tenda router models ship a hidden admin password. With no patch, containment is the only move.

CERT/CC flagged a hardcoded admin password in five Tenda router models (CVE-2026-11405). No fix exists yet, so here is how to detect and contain it.

Security news

Two pre-auth bypasses hit BeyondTrust's privileged-access appliances, found by the vendor's own AI

BeyondTrust patched four flaws in Remote Support and Privileged Remote Access, including two pre-auth CVSS 9.2 bypasses. Upgrade to 25.3.3 and hunt the window.

Security news

Two Joomla page builders are exploited for site takeover. The patch won't evict the intruder.

CISA flagged two CVSS-10 Joomla page-builder flaws, SP Page Builder (CVE-2026-48908) and Page Builder CK (CVE-2026-56290), as exploited.

Security news

Adobe ColdFusion is under active attack, but the max-severity rating overstates who is exposed

Adobe ColdFusion flaw CVE-2026-48282 (CVSS 10.0) is now exploited in the wild and in CISA KEV. Who is actually exposed, how to detect it, and what to patch.

Security news

The new Cavern C2 needs no CVE. It abuses your IT provider's own tools to get in.

Check Point ties the Iran-linked Cavern C2 to intrusions that skip vulnerabilities entirely, abusing IT providers' own deployment tools.

Security news

A default in Red Hat's Linux login system lets one directory account seize root on every server

CVE-2026-14474: when SSSD's LDAP sudo provider has no explicit search base, one directory account can plant a rule that grants root on every enrolled Linux

Security news

Gitea's Docker image trusts a login header from anyone, and probing has started

A default in Gitea's Docker image trusts the X-WEBAUTH-USER header from any IP, so anyone can log in as any user.

Security news

AI reopened a 2017-audited filesystem and found seven bugs your devices can't patch

runZero found seven flaws in FatFs, the filesystem inside millions of cameras, drones and controllers. No upstream patch exists. How to detect and contain it.

Security news

Kairos stole 2TB, encrypted nothing, and still got $1M. Watch the login, not the file locker.

Kairos stole 2TB from a US county, encrypted nothing, and was paid $1M. Encryptionless extortion breaks file-locker alarms. Detect the login and egress.

Security news

A poisoned security scanner ran on your build server and walked out with your cloud keys

The FBI's TeamPCP FLASH alert shows why a trojanized scanner steals from your servers, not the registry, and why pinning packages will not save you.

Security news

No password needed: a public exploit now hijacks unpatched Control Web Panel servers

A public exploit for a critical Control Web Panel flaw (CVE-2026-57517) lets unauthenticated attackers seize hosting servers. Patch to 0.9.8.1225 and hunt now.

Security news

The FBI seized NetNut's proxy network. Its two million compromised devices are still infected.

The FBI and Google seized the NetNut residential proxy network on July 2, but its two million compromised devices are still infected. Why IP reputation fails.

Security news

Scattered Spider keeps winning because your help desk, not a CVE, is the way in

An extradited Scattered Spider suspect breached a retailer in under three hours through a help-desk password reset. Here is the identity control that stops it.

Security news

Kemp LoadMaster's quote sanitizer became a pre-auth root RCE, exploited hours after the writeup dropped

Kemp LoadMaster's CVE-2026-8037 gives unauthenticated root through its API and is under active exploitation. Affected versions, the fix, and how to detect it.

Security news

The first AI-run ransomware locked a database with a key it never saved

The first ransomware attack run end to end by an AI agent broke in through a year-old Langflow flaw and encrypted a database with a key it never saved.

Security news

Cursor's AI agent trusted the content it read, and that content could switch off its sandbox

Two critical Cursor flaws, DuneSlide (CVE-2026-50548/50549, CVSS 9.8), let a poisoned MCP server or web result overwrite the sandbox binary and run code.

Security news

Argo CD can be taken over from inside your cluster, and there is no patch to wait for

Argo CD's repo-server runs code for unauthenticated callers and can take over your Kubernetes cluster. No patch or CVE exists yet, so isolate and watch it now.

Security news

A rigged puzzle talked six AI browsers into leaking a developer's SSH keys. One patch won't save you.

