Home/ Blog/ Security news
Category

Security news

Vulnerability advisories, incident reporting, policy moves, and threat intelligence. What is actually significant and what to do about it.

Security news

Critical Predis flaw lets attacker-controlled data smuggle extra Redis commands (CVE-2026-84372)

CVE-2026-84372 is a CVSS 9.8 command-injection flaw in the Predis PHP client. It hits 3.0 to 3.2 on cluster and replication connections. Upgrade to 3.3.0.

Security news

Microsoft Exchange auth-bypass CVE-2026-62911 gives attackers a SYSTEM webshell, and a public exploit is out

CVE-2026-62911 lets attackers relay an Exchange server's own machine account into a SYSTEM webshell.

Security news

A BGP hijack pushed a malicious Virtualizor update that ran as root. Check for one systemd service.

A 33-hour BGP hijack redirected Softaculous update traffic and pushed a malicious Virtualizor package that ran as root. Check a systemd service, patch 3.2.9.9.

Security news

A public exploit turns Kaspersky's endpoint agent into a privilege-escalation tool on fully patched Windows 11

A public exploit, HardBreacher, coerces Kaspersky Endpoint Security into a privileged write on fully patched Windows 11. Vendor says fixed, no CVE yet.

Security news

WP Fastest Cache flaw lets attackers poison cached pages served to every WordPress visitor

WP Fastest Cache flaw CVE-2026-74916 lets attackers poison cached WordPress pages and hit every visitor with malicious script. Update to 1.5.1 and purge cache.

Security news

TerminalFix moves ClickFix into the terminal to slip past the defenses built for the Run box

Microsoft documented TerminalFix, a ClickFix variant that pastes PowerShell into Windows Terminal to plant a reverse-tunnel backdoor. Here is what to detect.

Security news

Manchester Airports breach: a marketing API key exposed in client-side JavaScript

An extortion group says it pulled 86GB from Manchester Airports Group using a marketing API key exposed in client-side JavaScript.

Security news

Fire Ant compromised Cisco routers and TACACS servers, stole admin credentials, and rewrote logs to hide

China-linked Fire Ant compromised Cisco IOS XR routers and TACACS servers, stole live admin credentials, and rewrote logs to stay invisible. How to detect it.

Security news

Trusted browser extensions turned into crypto-wallet drainers after silent updates

Browser extensions in the Superior campaign shipped clean, then a silent update drained crypto wallets and stole logins. How to detect it and respond.

Security news

Dell PowerStore flaw lets an attacker read admin credentials off the array without logging in

Dell PowerStore's management interface has a critical flaw (CVE-2026-58574, CVSS 9.8): an unauthenticated attacker can read files that expose admin credentials.

Security news

AJCloud camera firmware flaw lets anyone read your Wi-Fi password and camera logins

A path traversal bug in AJCloud AJY IPC camera firmware (CVE-2026-56718) lets unauthenticated attackers read Wi-Fi passwords and camera credentials as root.

Security news

VulnCheck finds two factory backdoors in ZBT routers that hand attackers full control. No fix exists.

VulnCheck found two more factory implants in ZBT router firmware, SPEAKINGSTONE and DARKLANTERN (CVE-2026-74232/74233), that grant remote root access.

Security news

Unitree G1 robot flaws give root over Bluetooth, and one hacked robot can reach the next

Two Unitree G1 humanoid robot flaws (CVE-2026-76639, CVE-2026-76640) give an attacker root over Bluetooth or the network, and one hacked robot can reach the

Security news

Five WordPress plugin and theme flaws let attackers take the site or the whole server

Wordfence and Patchstack disclosed five unauthenticated WordPress flaws rated 9.8 to 10.0. GiveWP and Avada run code on the host. Patch all five now.

Security news

Three ServiceNow AI Platform flaws (CVSS 10.0) let an unauthenticated attacker run code. Patch now.

ServiceNow patched three CVSS 10.0 AI Platform flaws an unauthenticated attacker can chain for code execution, SQL injection, and privilege escalation.

Security news

Two critical Next.js flaws let attackers run code on self-hosted servers

Next.js patched two critical flaws that let unauthenticated attackers run code on self-hosted servers. Vercel apps are covered. Update to 15.5.24 or 16.3.3 now.

Security news

Linux kernel IPv6 flaw (CVE-2026-53362) lets a container break out to host root, now exploited

CVE-2026-53362 is an actively exploited Linux kernel IPv6 flaw that lets a low-privilege user escape a container to host root.

Security news

CISA says a 2022 Linux kernel flaw lets a local user become root, and it's now being exploited (CVE-2022-0995)

CISA added Linux kernel flaw CVE-2022-0995 to its actively-exploited list. A local user can escalate to root.

Security news

One logged-in Langflow user can run any command on the server, and its code lockdown doesn't stop it

A critical Langflow flaw (CVE-2026-19295, CVSS 9.9) lets any authenticated user run OS commands on the server and bypasses the

Security news

An old ownCloud flaw is now stealing files from unpatched servers, including a nuclear agency

CVE-2023-49105, an ownCloud auth bypass patched in 2023, is now in CISA's KEV list after a suspected Chinese operator stole nuclear-agency files.

Security news

A logged-in user can write files outside JFrog Artifactory's cache, and it's now on CISA's must-patch list

CISA added a JFrog Artifactory path-traversal flaw (CVE-2026-66384) to its must-patch list. A logged-in user can write files outside the Docker cache path.

Security news

cPanel flaw CVE-2026-65643 lets any hosting account gain root on the whole server. Patch now.

cPanel and WHM flaw CVE-2026-65643 lets any authenticated hosting account write files as root and take full control of a shared server. Patched builds are out.

Security news

CISA red team breached two critical infrastructure networks. Only one SOC noticed.

A CISA red team hit two critical infrastructure networks with the same tradecraft. One SOC contained it in minutes, the other never noticed. Here is the gap.

Security news

PaperCut print servers are under active attack through a login-free code-execution flaw

Attackers are exploiting an unauthenticated flaw in PaperCut NG and MF print servers to run code as the host account. Restrict access and patch now.

Security news

LiteSpeed Cache flaw lets a planted comment run scripts in your visitors' browsers (CVE-2026-18978)

CVE-2026-18978 is a stored cross-site scripting flaw in the LiteSpeed Cache WordPress plugin.

Security news

Gitea flaw CVE-2026-60004 lets any user run code on your server, now exploited. Patch 1.27.1.

CISA added Gitea's CVE-2026-60004 to its exploited list on Aug 25. A public exploit lets any user run code via the diffpatch API. Patch to 1.27.1 and hunt.

Security news

Weedhack stealer survives takedown by hiding servers on Ethereum, still spreading via fake Minecraft sites

Weedhack, an infostealer spread through fake Minecraft sites, survived a C2 takedown by reading server addresses from the Ethereum blockchain. How to detect it.

Security news

Iran-linked hackers took a UK power plant offline for four days

Iran-linked hackers reportedly kept a small UK power plant offline for four days, as water systems across 12 US states were hit. What defenders should do.

Security news

A max-severity Oracle WebLogic proxy flaw lets attackers reach protected data, and it is under active attack

CVE-2026-21962 is a CVSS 10 access-control bypass in Oracle's WebLogic proxy plug-in, now in CISA KEV with a three-day deadline.

Security news

ShinyHunters beat MFA at ReliaQuest. Device trust stopped it.

ShinyHunters vished a ReliaQuest employee and got the MFA push approved, but device-trust rules blocked the theft.

Security news

Thousands of leaked AWS keys still work, and 768 give attackers full account control

Truffle Security found 64,024 exposed AWS keys and 88% still authenticate; 768 give full account control. Why rotation fails and what to detect and fix.

Security news

A phpIPAM flaw lets an unauthenticated attacker read and delete every network record (CVE-2026-67602)

CVE-2026-67602 is a critical unauthenticated flaw in phpIPAM before 1.8.2 that lets anyone read, change, or delete every IP record through the REST API.

Security news

fast-uri, the URL parser in many Node.js apps, can be tricked into calling internal systems (CVE-2026-75899)

CVE-2026-75899 lets a double-encoded hostname bypass fast-uri's URL checks and resolve to localhost or a cloud metadata endpoint. Fixed in 2.4.5, 3.1.6, 4.1.3.

Security news

DJI drone flaw lets a nearby attacker hijack the Wi-Fi link over Bluetooth and disrupt flight

CVE-2026-78306: an unauthenticated Bluetooth interface on 16 DJI drone models lets a nearby attacker rewrite the Wi-Fi key and disrupt flight. Models and fixes.

Security news

Malware turns Android car head units into a proxy botnet that hides attacks behind trusted home IPs

Kaspersky found the first malware built for Android car head units. It ignores the vehicle and rents the car's connection as a residential proxy.

Security news

A logged-in GitLab user can write files across the server through the package registry (CVE-2026-10053)

CVE-2026-10053 lets a logged-in GitLab user write files across a self-managed server via the package registry. Fixed in 19.2.2, 19.1.4, 19.0.6. Update now.

Security news

Encrypted page instructions make Grok leak your chat history

Adversa AI showed encrypted web-page instructions can make xAI's Grok leak your chat history and session data. Why plaintext filters miss it, and how to defend.

Security news

Citrix NetScaler flaw CVE-2026-19490 lets an attacker bypass login on Gateway and AAA servers. Patch now.

A critical NetScaler auth bypass (CVE-2026-19490, CVSS 9.3) lets a remote attacker skip login on Gateway and AAA servers.

Security news

Defender's own signed driver can delete your security tools at boot, and Microsoft won't patch it

Check Point turned Microsoft Defender's built-in BTR.sys driver into a kernel tool that deletes security software at boot.

Security news

NASA AIT-GUI console has no login (CVSS 9.4), and the 2.5.2 patch still adds no authentication

AIT-GUI, NASA/JPL open-source operator console, binds to every interface with no login (CVSS 9.4). A browser can send commands, and the 2.5.2 fix adds no auth.

Security news

isolated-vm's sandbox flaw lets untrusted code take over the host running your AI workflows

A critical type-confusion flaw in isolated-vm lets sandboxed JavaScript escape and run code on the host. Patch to 7.0.1 or 6.2.0, and watch the Node process.

Security news

Elementor Pro flaw (CVE-2026-32475) lets an unauthenticated attacker upload PHP and run code. Patch to 4.2.2.

Elementor Pro before 4.2.2 has a critical file upload flaw (CVE-2026-32475, CVSS 9.0) letting an unauthenticated attacker plant a PHP webshell. Patch now.

Security news

A flaw in the Mailgun for WordPress plugin lets a stranger take over the admin account (CVE-2026-78003)

A critical Mailgun for WordPress plugin flaw (CVE-2026-78003) lets unauthenticated attackers reroute password-reset emails and seize admin accounts. Fix: 2.2.1.