A game-themed web page talked six AI browsers into leaking a developer's SSH keys. Why patching one vendor is not the fix, and what to watch instead.

Security news

Fake exploit code is delivering ChocoPoC, a stealer aimed at the researchers who run it

ChocoPoC hides a credential-stealing trojan inside fake CVE proof-of-concept repos, targeting the researchers and red teams who download and test them.

Explainers

How to Use Wazuh: A Practitioner's Guide to Agents, the Dashboard, and Detection

How to use Wazuh: install the server, enroll an agent, reach the dashboard, and write and test a detection rule with wazuh-logtest.

Security news

Microsoft said this SharePoint bug was unlikely to be exploited. CISA just proved it wrong.

Microsoft rated SharePoint's CVE-2026-45659 unlikely to be exploited. CISA added it to the KEV catalog on July 1 after active exploitation. Patch and hunt now.

Security news

MFA did not stop the Azure CLI password spray. A retired login flow is why.

A password spray beat Conditional Access at 64 organizations by abusing ROPC, a retired Azure login flow that never triggers an MFA prompt. What to fix now.

Security news

AI keeps inventing web addresses that do not exist. Attackers now buy them first.

Unit 42 found attackers registering the fake web domains AI models hallucinate, turning a chatbot's answer into a phishing and supply chain threat.

Security news

An old bash trick makes AI coding agents run the commands they just blocked

AI coding agent guardrails fall to GuardFall, a bash trick that bypassed the command safety check in 10 of 11 open-source agents Adversa AI tested.

Security news

119 browser extensions hid malware inside images and fonts for two years

Microsoft pulled 119 malicious Edge extensions in the StegoAd campaign. Steganographic payloads, 2.6 million installs, and a 2FA lesson for defenders.

Security news

SimpleHelp CVE-2026-48558: Forged Login Drops Djinn Stealer

A maximum-severity SimpleHelp flaw, CVE-2026-48558, lets attackers forge a login and is now exploited to drop Djinn Stealer against cloud and AI keys.

Security news

You don't have to install this npm malware. Opening the folder in your editor runs it.

Two hijacked npm packages skip the install step entirely. They run when you open the project in VS Code, then steal developer, browser, and wallet logins.

Security news

This backdoor is named after your VMware and EDR tools. Your allowlist trusts it.

A Chinese APT called CL-STA-1062 ships its TinyRCT backdoor disguised as VMware and EDR agents. Why filename allowlists miss it, and what to hunt instead.

Security news

libssh2 flaw: a malicious SSH server can hijack the client connecting to it

libssh2's CVE-2026-55200 lets a malicious SSH server run code on the client that connects to it. No login, a public PoC is out, and there is no tagged fix yet.

Security news

A seized iPhone gave up everything. The MacBook beside it gave up nothing.

Cellebrite's UFED tool fully read a locked iPhone in Russian custody but failed on the encrypted MacBook seized beside it.

Security news

A rigged 7-Zip archive can erase the Windows warning on downloaded files, and there is no fix yet

A crafted RAR5 archive lets 7-Zip 26.02 strip the Mark-of-the-Web, defeating Windows SmartScreen warnings. No patch exists yet.

Security news

Polymarket's servers were never hacked. A poisoned vendor script still stole $3 million from users.

A compromised third-party vendor injected malicious code into Polymarket's site and stole nearly $3 million from users. The backend was never breached.

Explainers

What is a SIEM, in plain terms (and how it differs from a SOC and EDR)

What a SIEM is, what it actually does, and how it differs from a SOC, an EDR, and plain log management - explained by a team that runs one.

Security news

Open the wrong repo and Amazon Q ran its config file as you, AWS keys included

Amazon Q Developer ran a repo's MCP config file as you, with AWS keys attached. CVE-2026-12957 is patched in 1.69.0. What to verify and hunt for now.

Security news

A widely used PHP tool for making PDFs can hand attackers your internal files and cloud keys

php-weasyprint's attachment option fetched attacker-controlled URLs server-side, reaching internal services, cloud metadata, and local files.

Security news

Mistic backdoor writes nothing to disk and quietly sells your network to ransomware crews

Mistic is an in-memory backdoor that access broker KongTuke uses to hold footholds and sell them to Qilin and other ransomware crews. Here is where to catch it.