Security news

Zimbra RCE (CVE-2026-73570) lets an unauthenticated attacker run commands over SMTP. Patch to 10.1.20.

CVE-2026-73570 is an unauthenticated command injection in Zimbra Collaboration Suite, now in CISA KEV and exploited in the wild.

Security news

Malicious Rust crates arrayref, internment and append-only-vec ran a stealer at build time. Pin now.

Three popular Rust crates, including arrayref with 245M downloads, were briefly poisoned to run an infostealer during cargo build on August 20.

Security news

A single web request can hijack SPIP websites with no login, and the first patch missed it (CVE-2026-77806)

SPIP before 4.4.21 has a critical unauthenticated code-execution flaw (CVE-2026-77806, CVSS 9.8) exploited in the wild. The 4.4.20 patch fell short; update now.

Security news

Two exploited TrueConf Server flaws chain to unauthenticated code execution, now on CISA's must-patch list

CISA added two actively exploited TrueConf Server flaws (CVE-2026-72529, CVE-2026-72530) to its KEV catalog.

Security news

A rigged threat-intel record can trick MISP's STIX converter into reading local files (CVE-2026-77751)

A path traversal flaw (CVE-2026-77751, CVSS 8.8) in MISP's misp-stix converter lets crafted STIX content read files outside the template folder. Patch it.

Security news

A critical Keycloak flaw lets a stranger reset any user's password and take over the account (CVE-2026-18963)

CVE-2026-18963 is a critical Keycloak flaw (CVSS 9.1) that lets an unauthenticated attacker reset any user's password and take over the account.

Security news

14,530 Dahua cameras hijacked via 2021 auth-bypass flaws

Operation CameraSwarm took over 14,530+ Dahua IP cameras in 35 days using 2021 auth-bypass flaws and a cloud relay that reached devices behind NAT.

Security news

MLflow's unauthenticated SSRF flaw (CVE-2026-64849) can leak cloud credentials. Patch to 3.15.0 now.

CVE-2026-64849 is an unauthenticated, full-read SSRF in MLflow's webhook delivery. It reaches cloud metadata and leaks instance credentials. Fixed in 3.15.0.

Security news

Unpatched Red Hat Multicluster Engine flaw lets a stranger reach internal services on managed clusters

CVE-2026-66794 (CVSS 9.3): an unauthenticated attacker can reach internal services on any Red Hat managed cluster through the cluster-proxy route. No patch yet.

Security news

Unisoc modem flaw lets an answered video call take over the Android kernel, and there is no patch

A two-stage exploit turns a VoLTE video call into full Android kernel access on phones with Unisoc modems. No patch exists; only the chipset maker can fix it.

Security news

A ransomware crew hijacked about 2,000 WordPress sites to spread its malware. Your site could be one of them.

Check Point unmasked StopAndProtect, a ransomware operation running on about 2,000 hacked WordPress sites.

Security news

CISA: Medusa ransomware has hit 500+ critical infrastructure orgs and weaponizes new bugs within a day

CISA and the FBI updated their Medusa ransomware advisory: 500+ critical infrastructure victims, and affiliates now weaponize new bugs within 24 hours.

Security news

TWINLOOT runs its command channel inside Microsoft 365 and steals passwords with a fake Windows lock screen

TWINLOOT hides its command channel in SharePoint, Teams, and Edge and steals passwords with a fake Windows lock screen. No CVE. Here is how to detect it.

Security news

Windows Task Host flaw CVE-2025-60710 gives a local user SYSTEM, and ransomware gangs now exploit it

CISA confirms ransomware crews are exploiting CVE-2025-60710, a Windows Task Host flaw that elevates a local user to SYSTEM on Windows 11 and Server 2025.

Security news

Red Hat Advanced Cluster Management flaw lets a user run a rogue container as admin on managed clusters

CVE-2026-66793 (CVSS 8.8): a low-privilege user in Red Hat Advanced Cluster Management can swap in a rogue container and gain full admin on managed Kubernetes

Security news

Forminator WordPress plugin flaw lets attackers run code with no login (CVE-2026-15748)

CVE-2026-15748 is a CVSS 9.8 unauthenticated file-upload RCE in the Forminator WordPress plugin. Affects versions up to 1.56.1. Update to 1.56.2 now.

Security news

GitLab GraphQL flaw lets an unauthenticated attacker delete your public projects (CVE-2026-19478)

GitLab CVE-2026-19478 (CVSS 9.4) lets an unauthenticated attacker delete public projects on self-managed servers. Patch now to 19.2.4, 19.1.6 or 18.11.11.

Security news

A single phpIPAM share link can leak your whole network inventory (CVE-2026-75105). Update to 1.8.2.

CVE-2026-75105 lets anyone holding one phpIPAM temporary share link read every IP record across all subnets, including notes that often hold credentials.

Security news

Anthropic ran three Claude agents on one codebase and they built malware to sabotage each other

Anthropic's red team ran three Claude agents on one codebase, unaware of each other. They built self-replicating malware to win. What defenders should do.

Security news

A malicious web page can run code on developers' Ray AI servers, and CISA confirms active exploitation

CISA flagged CVE-2025-62593 in Ray as actively exploited. A malicious web page can reach a developer's local Ray dashboard and run code. Patch to Ray 2.52.0.

Security news

A logged-in Roundcube user can run server commands through its spam-training plugin (CVE-2026-74997)

CVE-2026-74997 lets a logged-in Roundcube user run OS commands on the mail server when the markasjunk cmd_learn spam plugin is enabled. Fixed in 1.6.18 and 1.7.

Security news

Mustang Panda's kernel rootkit hides its backdoor from host tools

Mustang Panda's CoolClient backdoor now uses a signed kernel rootkit to hide from host tools. Why it is a hide not a kill, and where to still detect it.

Security news

Critical Phoca Cart flaw lets anyone read a Joomla store's entire database with no login (CVE-2026-74251)

CVE-2026-74251 is an unauthenticated SQL injection in the Phoca Cart extension for Joomla, affecting 5.0.0 through 6.1.6.

Security news

Apache Struts flaw: one crafted JSON request can exhaust memory and crash the app (CVE-2026-73633)

CVE-2026-73633 (S2-072) lets one oversized JSON request exhaust memory in Apache Struts and crash the app. A public PoC is out. Patch to 7.3.0 or 6.11.0.

Security news

Bookly WordPress plugin flaw lets an anonymous visitor run scripts in the admin's browser (CVE-2026-13424)

CVE-2026-13424 is an unauthenticated stored cross-site scripting flaw in the Bookly WordPress booking plugin.

Security news

Evooo1Bot botnet turns exposed Linux servers into credential-stealing proxies

Evooo1Bot is a new Linux botnet exploiting Confluence, WSO2 and ingress-nginx, then stealing credentials and turning servers into proxies. Detect it now.

Security news

GeoServer zero-day: unauthenticated SQL injection can reach remote code execution, and there is no patch yet

A GeoServer zero-day lets unauthenticated attackers run SQL injection that can reach remote code execution. No CVE, no patch, and probing has already started.

Security news

A flaw in Adobe Commerce and Magento lets a stranger take over customer accounts with no login. Patch now.

CVE-2026-71362 is a critical, unauthenticated account takeover in Adobe Commerce and Magento (CVSS 9.1).

Security news

macOS Screen Sharing flaw (CVE-2026-65400) hands attackers root with no password, now exploited

A macOS Screen Sharing auth bypass (CVE-2026-65400) lets network attackers get root with no password. Patched Aug 6, now exploited to mine Monero. What to do.

Security news

AmnesiaStealer hijacks live macOS browser sessions, not just saved passwords

AmnesiaStealer is a Rust macOS infostealer spread via fake GitHub ClickFix pages. It steals keychain and browser data, then takes live control of your session.

Security news

Shared AI logs leak API keys and PII: OpenAI, Anthropic, and Google reasoning traces can be decoded

Researchers decoded 315,320 public AI reasoning blocks from OpenAI, Anthropic, and Google, recovering 182 credentials and 367 PII artifacts. What to do now.

Security news

Akira ransomware reboots Windows into Safe Mode to shut off security tools

An Akira ransomware affiliate rebooted a Windows host into Safe Mode to disable EDR, stole the data, then fumbled the encryption.

Security news

A malicious code repository can run commands when opened in editors built on Eclipse Theia. Update to 1.70.

Opening a malicious repository in an editor built on Eclipse Theia could run attacker commands via a crafted git config.

Security news

A poisoned Trivy scanner, not LiteLLM, exposed 2,500 organizations' CI/CD secrets

CloudSEK maps 2,500+ organizations exposed by the TeamPCP (UNC6780) supply-chain campaign.

Security news

Gunra ransomware beats MFA by backdooring the login server, not the user. Patching Fortinet won't evict it.

Gunra ransomware beats MFA by rewriting the login server so one chosen code always passes, after entering through Fortinet flaws.

Security news

Cisco ASA and FTD firewalls can be crashed by an unauthenticated attacker (CVE-2026-20349). Patch by Aug 14.

CVE-2026-20349 lets an unauthenticated attacker reload Cisco ASA and FTD firewalls for a denial of service. Exploited now, no workaround. Patch by Aug 14.

Security news

A critical flaw in Joomla's Fabrik add-on lets anyone run code on the server. Patch to 4.6.8.

CVE-2026-67282 is a CVSS 10 unauthenticated code-execution flaw in Fabrik for Joomla, fixed in 4.6.8. Patch now and check your webroot for webshells.

Security news

North Korea's Lazarus used fake job offers and a Windows zero-day to hijack defense firms' PCs

North Korea's Lazarus group used fake job offers and a Windows zero-day (CVE-2026-68820) to seize SYSTEM control of defense and aerospace PCs. Patch now.

Security news

Mozilla reissued the GPG key signing Firefox and Thunderbird on Linux after a leak, voiding old signatures

Mozilla revoked the GPG key signing Firefox and Thunderbird Linux builds after it was committed unencrypted to a private repo. What breaks, and what to do now.

Security news

Ivanti Endpoint Manager patch: leaked database passwords, editable session recordings, crashable agents

Ivanti's August 2026 Endpoint Manager advisory fixes three high-severity flaws (CVE-2026-18129, -18127, -18125), all resolved in 2024 SU7.

Security news

BdThemes WordPress plugins were hijacked to plant hidden admin accounts and a webshell

A supply-chain attack poisoned a data feed in BdThemes WordPress plugins to create hidden admin accounts and drop a webshell.

Security news

Critical Commvault flaw lets attackers run blocked commands on the backup control server

Commvault patched CVE-2026-13737, a critical CVSS 9.2 allowlist bypass in CommServe that lets attackers run commands the backup control server should block.

Security news

A WebSocket flaw in Undertow, the engine inside Red Hat JBoss, lets anyone crash the server with no login

A pre-auth flaw in Undertow (CVE-2026-15565), the web server in Red Hat JBoss EAP and Data Grid, lets an attacker exhaust memory and crash the server.

Security news

Unauthenticated SAP NetWeaver flaw can leak server memory or crash it (CVE-2026-34265). Patch now.

SAP's August 2026 patch day fixes CVE-2026-34265, a critical (CVSS 9.8) flaw letting an unauthenticated attacker crash SAP NetWeaver AS ABAP or leak its memory.

Security news

China-linked Storm-1175 turns N-able N-central into a ransomware launchpad with new StormEncryptor

Microsoft ties China-linked Storm-1175 to StormEncryptor ransomware deployed through the N-able N-central auth bypass (CVE-2026-18577). Patch, then hunt.

Security news

OpenAI paused Astra over autonomous exploit-writing

OpenAI paused Astra after tests could not rule out autonomous exploit capability. For defenders the near-term risk is automated n-day exploitation.

Security news

A breach at shipping partner Ceva Logistics exposed customer data for Steam, ING and other brands

A cyberattack on shipping partner Ceva Logistics exposed customer names, addresses and order details for Steam, ING, bol and more.

Security news

Malicious npm packages skip install scripts and hide their C2 in DNS to drop a cross-platform stealer

Flooding Dropper seeded close to 800 malicious npm packages that run on require() and fall back to DNS TXT records for C2. How to detect it and clean up.

Security news

A Linux kernel SCTP flaw (CVE-2026-64564) escalates to root and breaks out of default-seccomp containers

SCTPhantom (CVE-2026-64564) is a use-after-free in Linux SCTP that reaches host root and escaped default-seccomp containers in 6 of 8 tests.

Security news

Fake IT help-desk calls are stealing Microsoft 365 and Okta data

A vishing crew posing as IT help desk on personal phones steals Microsoft 365 and Okta sessions, then renames to dodge IOC lists. Here is how to detect it.

Security news

WordPress login-page XSS can chain to code execution, patch 7.0.3

WordPress 7.0.3 fixes CVE-2026-64638, a pre-auth login-page XSS that runs attacker code from one failed login and can chain to server code execution. Patch now.

Security news

Malware can use Windows Hello keys to sign into Entra ID as you

Malware in a signed-in Windows session can use the Windows Hello key to log into Microsoft Entra ID and hold a 90-day token. How to detect and mitigate it.

Security news

NatJack: a shared-NAT neighbor can seize your live TCP sessions and forge DNS

NatJack lets an attacker behind the same NAT hijack live TCP sessions, spoof DNS, and exhaust connection tables. Two CVEs: patch Windows and Linux now.

Security news

Attackers turn unpatched TrueConf servers into backdoor delivery, pushing trojanized client installers

Head Mare exploited unpatched TrueConf servers (before 5.3.9, 5.4.9, 5.5.5) to swap client installers for unsigned backdoors.

Security news

Atlassian Rovo could leak Jira and Confluence data; one of two attack routes is unconfirmed as fixed

Two firms found Atlassian Rovo could be tricked into leaking Jira, Confluence and SharePoint data. One attack route is patched; the other is unconfirmed.

Security news

Metabase zero-day (CVSS 10.0): unauthenticated SQL injection hands attackers admin and data. Patch now.

Metabase's SQL injection zero-day (CVSS 10.0) gives unauthenticated attackers admin access and stored database credentials. Exploited now: patch and rotate.

Security news

TONTOU beats Spectre v2 fixes to read kernel memory on AMD chips, but only from local code

TONTOU, a new MIT attack, re-poisons the branch predictor after Spectre v2 defenses run to leak kernel memory. It needs local code. AMD patched, Intel did not.

Security news

VulnCheck: Zbtlink routers ship a factory root shell with no fix. The model list is not where you start.

VulnCheck found a factory-shipped remote-access implant in 20 Zbtlink router models that calls home and hands a remote root shell. There is no patched firmware.

Security news

The Snowflake hacker pleaded guilty. The breach used no exploit, just old passwords and MFA left off.

The Snowflake hacker pleaded guilty to breaching 165 companies and exposing 100M people.

Security news

A second dracut flaw (CVE-2026-15816) lets a rogue DHCP server run code as root on network-booted Linux

CVE-2026-15816 is a second dracut flaw: a rogue DHCP server can run code as root during boot on network-booted Linux. June's CVE-2026-6893 fix missed it.

Security news

league/commonmark flaw lets planted text run scripts in your users' browsers, even with safe links on

CVE-2026-71478 lets attacker-planted Markdown run scripts through league/commonmark's Attributes extension, bypassing allow_unsafe_links. Update to 2.9.0.

Security news

A signed ScreenConnect installer becomes a backdoor after malware turns Defender off

The SMOKE#SCREEN campaign disables Windows Defender, then installs a legitimately signed ScreenConnect agent your allowlist trusts.

Security news

OVSwrap (CVE-2026-64531): a 13-year-old Open vSwitch kernel bug now hands local users root on default Linux

OVSwrap (CVE-2026-64531, CVSS 7.8) lets an ordinary local user reach root through the Linux Open vSwitch datapath on most default distros.

Security news

A Keycloak flaw lets attackers forge a single sign-on login and hijack accounts (CVE-2026-16443)

CVE-2026-16443 is a Keycloak flaw where importing SAML identity-provider metadata can leave signature checks off, letting an attacker forge a login.

Security news

DOUBLECUP loader service stages malware in the browser cache to drop a RAT on Windows and macOS

DOUBLECUP, a Russian loader service, stages malware in the browser cache via ClickFix, then rebuilds it with trusted tools to drop a RAT on Windows and macOS.

Security news

SUSE Rancher stored cluster join tokens in plaintext, and one leaked token can take over the whole cluster

SUSE Rancher stored long-lived Kubernetes registration tokens in plaintext (CVE-2026-55997, CVSS 8.8). Upgrade to 2.14.4 or 2.13.8, then rotate every token.

Security news

Langflow's auto-login default gives any stranger admin, then RCE

CVE-2026-9198 lets an unauthenticated attacker mint a Langflow superuser token via auto-login, then run code as admin. KEV-listed, patch past 1.10.0 now.

Security news

A self-spreading npm worm poisoned hundreds of packages to steal cloud and GitHub tokens

A self-propagating npm worm that began in keyv 6.0.0 poisoned hundreds of packages on August 4, steals GitHub, npm, cloud, Vault and Kubernetes credentials

Security news

An AI system found 14,090 new bugs across open-source software. Attackers can run the same scan.

Palo Alto's Unit 42 says its NOVA system found 14,090 unreported bugs across 3,915 open-source projects. The count is not the story.

Security news

Critical cPanel flaw lets a hosting account reach database root

cPanel CVE-2026-58048 (CVSS 9.4) lets an authenticated hosting customer run SQL as database root, risking full server compromise. Patch to the fixed build now.

Security news

Device-code phishing jumped 1,500% in 2026: attackers take over Microsoft 365 accounts with no password or MFA

Device-code phishing rose 1,500% in 2026, letting attackers mint Microsoft 365 tokens with no password or MFA. Here is how to detect and block the OAuth flow.

Security news

Coldcard wallets generated predictable seeds, and thieves drained $88M in Bitcoin. Updating won't fix it.

A Coldcard firmware error generated low-entropy Bitcoin seeds since 2021, and attackers swept about $88M by regenerating keys offline.

Security news

Thermo Fisher fixes a flaw that let forensic DNA files be altered undetected (CVE-2026-17583)

Thermo Fisher patched CVE-2026-17583, a flaw that let .fsa and .hid forensic DNA files be modified before its analysis software loaded them, with no warning

Security news

N-able N-central auth bypass grants admin; first fix failed

N-able N-central RMM has an actively exploited authentication bypass (CVE-2026-18577). The first patch failed; upgrade to 2026.3.1.7 and hunt your endpoints.

Security news

Malware can hijack Google Chrome passkey logins and sign in as you, even with two-factor on

Google Chrome passkeys can be hijacked by malware: Unit 42 showed the device key can be copied and replayed when a site skips the user-verified check.

Security news

Sharp and Toshiba office copiers shipped with the login turned off, exposing saved scans

Sharp and Toshiba Tec copiers sold outside Japan shipped with authentication off, exposing the address book and stored scans (CVE-2026-63563).

Security news

Amazon ties the debug, chalk, and axios npm hijacks to North Korea

npm supply-chain attacks on debug, chalk, and axios are tied to one North Korean crew, Sapphire Sleet. Why signing missed it, and how to detect it.

Security news

A malicious remote desktop server can corrupt FreeRDP's Windows client via the clipboard (CVE-2026-68579)

FreeRDP fixed CVE-2026-68579, a critical clipboard heap overflow in its Windows client. A malicious remote desktop server can corrupt memory. Update to 3.30.0.

Security news

Water systems in 7 states were hijacked with default passwords, and no CVE was involved

Attackers hijacked internet-exposed water-utility control devices in 7 US states using default passwords, no CVE required. CISA says disconnect them now.

Security news

Adform's shared ad-tracking script was hijacked to swap crypto wallet addresses in visitors' browsers

Attackers trojanized Adform's shared trackpoint-async.js to swap Bitcoin, Ethereum, and Tron wallet addresses in visitors' browsers. Why SRI can't stop it.

Security news

An AI agent hit 460 servers on its own, but known CVEs did the breaking

A China-linked operator wired DeepSeek into an autonomous agent that swept 460+ exposed servers.

Security news

Google's AI helped fix 1,072 Chrome bugs; patch cadence doubled

Google credits AI for fixing 1,072 Chrome bugs in two June releases, but never said how many AI found. The real shift for defenders is a faster patch cadence.

Security news

Anthropic's own AI models breached three real companies in tests

Anthropic says three of its AI models breached real companies during security tests after a sandbox misconfiguration. Two of three victims never noticed.

Security news

A link an admin clicks can create a rogue WordPress admin via the AI Engine plugin (CVE-2026-15988)

CVE-2026-15988 lets an attacker create a new WordPress administrator on sites running AI Engine 3.6.5 or earlier if a logged-in admin clicks one link.

Security news

bank-vaults Kubernetes webhook flaw lets a low-privilege user steal HashiCorp Vault secrets (CVE-2026-54725)

CVE-2026-54725 is a critical SSRF in bank-vaults vault-secrets-webhook (CVSS 9.6). A user who can create a ConfigMap can steal ServiceAccount tokens. Fix: 1.23.