Security news

GitLab patched a no-login flaw that can hijack a user's session. Self-hosted servers are the exposed ones.

GitLab's June 24 release fixes 14 flaws, including an unauthenticated cross-site scripting bug.

Security news

A free GitHub account can push code as a trusted maintainer. Upgrading actions/checkout won't fix it.

Cordyceps lets anyone with a free GitHub account run code as a maintainer on 300+ repos. Why upgrading actions/checkout closes one door, not the others.

Security news

A new flaw lets attackers take over Quest NetVault backup servers, login or not

CVE-2026-7570 is a SQL-injection-to-remote-code-execution flaw in Quest NetVault Backup, rated 8.8. The login can be bypassed. Quest fixed it in 14.0.2.

Security news

The free plugin was clean. The paid update is what backdoored these WordPress sites.

Backdoored ShapedPlugin Pro updates stole admin logins and 2FA seeds from WordPress sites between April and June 2026. A password reset alone will not clear it.

Security news

Cisco Unified CM's flaw is being exploited. Whether it touches you depends on one default setting.

CVE-2026-20230 in Cisco Unified CM can reach root, but only where WebDialer is enabled, and it ships off. Check that before you panic-patch.

Security news

A guest virtual machine can read its host's memory through a flaw in QEMU's built-in networking

A patched flaw in libslirp, QEMU's usermode networking, lets a privileged guest virtual machine read gigabytes of host memory. Update to libslirp 4.9.2 now.

Security news

Add-ons for the OpenClaw AI assistant are stealing logins and running crypto scams

Malicious OpenClaw skills on the ClawHub marketplace steal credentials and hijack AI agents for crypto fraud, and some slip past the store's own scanner.

Security news

A new Mac backdoor is built to fool the AI that inspects it

macOS.Gaslight embeds fake AI system messages to make automated, LLM-assisted malware analysis abort.

Security news

PixelSmash: a video your server opens by itself can run an attacker's code

PixelSmash (CVE-2026-8461) lets a crafted video run code on FFmpeg-based media servers like Jellyfin and Nextcloud. Update to FFmpeg 8.1.2, then hunt.

Security news

Fake WhatsApp Invoice Installs ManageEngine RMM to Hijack PCs

A fake invoice on WhatsApp silently installs ManageEngine Endpoint Central, a legitimate remote-management tool, to hijack PCs.

Security news

A single Budibase app builder can read your server's secrets and take over every workspace

CVE-2026-54352 lets a Budibase workspace builder read the server's secret file via a crafted PWA zip and take over every workspace. Patch self-hosted to 3.39.9.

Security news

Washington export-controlled an AI for finding bugs. Your oldest code is the soft target.

The US used export-control powers to pull a frontier AI model that finds software bugs at scale.

Security news

Central Dogma: Public Default Secret Lets Nearby Attackers In

Central Dogma before 0.84.0 silently uses a public default secret when ZooKeeper replication runs without one set, letting nearby attackers seize the cluster.

Security news

Squid Squidbleed CVE-2026-47729: Credential Leak, 7.6 Is No Fix

Squidbleed (CVE-2026-47729) leaks memory from Squid proxies in default config, including login credentials. A public exploit is out, and 7.6 does not patch it.

Security news

Prinz Eugen Ransomware Encrypts Newest Files First, No Note

Prinz Eugen ransomware encrypts your most recently changed files first and drops no ransom note, defeating canary traps and note-based SOC alerts. What to do.

Security news

Your AI agent trusts your own computer. One web page turns that into a takeover.

Microsoft's AutoJack shows how one web page an AI browsing agent visits can run code on the host. The bug is a near miss. The architecture lesson is not.

Security news

Your Fortinet password reset won't lock the FortiBleed attacker out

CISA warned Fortinet users on June 18; reporting counted 86,644 affected devices. Resetting passwords is not enough: kill live sessions and fix the hashing.

Security news

Gravity SMTP CVE-2026-4020: Live SES and OAuth Keys Leak to All

Gravity SMTP's CVE-2026-4020 hands live Amazon SES, Google, and OAuth keys to unauthenticated visitors on 100,000 WordPress sites.