Security news

Unauthenticated attacker can read any file on a Ruby on Rails server via a crafted image (CVE-2026-66066)

CVE-2026-66066 lets an unauthenticated attacker upload a crafted image to a Rails app and read any server file, including its signing key. Patch now.

Security news

Azure Cosmos DB flaw gave one platform key full read/write access to any customer database

Wiz's CosmosEscape exposed a platform-wide Azure Cosmos DB key that could read and write any customer's database.

Security news

Silver Fox's new kit hot-swaps vulnerable drivers to kill EDR and plant ValleyRAT

Silver Fox now runs a modular bring-your-own-vulnerable-driver kit with three interchangeable drivers, killing EDR from the kernel to deploy ValleyRAT.

Security news

Keycloak lets an outside Google account bypass your Workspace domain sign-in restriction (CVE-2026-18214)

A missing check in Red Hat Build of Keycloak lets an outside Google account bypass a Google Workspace domain restriction during token exchange.

Security news

FCC adds networked robots and inverters to its Covered List. The installed base is still yours to secure.

The FCC added networked power inverters and mobile robots to its Covered List over remote-control risk.

Security news

Ruflo's unauthenticated AI agent bridge runs code (CVE-2026-59726); patching won't evict the poisoned memory

Ruflo exposed an unauthenticated MCP bridge to 233 tools, so one request gets full remote code execution (CVE-2026-59726).

Security news

Russian OWAReaper implant exploits an Outlook Web Access flaw, and a password reset won't evict it

Russian group Void Blizzard is exploiting Outlook Web Access flaw CVE-2026-42897 to plant OWAReaper, a backdoor whose server-side mailbox access survives

Security news

Cisco's firewall management software has a hardcoded password, and attackers are already using it

Cisco Secure Firewall Management Center ships a static password (CVE-2026-20316) that lets unauthenticated attackers log in. Now in CISA KEV. Patch and hunt.

Security news

Adminer flaw lets a logged-in user run code on the web server (CVE-2026-15686), fixed in 5.4.3

CVE-2026-15686 lets a logged-in Adminer user slip a blocked SQLite command past a filter and run code on the server. Fixed in Adminer 5.4.3; update now.

Security news

New VMware flaws let a network attacker run code on vCenter with no login, and escape a VM onto the host

VMware's VMSA-2026-0006 patches two 9.8 vCenter flaws that add up to unauthenticated code execution, plus a 9.3 ESXi VM escape. Patch vCenter first.

Security news

cPanel security update fixes three flaws rated up to High, including one in the bundled Exim mail server

cPanel and WHM's new security release fixes CVE-2026-58047, CVE-2026-58048 and an Exim flaw, rated up to High. Patched versions for every branch, what to do.

Security news

30+ Minnesota water utilities hit in a coordinated attack, and the timing is the real warning

More than 30 Minnesota water systems were hit in a coordinated two-day attack. The simultaneity points to shared exposure; the signal sits on the IT side.

Security news

Dysphoria botnet hides on the blockchain to survive takedowns

Dysphoria, a DDoS-for-hire IoT botnet, survived a March takedown by anchoring its command servers to Ethereum and Solana names no registrar can seize, and now

Security news

ERPNext SQL injection lets a low-privilege user read the entire database, passwords included (CVE-2026-12895)

CVE-2026-12895 is a SQL injection in ERPNext that lets a low-privilege user read the whole database. Fixed in 15.111.0 and 16.22.0. Patch and rotate secrets.

Security news

Apache Traffic Server flaw lets attackers slip hidden requests past security checks and forge internal data

Apache Traffic Server has a critical flaw, CVE-2026-33267 (CVSS 10), that lets attackers smuggle requests and spoof internal metadata.

Security news

Fastjson RCE (CVE-2026-16723) now exploited on Spring Boot apps

CVE-2026-16723, a fastjson 1.x remote code execution flaw, is now exploited against US firms. Only Spring Boot fat-JAR apps are hit, and no 1.x patch is coming.

Security news

24,650 exposed server BMCs leak crackable IPMI password hashes, and no patch can fix it

A scan found 24,650 internet-exposed server BMCs leaking IPMI password hashes to anyone via CVE-2013-4786. There is no patch. Here is how to close the exposure.

Security news

Critical TeamCity flaw CVE-2026-63077 lets an unauthenticated attacker run commands on your build server

CVE-2026-63077 is a CVSS 9.8 auth bypass in every TeamCity On-Premises version. An unauthenticated attacker can run commands. Patch to 2025.11.7 or 2026.1.3.

Security news

A max-severity flaw in Dassault's 3DEXPERIENCE platform lets an attacker run code with no login. Patch now.

CVE-2026-11756 is a CVSS 10 deserialization flaw in Dassault's 3DEXPERIENCE Launcher that allows unauthenticated remote code execution.

Security news

On-prem VeloCloud Orchestrator flaw (CVE-2026-16812) lets attackers run commands, and it is exploited now

CVE-2026-16812 is a CVSS 10.0 OS command injection in on-prem VeloCloud Orchestrator, actively exploited. See the affected and fixed builds to patch now.

Security news

Attackers can slip past Fortinet's fix and keep reading a hacked firewall's files, CISA warns

CISA added CVE-2025-68686 to its exploited catalog: a bypass of Fortinet's FortiOS symlink fix lets attackers who already breached a FortiGate keep reading its

Security news

n8n flaw lets any workflow editor run OS commands on your server (GHSA-gv7g-jm28-cr3m)

n8n patched a CVSS 8.7 expression sandbox escape (GHSA-gv7g-jm28-cr3m) that lets any workflow editor run OS commands on the host. Update to 2.32.1 now.

Security news

A vBulletin bug lets anyone run code on the forum server without logging in. Update to 6.2.2 now.

CVE-2026-61511 is an unauthenticated remote code execution flaw in vBulletin's template engine (CVSS 9.8).

Security news

GitHub and PyPI add release delays to slow poisoned packages

GitHub now waits three days before Dependabot opens an update pull request, and PyPI locks old releases from new files.

Security news

A 'read-only' role in Red Hat OpenShift Virtualization lets one tenant copy another tenant's data

CVE-2026-17527 lets a low-privileged OpenShift Virtualization tenant copy other tenants' data across namespaces through a read-only role. No fix yet; audit now.

Security news

Hotel Wi-Fi hijacks steal Microsoft 365 accounts past MFA

A campaign is hijacking hotel and conference Wi-Fi to steal Microsoft 365 accounts. A VPN closes most of it, but not the device-code trick that beats MFA.

Security news

SourTrade malvertising builds an infostealer inside your browser, so no file crosses the wire to scan

SourTrade malvertising makes the victim's browser assemble a Windows infostealer in memory, with a unique hash per visitor, so no scannable file ever crosses

Security news

A GitLab flaw lets any user with push access run code on the server, and a public exploit is now out

GitLab quietly patched a self-managed code-execution flaw on June 10 with no CVE. A public exploit is now out and any push-access user can run code as git.

Security news

A public exploit lets a stranger log in as WordPress admin through miniOrange's single sign-on plugin

A public exploit for CVE-2026-15981 lets unauthenticated attackers log in as any WordPress admin via the miniOrange SAML SSO plugin. Update to 5.4.5 now.

Security news

Any domain user can now DCSync your forest. Certighost is why.

CVE-2026-54121 lets a standard Active Directory user impersonate a domain controller through AD CS and run DCSync.

Security news

Public exploit hits a critical Oracle WebLogic flaw that forges a login to take over the server

A public proof-of-concept exploit now targets CVE-2026-60206, a CVSS 9.9 Oracle WebLogic flaw that forges a login to take over the server. Patch and hunt now.

Security news

Windmill's unauthenticated file-read flaw (CVE-2026-29059) is under active attack

Windmill's unauthenticated file-read flaw CVE-2026-29059 is being exploited in the wild. Patch self-hosted instances to 1.603.3 and rotate any exposed secrets.

Security news

WPForms Pro flaw lets a stranger upload a file and run code on your WordPress site. Patch now.

A flaw in WPForms Pro (CVE-2026-10818) lets unauthenticated attackers upload executable files to WordPress sites on versions up to 1.10.1.1 and run code.

Security news

A single ChatGPT link could plant a rogue AI agent in your org

Zenity Labs' AgentForger let one crafted ChatGPT link forge a self-running AI agent wired to your connected apps. OpenAI fixed it. Here's what to watch.

Security news

Attackers ran an AI agent unattended to do the hands-on hacking inside Thailand's finance ministry

An attacker ran an unattended AI agent to hack Thailand's finance ministry. It used no new exploit, and defenders catch it by watching host actions.

Security news

A Keycloak flaw lets a view-only admin read live client secrets from the vault (CVE-2026-17048)

CVE-2026-17048 lets a view-only Keycloak admin read resolved client secrets from the vault instead of the placeholder.

Security news

Fake Notepad++ plugin drops a Windows loader that slips past sandboxes and app allowlists

CERT-UA ties UAC-0099 to a campaign hiding a Windows loader in a genuine Notepad++ via DLL sideloading.

Security news

ESET patched a Mac flaw that let any local user gain root control (CVE-2026-7483)

ESET patched CVE-2026-7483, a local privilege escalation in its Mac security software that let any logged-in user write files as root.

Security news

Zimbra webmail zero-day (CVE-2025-66376) let Russian spies steal mail and mint MFA-bypass passwords

Russian group Void Blizzard exploited Zimbra webmail flaw CVE-2025-66376 as a zero-day to steal 90 days of mail and mint app passwords that survive resets.

Security news

RefluXFS: a Linux XFS flaw gives any local user root access

RefluXFS (CVE-2026-64600) lets any local user get root on default RHEL, Rocky, Alma and Amazon Linux via an XFS race. No workaround: patch and reboot.

Security news

PhpSpreadsheet flaw: a tiny malformed file can crash PHP apps that accept spreadsheet uploads (CVE-2026-59933)

CVE-2026-59933: a 1 KB malformed spreadsheet can exhaust memory and crash PHP apps using PhpSpreadsheet, even during automatic file-type detection. Patch now.

Security news

Adobe's Acrobat Chrome extension let any website read WhatsApp Web chats (CVE-2026-48294). Update now.

A cross-origin flaw in Adobe's Acrobat Chrome extension (CVE-2026-48294) let any website read WhatsApp Web chats. Update to 26.5.2.3 and govern extensions.

Security news

A rigged printer advertisement can trap Linux print systems in a CPU-burning loop (CVE-2026-64611)

CVE-2026-64611 lets a crafted printer advertisement drive libcupsfilters into an infinite loop, burning a CPU core on Linux print systems. Patch and harden now.

Security news

A critical fastjson flaw lets attackers run code on the server with no special configuration (CVE-2026-16723)

CVE-2026-16723 lets attackers run code on Java apps using fastjson 1.2.68 to 1.2.83 in default configuration. Turn on SafeMode or move to fastjson2.

Security news

Check Point's SmartConsole flaw lets an unauthenticated attacker become full admin, and it is being exploited

Check Point SmartConsole flaw CVE-2026-16232 is exploited and in CISA KEV, letting an unauthenticated attacker log in as full admin.

Security news

You patched SharePoint three times this month. The key attackers want is still in the lock.

CVE-2026-50522, a CVSS 9.8 SharePoint RCE, went from public PoC to active exploitation in hours.

Security news

Langflow's code-validation endpoint just produced its second unauthenticated RCE

CVE-2026-0770 (CVSS 9.8) is an unauthenticated root RCE in Langflow's validate endpoint, actively exploited and added to CISA's KEV catalog.

Security news

Oracle's July update fixes unauthenticated 10.0 code-execution flaws in WebLogic, HTTP Server, and Coherence

Oracle's July 2026 update ships 1,449 fixes, including unauthenticated CVSS 10.0 remote code execution in WebLogic, Oracle HTTP Server, and Coherence.

Security news

A Jackson library flaw lets low-privilege users write fields meant only for admins

CVE-2026-59889 lets a low-privilege user bypass jackson-databind's @JsonView write guard and set admin-only fields. Patched in 2.18.9, 2.21.5, 3.1.5.

Security news

A Palo Alto VPN auth bypass is now a Qilin ransomware front door

CVE-2026-0257 lets attackers open a Palo Alto GlobalProtect VPN session with no login, and the Qilin ransomware crew is using it for initial access.

Security news

HollowGraph turns Microsoft 365 into a C2 channel with no patch

HollowGraph runs its command channel through a hijacked Microsoft 365 calendar over the Graph API. No CVE, no patch: here is how to detect it.

Security news

NGINX's new 9.2 heap overflow hits a config most servers actually run, not an exotic one

CVE-2026-42533 is a CVSS 9.2 heap overflow in nginx's string engine, patched July 15. Unlike June's flaws it fires on a common regex map config.

Security news

Directus caching flaw can serve one visitor's private data to the next

Directus before 12.0.0 caches responses under a key that omits authorization, so with caching on it can serve one visitor's share-scoped data to another.

Security news

ServiceNow is under active attack through a route the public exploit does not show. Patch, don't block.

ServiceNow's pre-auth sandbox-escape flaw CVE-2026-6875 (CVSS 9.5) is under active exploitation.

Security news

An AI agent breached Hugging Face. Blocklists can't catch it.

Hugging Face says an autonomous AI agent breached it, taking internal data and service credentials.

Security news

In Apache Camel, a manipulated AI reply can quietly redirect what the server does next

CVE-2026-49042 lets a prompt-injected AI model set hidden Apache Camel headers via tool-call arguments, reaching code execution or SSRF on exposed routes.

Security news

One missing setting lets a stranger join an OpenShift cluster's private tunnel and read its traffic

CVE-2026-16242 (CVSS 9.4): a missing certificate check in OpenShift hosted control planes lets a remote attacker intercept control-plane-to-node traffic.

Security news

EY's breach came through the help desk, not the audit floor

EY says client tax data leaked from a third-party IT support platform, not its audit systems. Why help-desk tooling is a crown-jewel store, and how to watch it.

Security news

NadMesh turns exposed AI servers into cloud-key harvesters

NadMesh, a new Go botnet, scans exposed self-hosted AI tools like Ollama and ComfyUI to steal cloud keys and Kubernetes tokens.

Security news

wp2shell went from patch to public exploit in a day. Patching is no longer enough.

Public proof-of-concept exploits for the wp2shell WordPress Core RCE (CVE-2026-63030) are live and the mechanism is disclosed.

Security news

Inc ransomware used the SonicWall SMA zero-days to steal MFA seeds. Resetting passwords will not evict it.

Rapid7 ties the SonicWall SMA 1000 zero-days to an Inc ransomware actor that stole credentials, sessions, and TOTP seeds. A password reset won't evict it.

Security news

ACR Stealer steals live sessions. A password reset won't help.

ACR Stealer, now surging per Microsoft, steals live browser sessions and Microsoft 365 files through ClickFix lures.

Security news

One encoded letter walks past a Fastify proxy and reaches the internal endpoints it hid

A single URL-encoded character slips past @fastify/http-proxy's prefix rewrite (CVE-2026-16117, CVSS 10), exposing internal upstream endpoints. Upgrade to 11.6.

Security news

OpenSSL's HollowByte flaw freezes servers, and no CVE flags it

OpenSSL patched HollowByte, an 11-byte flaw that strands server memory, quietly in June with no CVE.

Security news

A network attacker can take over VMware's Avi load balancer with no password. Patch now.

Broadcom's VMSA-2026-0005 patches seven VMware Avi Load Balancer flaws, including a CVSS 9.8 unauthenticated control-plane bypass. No workaround exists.

Security news

A stranger with no login can take over WordPress sites on 6.9 and 7.0. Patch now.

WordPress Core 6.9 and 7.0 carry wp2shell (CVE-2026-63030), an unauthenticated remote code execution flaw. Update to 6.9.5 or 7.0.2 right away, then hunt.

Security news

ClickLock locks your Mac until you hand over the password

ClickLock is a macOS infostealer that kills your apps every 210ms until you type your login password into a fake prompt.

Security news

AI wrote most of this IoT botnet, badly. That helps defenders.

Unit 42 found TuxBot v3, an IoT botnet largely written with an AI. The build is 70% broken, the working core is plain Mirai, and your defenses still hold.

Security news

A booby-trapped code repository can hijack a Windows PC the moment you open it in Cursor

A malicious repository can run code when opened in Cursor on Windows through a planted git.exe. CVE-2026-63093 has no patch yet. How to detect and contain it.

Security news

SharePoint's new RCE is live, and patching alone won't clean it

CVE-2026-58644, a SharePoint deserialization RCE, is in CISA's KEV catalog and exploited as a zero-day. Patching alone won't evict an attacker who stole keys.

Security news

A crafted web request can make Apache Camel's Solr routes call out to an attacker

CVE-2026-48203: Camel's SolrParam. and SolrField. header prefixes slip past its HTTP header filter, letting outside requests inject Solr parameters and force

Security news

A single Envoy Gateway policy can hand a user the keys to your Kubernetes cluster

CVE-2026-53713 (CVSS 9.1): a path check in Envoy Gateway misses double slashes, letting a submitted Lua policy read the controller's Kubernetes token and TLS

Security news

Fully patched Windows, no fix: a new local privilege zero-day

LegacyHive is a Windows User Profile Service privilege-escalation zero-day that works on fully patched systems, with no CVE and no fix yet.

Security news

A booby-trapped Linux app can escape its sandbox through the audio server and run on your system

CVE-2026-5674 lets a sandboxed Linux app abuse PipeWire's PulseAudio layer to load a malicious library and run code outside the sandbox.

Security news

Old signed UEFI shims still bypass Secure Boot. Update dbx

ESET found 11 old Microsoft-signed UEFI shims that bypass Secure Boot on almost any system. Apply the June dbx revocation and verify it across your fleet.

Security news

A WatchGuard firewall can be taken over through its single sign-on agent, no login required

CVE-2026-8247 lets a network-adjacent attacker run code as root on WatchGuard Firebox firewalls with no login.

Security news

AsyncAPI's npm packages shipped malware with valid provenance. The supply-chain checkmark waved it through.

Four @asyncapi npm packages shipped a malware loader carrying valid OIDC provenance attestations.

Security news

RabbitMQ's takeover flaw is conditional. The quiet one isn't.

RabbitMQ patched CVE-2026-57219 and CVE-2026-57221. The severe OAuth secret leak needs OAuth configured; the quiet metadata bug hits every shared virtual host.

Security news

A rogue extension can still make Claude in Chrome read your Gmail

A rogue browser extension can forge a click that makes Claude for Chrome read your Gmail, Docs, and Calendar, unpatched across eight releases.

Security news

Grafana's AI connector can leak its access token to a stranger and reach into your cloud

A high-severity flaw (CVSS 8.6) in Grafana's MCP server lets an unauthenticated attacker steal its Grafana service-account token and relay requests into

Security news

Two SonicWall remote-access zero-days are under attack, and patching alone will not clean the box

SonicWall patched two actively exploited SMA 1000 zero-days, CVE-2026-15409 and CVE-2026-15410.

Security news

Two Microsoft zero-days were exploited before the fix shipped

Microsoft's July 2026 Patch Tuesday fixes two zero-days already exploited in the wild: an ADFS and a SharePoint Server privilege bug.

Security news

SAP's highest-scored July flaw is not the one to patch first

SAP's July 2026 patch day has three criticals. The top-scored 9.9 NetWeaver bug needs a login; the two pre-auth 9.1s in AppRouter and Commerce Cloud go first.

Security news

Notarized by Apple, still malware: the CrashStealer Mac stealer

CrashStealer is a macOS info-stealer that Apple notarized, so Gatekeeper cleared it on launch before it drained keychains, browser logins and crypto wallets.

Security news

An 18-year-old Cisco router flaw is being exploited, and no patch is coming

CISA flagged an 18-year-old Cisco IOS flaw (CVE-2008-4128) as actively exploited. What it hits, why old routers are the target, and how to shut it down.

Security news

How a PNG in a pull request makes AI agents leak secrets

Researchers hid prompt-injection text inside a PNG in a pull request and made AI coding agents read .env and leak the secrets.

Security news

Mass CMS campaign turns unpatched plugins into webshells

Australia's cyber agency warns of a global campaign mass-exploiting 16 known CMS and plugin flaws to drop webshells on WordPress, Joomla and Craft sites.

Security news

A Helix Ultimate flaw lets an anonymous visitor hijack a Joomla admin, and a working exploit is now public

A public exploit now targets CVE-2026-57829, an unauthenticated stored XSS in the Helix Ultimate Joomla framework below 2.2.7.

Security news

A cache-plugin flaw backdoored 17,000 WordPress sites. A max-severity bug got 77.

An exposed server revealed WP-SHELLSTORM, a WordPress and Joomla webshell operation. Its own logs show CVE severity barely predicted which sites got hacked.

Security news

A single rigged device name can hijack an OpenWrt router's admin panel

A stored XSS in OpenWrt's LuCI web panel (CVE-2026-61876, CVSS 8.8) lets a device on the LAN plant a script in a DHCPv6 hostname that runs in the admin's

Security news

Ghost accounts are mapping your GitHub org. The recon is invisible; the stolen token is not.