Security news

Operation Endgame Seized 106 SocGholish Servers, Entry Still Open

Operation Endgame seized 106 SocGholish servers and cleaned 14,971 WordPress sites. The takedown hit an access broker, not the entry vector.

Security news

Appium MCP XSS: A Test App Can Hijack the AI Agent Driving It

An XSS flaw in Appium's official MCP server let a hostile test app hijack the AI agent driving it and call its tools. Patch appium-mcp to 1.85.10 now.

Security news

EDR evasion is now a shipped product. Your agent's silence is the only alarm left.

The Gentlemen ransomware gang ships a standardized EDR killer to affiliates using BYOVD. Here is why driver-name hunting fails and what to detect instead.

Security news

WordPress Form Plugin CVE-2026-9843: Entry Deletes Files on View

CVE-2026-9843 lets an unauthenticated visitor plant a form entry that deletes WordPress files when an admin opens it.

Security news

Mastra's npm packages passed inspection, then turned hostile a day later

Attackers hijacked a dormant maintainer account to poison 140+ Mastra npm packages with a wallet-stealing payload.

Security news

Quarkus fixed a semicolon auth bypass in May. Its encoded cousin just reopened it.

Quarkus fixed a semicolon authorization bypass in May, but CVE-2026-50559 reopens it with URL-encoded characters. What to patch now and how to detect abuse.

Security news

JetBrains Hub CVE-2026-56141: Predictable 2FA Recovery Codes

JetBrains Hub generated predictable 2FA recovery codes (CVE-2026-56141, CVSS 9.8), allowing pre-auth account takeover.

Security news

Perry CVE-2026-53776: JWT Expiry Disabled, Revoked Tokens Work

CVE-2026-53776: Perry's bundled JWT helper hard-codes validate_exp = false, so expired and revoked tokens stay valid. Patch to 0.5.1166 and rotate signing keys.

Security news

Two NGINX bugs scored 9.2. On a default server you get a crash, not a shell.

F5's two critical NGINX flaws (CVE-2026-42530, CVE-2026-42055) score 9.2, but RCE needs ASLR off and a non-default config. Here is what to actually triage.

Security news

ClickFix is now shared attack infrastructure, and the lure is the wrong thing to detect

Three unrelated crews adopted ClickFix delivery in a single quarter. The lure keeps changing; the execution chain does not. Here is where to detect it.

Security news

RoguePlanet CVE-2026-50656: Defender Engine Privilege Escalation

RoguePlanet (CVE-2026-50656) is a public-exploit privilege escalation in Microsoft Defender's engine.

Security news

15 JetBrains Plugins Stole AI API Keys Across 70,000 Installs

Aikido found 15 JetBrains Marketplace plugins stealing AI API keys across 70,000 installs.

Security news

Joomla JCE CVE-2026-48907: Unauthenticated RCE, Exploited Now

Unauthenticated RCE (CVSS 10, CVE-2026-48907) in JCE, the most-installed Joomla editor. KEV-listed and exploited. Patch to 2.9.99.6 and hunt for webshells.

Security news

SprySOCKS: Linux Backdoor Adds a Self-Hiding Windows Kernel Driver

SprySOCKS, a China-nexus Linux backdoor, now ships a Windows kernel-driver variant that hides itself from the host. Here is where defenders can still catch it.

Security news

LiteSpeed's cPanel plugin gave shared-hosting tenants root twice in 2026. CageFS didn't help.

CVE-2026-54420 and CVE-2026-48172 let shared-hosting tenants reach root through the LiteSpeed cPanel plugin. Why CageFS isolation failed and what to patch now.

Security news

Awesome Motive's WordPress CDN backdoor only fired for logged-in admins. Your scanner missed it.

OptinMonster, TrustPulse and PushEngage served a backdoor that ran only for logged-in WordPress admins, evading visitor scanners. How to scope and hunt it.

Security news

SearchLeak: Prompt Injection Stole Microsoft 365 Copilot Data

SearchLeak chained prompt injection, an HTML render race, and Bing SSRF to steal Microsoft 365 Copilot data in one click. What it means for detection.

Ready to meet the Guardians?

Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.