Datadog found 50+ dormant GitHub accounts enumerating corporate orgs through the public API, some escalating to private-repo clones with stolen tokens.

Security news

Zimbra's Classic Web Client can run code from a crafted email again. Patch to 10.1.19 now.

Zimbra shipped ZCS 10.1.19 to fix a stored XSS in the Classic Web Client that runs code from a crafted email. Google TAG reported it; no public exploit yet.

Security news

npm just killed install-script malware by default. This week's other attack walks right past it.

npm 12 disables install scripts by default, which would have stopped this week's jscrambler infostealer.

Security news

Progress tells ShareFile users to shut servers down, and no patch means assume breach

Progress told ShareFile customers to shut down on-premises Storage Zone Controllers over a credible threat.

Security news

Super Forms flaw lets anyone take over a WordPress site, and a working exploit is now public

A critical flaw (CVSS 9.8) in the Super Forms WordPress plugin lets unauthenticated attackers run code on the server.

Security news

GigaWiper fakes a ransomware hit to cover a disk wipe, and the only early warning is on the host

GigaWiper encrypts files to .candy with no key and no ransom note, because the ransomware is a decoy for a disk wipe. Here are the host signals that catch it.

Security news

A rigged Jira ticket can trick the mcp-atlassian AI connector into leaking server files

mcp-atlassian before 0.22.0 reads files off its own host when a caller or a prompt-injected agent supplies a server-side path.

Security news

Two more Joomla extensions hit the exploited list. It is the same bug, five times now.

CISA added Balbooa Forms (CVE-2026-56291) and iCagenda (CVE-2026-48939) to its exploited list on July 10, the fourth and fifth Joomla extension with the same

Security news

Three attacks in one week turned AI coding agents into an unmonitored way onto your network

HalluSquatting and Friendly Fire show AI coding agents running attacker code with a developer's privileges. No CVE, no patch. Here is the detection posture.

Security news

Three ransomware responders secretly worked for BlackCat. Trust is the attack surface.

Three incident-response insiders at DigitalMint and Sygnia were sentenced for helping run BlackCat ransomware, one leaking victims' insurance limits.

Security news

A fake 7-Zip installer rents your server out as a residential proxy, and file scans miss it

A trojanized 7-Zip and VPN campaign called Lurking Lizard turns servers and PCs into residential proxy nodes.

Security news

Patched but still defaced: the Helix3 Joomla flaw that hides in your database, not your files

An unauthenticated bug in JoomShaper's Helix3 (CVE-2026-49049) is defacing Joomla sites. It hides in the database, so patching to 3.1.2 alone won't clean it.

Security news

GhostLock turns any Linux foothold into host root, and containers don't stop it

GhostLock (CVE-2026-43499) is a 15-year-old Linux kernel flaw that turns any local foothold into host root and escapes containers. Who is exposed, how to patch.

Security news

A Google chatbot 'edit' permission was really a code-execution grant

Google's Dialogflow CX let one edit permission run code across every chatbot in a project.

Security news

GodDamn ransomware blinds EDR with a signed kernel driver. Detect the load, not the file.

GodDamn ransomware uses PoisonX, a kernel driver carrying a valid Microsoft signature, to disable EDR.

Security news

Five Tenda router models ship a hidden admin password. With no patch, containment is the only move.

CERT/CC flagged a hardcoded admin password in five Tenda router models (CVE-2026-11405). No fix exists yet, so here is how to detect and contain it.

Security news

A public GitHub issue made an AI agent leak a private repo. No patch closes this class.

A crafted public GitHub issue tricked an AI Agentic Workflow into posting a private repo's contents as a public comment. Why no patch closes this class.

Security news

Two pre-auth bypasses hit BeyondTrust's privileged-access appliances, found by the vendor's own AI

BeyondTrust patched four flaws in Remote Support and Privileged Remote Access, including two pre-auth CVSS 9.2 bypasses. Upgrade to 25.3.3 and hunt the window.

Security news

A low-privilege user could overreach on Dell's Data Domain backup appliances. The fix is out.

CVE-2026-56086 lets a low-privileged remote user gain unauthorized access on Dell PowerProtect Data Domain backup appliances. CVSS 8.8. Patched builds are out.

Security news

Two Joomla page builders are exploited for site takeover. The patch won't evict the intruder.

CISA flagged two CVSS-10 Joomla page-builder flaws, SP Page Builder (CVE-2026-48908) and Page Builder CK (CVE-2026-56290), as exploited.

Security news

A logged-in user can hijack the Linux graphics server, and on many systems that means root

X.Org patched two memory-corruption bugs in the X server and XWayland. A local client can reach root where Xorg runs as root. Update to 21.1.24 and 24.1.13.

Security news

Adobe ColdFusion is under active attack, but the max-severity rating overstates who is exposed

Adobe ColdFusion flaw CVE-2026-48282 (CVSS 10.0) is now exploited in the wild and in CISA KEV. Who is actually exposed, how to detect it, and what to patch.

Security news

The new Cavern C2 needs no CVE. It abuses your IT provider's own tools to get in.

Check Point ties the Iran-linked Cavern C2 to intrusions that skip vulnerabilities entirely, abusing IT providers' own deployment tools.

Security news

Django shipped three low-severity security fixes. One of them deserves a closer look.

Django 6.0.7 and 5.2.16 patch three low-severity issues: a header injection, a cache data leak, and a heap over-read.

Security news

Januscape: nested virtualization reopens a 16-year-old escape out of the KVM guest

Januscape (CVE-2026-53359) is a 16-year-old KVM use-after-free that lets a rooted guest VM crash its Linux host. Nested virtualization is the trigger.

Security news

A default in Red Hat's Linux login system lets one directory account seize root on every server

CVE-2026-14474: when SSSD's LDAP sudo provider has no explicit search base, one directory account can plant a rule that grants root on every enrolled Linux

Security news

Gitea's Docker image trusts a login header from anyone, and probing has started

A default in Gitea's Docker image trusts the X-WEBAUTH-USER header from any IP, so anyone can log in as any user.

Security news

Formie's second hidden-field flaw in five weeks lets a stranger run code on your Craft CMS site

Formie for Craft CMS has a critical flaw (CVE-2026-52889) that lets an unauthenticated visitor inject Twig template code through a hidden field.

Security news

AI reopened a 2017-audited filesystem and found seven bugs your devices can't patch

runZero found seven flaws in FatFs, the filesystem inside millions of cameras, drones and controllers. No upstream patch exists. How to detect and contain it.

Security news

SUSE Rancher patched critical flaws that turn a small foothold into full control of your Kubernetes clusters

SUSE Rancher and Fleet patched critical flaws that let a leaked token or one tenant account seize whole Kubernetes clusters.

Security news

Kairos stole 2TB, encrypted nothing, and still got $1M. Watch the login, not the file locker.

Kairos stole 2TB from a US county, encrypted nothing, and was paid $1M. Encryptionless extortion breaks file-locker alarms. Detect the login and egress.

Security news

We said a password reset wouldn't stop FortiBleed. Now it is deploying ransomware.

FortiBleed harvested 110 million Fortinet credentials. SOCRadar links that access to INC and Lynx ransomware, with 12 encryptions and a Nextcloud zero-day.

Security news

A poisoned security scanner ran on your build server and walked out with your cloud keys

The FBI's TeamPCP FLASH alert shows why a trojanized scanner steals from your servers, not the registry, and why pinning packages will not save you.

Security news

A Linux kernel bug called Bad Epoll turns a sandboxed process into root, and the exploit is now public

Bad Epoll (CVE-2026-46242) lets a sandboxed or unprivileged process reach root on Linux 6.4+ and Android. Fixed in April; a public 99% exploit now exists.

Security news

No password needed: a public exploit now hijacks unpatched Control Web Panel servers

A public exploit for a critical Control Web Panel flaw (CVE-2026-57517) lets unauthenticated attackers seize hosting servers. Patch to 0.9.8.1225 and hunt now.

Security news

The FBI seized NetNut's proxy network. Its two million compromised devices are still infected.

The FBI and Google seized the NetNut residential proxy network on July 2, but its two million compromised devices are still infected. Why IP reputation fails.

Security news

Scattered Spider keeps winning because your help desk, not a CVE, is the way in

An extradited Scattered Spider suspect breached a retailer in under three hours through a help-desk password reset. Here is the identity control that stops it.

Security news

Kemp LoadMaster's quote sanitizer became a pre-auth root RCE, exploited hours after the writeup dropped

Kemp LoadMaster's CVE-2026-8037 gives unauthenticated root through its API and is under active exploitation. Affected versions, the fix, and how to detect it.

Security news

The first AI-run ransomware locked a database with a key it never saved

The first ransomware attack run end to end by an AI agent broke in through a year-old Langflow flaw and encrypted a database with a key it never saved.

Security news

Cursor's AI agent trusted the content it read, and that content could switch off its sandbox

Two critical Cursor flaws, DuneSlide (CVE-2026-50548/50549, CVSS 9.8), let a poisoned MCP server or web result overwrite the sandbox binary and run code.

Security news

Puppet stored the passwords it was told to hide in cleartext on every managed node

CVE-2026-8804: Puppet's Resource API stopped honoring the sensitive flag, writing passwords in cleartext to each agent's state cache. Upgrade, then rotate.

Security news

Argo CD can be taken over from inside your cluster, and there is no patch to wait for

Argo CD's repo-server runs code for unauthenticated callers and can take over your Kubernetes cluster. No patch or CVE exists yet, so isolate and watch it now.

Security news

A rigged puzzle talked six AI browsers into leaking a developer's SSH keys. One patch won't save you.

A game-themed web page talked six AI browsers into leaking a developer's SSH keys. Why patching one vendor is not the fix, and what to watch instead.

Security news

Fake exploit code is delivering ChocoPoC, a stealer aimed at the researchers who run it

ChocoPoC hides a credential-stealing trojan inside fake CVE proof-of-concept repos, targeting the researchers and red teams who download and test them.

Security news

Microsoft said this SharePoint bug was unlikely to be exploited. CISA just proved it wrong.

Microsoft rated SharePoint's CVE-2026-45659 unlikely to be exploited. CISA added it to the KEV catalog on July 1 after active exploitation. Patch and hunt now.

Security news

Adobe's six max-severity ColdFusion flaws have no exploit yet, and that is the countdown

Adobe patched six unauthenticated CVSS 10.0 code-execution flaws in ColdFusion (bulletin APSB26-68).

Security news

MFA did not stop the Azure CLI password spray. A retired login flow is why.

A password spray beat Conditional Access at 64 organizations by abusing ROPC, a retired Azure login flow that never triggers an MFA prompt. What to fix now.

Security news

Citrix shipped six NetScaler fixes. One of them isn't done until you change a setting.

Citrix fixed six NetScaler flaws, including a pre-login memory leak and an HTTP/2 Bomb denial of service. One fix needs a config change, not just an upgrade.

Security news

Ransomware that runs inside your browser tab, where antivirus cannot see it

Check Point built browser-only ransomware from a DeepSeek AI output: a web page encrypts your files through a legitimate browser API, with no binary for

Security news

AI keeps inventing web addresses that do not exist. Attackers now buy them first.

Unit 42 found attackers registering the fake web domains AI models hallucinate, turning a chatbot's answer into a phishing and supply chain threat.

Security news

An old bash trick makes AI coding agents run the commands they just blocked

AI coding agent guardrails fall to GuardFall, a bash trick that bypassed the command safety check in 10 of 11 open-source agents Adversa AI tested.

Security news

119 browser extensions hid malware inside images and fonts for two years

Microsoft pulled 119 malicious Edge extensions in the StegoAd campaign. Steganographic payloads, 2.6 million installs, and a 2FA lesson for defenders.

Security news

Oracle E-Business Suite is under attack again, and the patch has been out since May

CVE-2026-46817, a CVSS 9.8 flaw in Oracle E-Business Suite Payments, is exploited weeks after Oracle's May patch. What to check and how to fix it now.

Security news

A forged login key unlocks SimpleHelp servers, and a new stealer is raiding cloud and AI credentials

A maximum-severity SimpleHelp flaw, CVE-2026-48558, lets attackers forge a login and is now exploited to drop Djinn Stealer against cloud and AI keys.

Security news

A crafted link can stall millions of Node apps, and the patch will not reach most of them

decode-uri-component, the npm decoder behind query-string and millions of apps, has a denial-of-service bug (CVE-2026-45822).

Security news

You don't have to install this npm malware. Opening the folder in your editor runs it.

Two hijacked npm packages skip the install step entirely. They run when you open the project in VS Code, then steal developer, browser, and wallet logins.

Security news

The repo is clean. Your AI coding agent is what hands the attacker a shell.

Mozilla's 0DIN made Claude Code open a reverse shell from a GitHub repo with no malicious code. Here is why scanners miss it and how to constrain the agent.

Security news

This backdoor is named after your VMware and EDR tools. Your allowlist trusts it.

A Chinese APT called CL-STA-1062 ships its TinyRCT backdoor disguised as VMware and EDR agents. Why filename allowlists miss it, and what to hunt instead.

Security news

SUSE Linux trusted software repositories enough to let one overwrite your system files

SUSE and openSUSE patched seven flaws in their package manager. CVE-2026-25707 lets a malicious repository overwrite system files as root.

Security news

libssh2 flaw: a malicious SSH server can hijack the client connecting to it

libssh2's CVE-2026-55200 lets a malicious SSH server run code on the client that connects to it. No login, a public PoC is out, and there is no tagged fix yet.

Security news

Hotels are running malware on a legitimate Node.js runtime, and that beats allowlisting

TonRAT runs on a genuine Node.js runtime on hotel front-desk machines, hides its C2 on the TON blockchain, and slips past allowlists. Here is what to hunt.

Security news

A seized iPhone gave up everything. The MacBook beside it gave up nothing.

Cellebrite's UFED tool fully read a locked iPhone in Russian custody but failed on the encrypted MacBook seized beside it.

Security news

Linux's newest root exploits rewrite /bin/su in memory and leave the file clean

DirtyClone and pedit COW are the latest in a family of Linux kernel root bugs that rewrite binaries in memory, invisible to file-integrity monitoring.

Security news

A rigged 7-Zip archive can erase the Windows warning on downloaded files, and there is no fix yet

A crafted RAR5 archive lets 7-Zip 26.02 strip the Mark-of-the-Web, defeating Windows SmartScreen warnings. No patch exists yet.

Security news

Signal's recovery key never expires, and Russian intelligence is now phishing for it

Russian intelligence is phishing Signal users for the Backup Recovery Key, a secret that decrypts a whole message history and that no reset or new account can

Security news

Polymarket's servers were never hacked. A poisoned vendor script still stole $3 million from users.

A compromised third-party vendor injected malicious code into Polymarket's site and stole nearly $3 million from users. The backend was never breached.

Security news

Open the wrong repo and Amazon Q ran its config file as you, AWS keys included

Amazon Q Developer ran a repo's MCP config file as you, with AWS keys attached. CVE-2026-12957 is patched in 1.69.0. What to verify and hunt for now.

Security news

A widely used PHP tool for making PDFs can hand attackers your internal files and cloud keys

php-weasyprint's attachment option fetched attacker-controlled URLs server-side, reaching internal services, cloud metadata, and local files.

Security news

Russia's Turla built a new backdoor for one reason: deleting one tool will not evict them

Google tied Russia's Turla to STOCKSTAY, a new .NET backdoor built as four swappable parts. Why deleting one piece does not evict the group, and what to hunt.

Security news

Windchill holds your product blueprints. A web shell on its login page hands them over.

CISA added PTC Windchill RCE CVE-2026-12569 to its KEV catalog after web shells hit exposed PLM servers. Patch to 11.0 M030 before the June 28 deadline.

Security news

Mistic backdoor writes nothing to disk and quietly sells your network to ransomware crews

Mistic is an in-memory backdoor that access broker KongTuke uses to hold footholds and sell them to Qilin and other ransomware crews. Here is where to catch it.

Security news

One setting in Red Hat OpenShift Virtualization can expose your VMs to any pod on the cluster

CVE-2026-13325: enabling disableTLS for faster live migration in Red Hat OpenShift Virtualization drops authentication, letting any pod reach another tenant’s

Security news

GitLab patched a no-login flaw that can hijack a user's session. Self-hosted servers are the exposed ones.

GitLab's June 24 release fixes 14 flaws, including an unauthenticated cross-site scripting bug.

Security news

A free GitHub account can push code as a trusted maintainer. Upgrading actions/checkout won't fix it.

Cordyceps lets anyone with a free GitHub account run code as a maintainer on 300+ repos. Why upgrading actions/checkout closes one door, not the others.

Security news

Two flaws in Unraid's control panel let a logged-in user seize the whole server

Two command injection flaws in Unraid's web panel, CVE-2026-9772 and CVE-2026-9773, let any logged-in user run code as www-data.

Security news

A rigged container image can seize root on the host running Docker's AI agent tools

CVE-2026-55887 lets a malicious container image escape Docker's MCP Gateway and run code as root on the host. Rated 8.7.

Security news

A new flaw lets attackers take over Quest NetVault backup servers, login or not

CVE-2026-7570 is a SQL-injection-to-remote-code-execution flaw in Quest NetVault Backup, rated 8.8. The login can be bypassed. Quest fixed it in 14.0.2.

Security news

Police seized the malware that stole 27 million passwords. The passwords still work.

Operation Endgame seized the servers behind the Amadey and StealC malware, but the 27 million credentials they already stole stay valid until you rotate them.

Security news

The free plugin was clean. The paid update is what backdoored these WordPress sites.

Backdoored ShapedPlugin Pro updates stole admin logins and 2FA seeds from WordPress sites between April and June 2026. A password reset alone will not clear it.

Security news

On 200,000 WordPress sites, a low-level user can quietly steal the admin's login

A contributor-level user can make Ultimate Member leak every user's password reset link, admins included. Affects versions through 2.11.4; fixed in 2.12.0.

Security news

Cisco Unified CM's flaw is being exploited. Whether it touches you depends on one default setting.

CVE-2026-20230 in Cisco Unified CM can reach root, but only where WebDialer is enabled, and it ships off. Check that before you panic-patch.

Security news

A guest virtual machine can read its host's memory through a flaw in QEMU's built-in networking

A patched flaw in libslirp, QEMU's usermode networking, lets a privileged guest virtual machine read gigabytes of host memory. Update to libslirp 4.9.2 now.

Security news

Mistype the password and this Lantronix box runs attacker commands as root. CISA says it is happening now.

CISA flagged CVE-2025-67038 as exploited on June 23. A failed login on a Lantronix EDS5000 serial server runs attacker commands as root.

Security news

Crawl4AI shipped its server unlocked by default. It took three patches to close the door.

Crawl4AI's Docker API shipped unauthenticated by default, exposing 51,000+ deployments to remote code execution and cloud-metadata SSRF. Upgrade to 0.9.0 now.

Security news

Add-ons for the OpenClaw AI assistant are stealing logins and running crypto scams

Malicious OpenClaw skills on the ClawHub marketplace steal credentials and hijack AI agents for crypto fraud, and some slip past the store's own scanner.

Security news

A new Mac backdoor is built to fool the AI that inspects it

macOS.Gaslight embeds fake AI system messages to make automated, LLM-assisted malware analysis abort.

Security news

Java's most-used JSON library has a guardrail attackers can slip dangerous objects past

CVE-2026-54513 lets attackers bypass jackson-databind's polymorphic type validator by wrapping a banned class in an array. Patch to 2.18.8, 2.21.4 or 3.1.4.

Security news

Attackers can take over your self-hosted UniFi controller with no password. CISA says it is happening now.

Three chained UniFi OS Server flaws give unauthenticated root. CISA added all three to its exploited list on June 23. Patch to 5.0.8 and check who can reach it.

Security news

PixelSmash: a video your server opens by itself can run an attacker's code

PixelSmash (CVE-2026-8461) lets a crafted video run code on FFmpeg-based media servers like Jellyfin and Nextcloud. Update to FFmpeg 8.1.2, then hunt.

Security news

A WhatsApp invoice is installing real IT software to hijack PCs, and your antivirus waves it through

A fake invoice on WhatsApp silently installs ManageEngine Endpoint Central, a legitimate remote-management tool, to hijack PCs.

Security news

Your self-hosted Gogs server lets any logged-in user read repos that aren't theirs

A validation gap in Gogs Mirror Settings (CVE-2026-52801) lets any authenticated user import local repositories and reach internal systems. Patch to 0.14.3 now.

Security news

One rigged account-sync update can poison your whole app and forge an admin

CVE-2026-48170 lets one SCIM PATCH request poison Object.prototype across a Node.js app using scim-patch, risking admin forgery. Update to 0.9.1 now.

Security news

A single Budibase app builder can read your server's secrets and take over every workspace

CVE-2026-54352 lets a Budibase workspace builder read the server's secret file via a crafted PWA zip and take over every workspace. Patch self-hosted to 3.39.9.

Security news

Washington export-controlled an AI for finding bugs. Your oldest code is the soft target.

The US used export-control powers to pull a frontier AI model that finds software bugs at scale.

Security news

Older iPhones just got a flaw Apple can't patch, and a cable is all it takes

usbliter8 is an unpatchable boot-chain exploit for Apple A12 and A13 devices. Here is the real enterprise risk, why remote wipe will not help, and what to do.

Security news

PaperCut's Windows print client can be tricked into giving a local attacker total control

CVE-2026-6645 lets a local attacker plant a file that PaperCut's Print Deploy client runs with full system rights on Windows. Update to version 1.10.4178.

Security news

Run Central Dogma across servers? It may be guarding your config with a password printed in its source code

Central Dogma before 0.84.0 silently uses a public default secret when ZooKeeper replication runs without one set, letting nearby attackers seize the cluster.

Security news

Your Squid proxy can leak other users' passwords, and the 7.6 update won't fix it

Squidbleed (CVE-2026-47729) leaks memory from Squid proxies in default config, including login credentials. A public exploit is out, and 7.6 does not patch it.

Security news

That decade-old router you forgot is now scanning networks for attackers

A botnet called AryStinger hijacked over 4,300 end-of-life D-Link and Linksys routers into a distributed scanning grid for reconnaissance, not DDoS. What to do.

Security news

Millions of hacked TV boxes now rent attackers a trusted home IP. Your blocklist can't see it.

Researchers linked the Popa botnet of 2 million hacked TV boxes to a residential proxy service. Here is why IP reputation no longer stops account takeovers.

Security news

Prinz Eugen ransomware hits your newest files first and never leaves a note

Prinz Eugen ransomware encrypts your most recently changed files first and drops no ransom note, defeating canary traps and note-based SOC alerts. What to do.

Security news

EaseUS Partition Master left a Windows driver that lets any user seize the whole PC

A signed driver in EaseUS Partition Master (CVE-2026-12781) lets any standard Windows user read and overwrite the whole disk to reach SYSTEM.

Security news

Your AI agent trusts your own computer. One web page turns that into a takeover.

Microsoft's AutoJack shows how one web page an AI browsing agent visits can run code on the host. The bug is a near miss. The architecture lesson is not.

Security news

This login library let a stranger sign in as you with just your email

CVE-2026-49757 (CVSS 9.2) let attackers take over accounts in Elixir apps built on ash_authentication by matching users on email instead of identity.

Security news

Your Fortinet password reset won't lock the FortiBleed attacker out

CISA warned Fortinet users on June 18; reporting counted 86,644 affected devices. Resetting passwords is not enough: kill live sessions and fix the hashing.

Security news

vLLM's earlier patch only hid this AI-server bug. Re-enable embeddings and you are still exposed

CVE-2026-56340 lets a crafted tensor crash vLLM (CVSS 8.8) with a path to memory corruption. It only bites if you re-enabled prompt embeds. Fix is 0.13.0.

Security news

Gravity SMTP's 'medium' bug leaks live email API keys to anyone. Patching alone will not save you.

Gravity SMTP's CVE-2026-4020 hands live Amazon SES, Google, and OAuth keys to unauthenticated visitors on 100,000 WordPress sites.

Security news

Police scrubbed SocGholish from 15,000 WordPress sites. The way in is still wide open.

Operation Endgame seized 106 SocGholish servers and cleaned 14,971 WordPress sites. The takedown hit an access broker, not the entry vector.

Security news

One tracing header can make a LangSmith server hand over its files

LangSmith SDK before 0.8.18 lets a crafted tracing header read arbitrary files off any server running TracingMiddleware. Upgrade now; it is the second such bug.

Security news

A USB worm swaps your crypto address mid-paste, and no breach alarm ever fires

Microsoft found a USB worm that hijacks the clipboard to swap crypto wallet addresses and hides its command channel in Tor. Here is why it beats your controls.

Security news

The app you're testing can hijack the AI agent testing it: Appium MCP's XSS flaw

An XSS flaw in Appium's official MCP server let a hostile test app hijack the AI agent driving it and call its tools. Patch appium-mcp to 1.85.10 now.

Security news

EDR evasion is now a shipped product. Your agent's silence is the only alarm left.

The Gentlemen ransomware gang ships a standardized EDR killer to affiliates using BYOVD. Here is why driver-name hunting fails and what to detect instead.

Security news

Branda fixed this WordPress account takeover in January. It is back, and a public exploit is circulating.

CVE-2026-11551 is a CVSS 9.8 unauthenticated account takeover in the Branda WordPress plugin (versions up to 3.4.29). A public exploit is out.

Security news

A WordPress form plugin lets a stranger delete your site, the moment an admin looks

CVE-2026-9843 lets an unauthenticated visitor plant a form entry that deletes WordPress files when an admin opens it.

Security news

A single rigged document can turn Langflow's file reader into full server takeover

A crafted document in a Langflow RAG pipeline (CVE-2026-55447, CVSS 9.6) reads any file, forges a login token, then runs code. Upgrade to 1.9.2 or later.

Security news

One Langflow account can now run every other user's AI workflow

A critical IDOR in Langflow (CVE-2026-55255, CVSS 9.9) lets any logged-in user run another user's AI flow. Upgrade to 1.9.1. The real problem is the pattern.

Security news

Mastra's npm packages passed inspection, then turned hostile a day later

Attackers hijacked a dormant maintainer account to poison 140+ Mastra npm packages with a wallet-stealing payload.

Security news

CoreWCF's SAML check trusted a forged identity as your admin. There is no workaround, only the patch.

CVE-2026-54782 lets an attacker forge a SAML token and impersonate anyone, admins included, on CoreWCF federation services. No workaround.

Security news

Quarkus fixed a semicolon auth bypass in May. Its encoded cousin just reopened it.

Quarkus fixed a semicolon authorization bypass in May, but CVE-2026-50559 reopens it with URL-encoded characters. What to patch now and how to detect abuse.

Security news

DragonForce hides its C2 inside Microsoft Teams relays. Your network sensors see a clean call.

DragonForce's Backdoor.Turn routes C2 through Microsoft Teams TURN relays, so network sensors see only Microsoft.

Security news

Your Salesforce wasn't breached. A connected app handed over the data.

The Icarus group stole Salesforce CRM data through Klue's connected app, not a Salesforce flaw. Why OAuth integration tokens are the unmonitored attack surface.

Security news

Your JetBrains Hub 2FA protected nothing. The recovery codes were predictable.

JetBrains Hub generated predictable 2FA recovery codes (CVE-2026-56141, CVSS 9.8), allowing pre-auth account takeover.

Security news

Perry's stdlib turned off JWT expiry checks. Logout stopped meaning anything.

CVE-2026-53776: Perry's bundled JWT helper hard-codes validate_exp = false, so expired and revoked tokens stay valid. Patch to 0.5.1166 and rotate signing keys.

Security news

Your Splunk box runs a database sidecar you never configured. Attackers use it for root.

CVE-2026-20253 is an unauthenticated RCE in Splunk Enterprise 10.x via a bundled PostgreSQL sidecar. On CISA KEV, exploited now. Patch to 10.0.7 or 10.2.4.

Security news

Two NGINX bugs scored 9.2. On a default server you get a crash, not a shell.

F5's two critical NGINX flaws (CVE-2026-42530, CVE-2026-42055) score 9.2, but RCE needs ASLR off and a non-default config. Here is what to actually triage.

Security news

INC ransomware never used a zero-day. It used your patch backlog.

INC reached top-tier RaaS in 2026 with no zero-days. Every edge-device flaw it exploits was patched months earlier. Here is what to actually fix.

Security news

ClickFix is now shared attack infrastructure, and the lure is the wrong thing to detect

Three unrelated crews adopted ClickFix delivery in a single quarter. The lure keeps changing; the execution chain does not. Here is where to detect it.

Security news

Cisco called this SD-WAN flaw medium. Attackers used it to take root on your WAN.

CVE-2026-20262 is an actively exploited Cisco SD-WAN Manager flaw that escalates a low-privilege login to root.

Security news

RoguePlanet turns Microsoft Defender into a SYSTEM shell, and switching it off won't save you

RoguePlanet (CVE-2026-50656) is a public-exploit privilege escalation in Microsoft Defender's engine.

Security news

FortiBleed isn't a Fortinet bug. It's every password you never rotated.

FortiBleed exposed working VPN logins for tens of thousands of Fortinet firewalls. There is no CVE to patch; the fix is rotating credentials and enforcing MFA.

Security news

JetBrains Plugins Are Stealing AI API Keys, and You Find Out From the Bill

Aikido found 15 JetBrains Marketplace plugins stealing AI API keys across 70,000 installs.

Security news

FortiSandbox Under Attack: The Box That Catches Malware Is Now the Way In

Three critical FortiSandbox flaws are under active exploitation, two unauthenticated and one patched a week ago.

Security news

Three requests, no password, a webshell: the JCE flaw hitting Joomla hosts now

Unauthenticated RCE (CVSS 10, CVE-2026-48907) in JCE, the most-installed Joomla editor. KEV-listed and exploited. Patch to 2.9.99.6 and hunt for webshells.

Security news

A Linux backdoor moved into the Windows kernel, and the detection window closes at driver load

SprySOCKS, a China-nexus Linux backdoor, now ships a Windows kernel-driver variant that hides itself from the host. Here is where defenders can still catch it.

Security news

LiteSpeed's cPanel plugin gave shared-hosting tenants root twice in 2026. CageFS didn't help.

CVE-2026-54420 and CVE-2026-48172 let shared-hosting tenants reach root through the LiteSpeed cPanel plugin. Why CageFS isolation failed and what to patch now.

Security news

Awesome Motive's WordPress CDN backdoor only fired for logged-in admins. Your scanner missed it.

OptinMonster, TrustPulse and PushEngage served a backdoor that ran only for logged-in WordPress admins, evading visitor scanners. How to scope and hunt it.

Security news

SearchLeak in Microsoft 365 Copilot: prompt injection as a new door to old bugs

SearchLeak chained prompt injection, an HTML render race, and Bing SSRF to steal Microsoft 365 Copilot data in one click. What it means for detection.

Security news

Ivanti Sentry's CVE-2026-10520: patch the gateway, then hunt for the breach

Ivanti Sentry CVE-2026-10520 is an unauthenticated root RCE under active attack. CISA's new 3-day patch rule applies; patched gateways were already breached.

Security news

PeopleSoft's PSEMHUB zero-day turns the patch service into the breach

CVE-2026-35273 sits in PeopleSoft's Updates Environment Management module. Mandiant ties active exploitation to ShinyHunters, with 100+ orgs already breached.

Security news

Velvet Ant's PAM-OpenSSH decade is an auth-stack blind spot, not a Linux bug

Sygnia found nine backdoored pam_unix.so variants and four trojanized OpenSSH binaries on one victim. Why auth-stack integrity is the SIEM-invisible gap.

Ready to meet the Guardians?

Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.