<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Suriq Blog</title><description>Deep-dives, comparisons, and incident replays from the engineers building autonomous defense.</description><link>https://suriq.io/</link><language>en-us</language><item><title>Critical Predis flaw lets attacker-controlled data smuggle extra Redis commands (CVE-2026-84372)</title><link>https://suriq.io/blog/predis-crlf-command-injection-cve-2026-84372/</link><guid isPermaLink="true">https://suriq.io/blog/predis-crlf-command-injection-cve-2026-84372/</guid><description>CVE-2026-84372 is a CVSS 9.8 command-injection flaw in the Predis PHP client. It hits 3.0 to 3.2 on cluster and replication connections. Upgrade to 3.3.0.</description><pubDate>Tue, 01 Sep 2026 21:39:10 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Microsoft Exchange auth-bypass CVE-2026-62911 gives attackers a SYSTEM webshell, and a public exploit is out</title><link>https://suriq.io/blog/exchange-cve-2026-62911-auth-bypass-webshell-poc/</link><guid isPermaLink="true">https://suriq.io/blog/exchange-cve-2026-62911-auth-bypass-webshell-poc/</guid><description>CVE-2026-62911 lets attackers relay an Exchange server&apos;s own machine account into a SYSTEM webshell.</description><pubDate>Tue, 01 Sep 2026 18:57:39 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A BGP hijack pushed a malicious Virtualizor update that ran as root. Check for one systemd service.</title><link>https://suriq.io/blog/virtualizor-bgp-hijack-malicious-update/</link><guid isPermaLink="true">https://suriq.io/blog/virtualizor-bgp-hijack-malicious-update/</guid><description>A 33-hour BGP hijack redirected Softaculous update traffic and pushed a malicious Virtualizor package that ran as root. Check a systemd service, patch 3.2.9.9.</description><pubDate>Tue, 01 Sep 2026 17:07:45 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A public exploit turns Kaspersky&apos;s endpoint agent into a privilege-escalation tool on fully patched Windows 11</title><link>https://suriq.io/blog/kaspersky-endpoint-security-hardbreacher-privilege-escalation/</link><guid isPermaLink="true">https://suriq.io/blog/kaspersky-endpoint-security-hardbreacher-privilege-escalation/</guid><description>A public exploit, HardBreacher, coerces Kaspersky Endpoint Security into a privileged write on fully patched Windows 11. Vendor says fixed, no CVE yet.</description><pubDate>Tue, 01 Sep 2026 12:16:31 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>WP Fastest Cache flaw lets attackers poison cached pages served to every WordPress visitor</title><link>https://suriq.io/blog/wp-fastest-cache-cache-poisoning-cve-2026-74916/</link><guid isPermaLink="true">https://suriq.io/blog/wp-fastest-cache-cache-poisoning-cve-2026-74916/</guid><description>WP Fastest Cache flaw CVE-2026-74916 lets attackers poison cached WordPress pages and hit every visitor with malicious script. Update to 1.5.1 and purge cache.</description><pubDate>Tue, 01 Sep 2026 08:14:09 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>TerminalFix moves ClickFix into the terminal to slip past the defenses built for the Run box</title><link>https://suriq.io/blog/terminalfix-clickfix-windows-terminal-reverse-tunnel/</link><guid isPermaLink="true">https://suriq.io/blog/terminalfix-clickfix-windows-terminal-reverse-tunnel/</guid><description>Microsoft documented TerminalFix, a ClickFix variant that pastes PowerShell into Windows Terminal to plant a reverse-tunnel backdoor. Here is what to detect.</description><pubDate>Mon, 31 Aug 2026 19:00:53 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Manchester Airports breach: a marketing API key exposed in client-side JavaScript</title><link>https://suriq.io/blog/manchester-airports-client-side-api-key-breach/</link><guid isPermaLink="true">https://suriq.io/blog/manchester-airports-client-side-api-key-breach/</guid><description>An extortion group says it pulled 86GB from Manchester Airports Group using a marketing API key exposed in client-side JavaScript.</description><pubDate>Mon, 31 Aug 2026 16:19:43 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Fire Ant compromised Cisco routers and TACACS servers, stole admin credentials, and rewrote logs to hide</title><link>https://suriq.io/blog/fire-ant-cisco-router-tacacs-credential-theft/</link><guid isPermaLink="true">https://suriq.io/blog/fire-ant-cisco-router-tacacs-credential-theft/</guid><description>China-linked Fire Ant compromised Cisco IOS XR routers and TACACS servers, stole live admin credentials, and rewrote logs to stay invisible. How to detect it.</description><pubDate>Mon, 31 Aug 2026 12:22:51 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Trusted browser extensions turned into crypto-wallet drainers after silent updates</title><link>https://suriq.io/blog/browser-extension-silent-update-wallet-drainer/</link><guid isPermaLink="true">https://suriq.io/blog/browser-extension-silent-update-wallet-drainer/</guid><description>Browser extensions in the Superior campaign shipped clean, then a silent update drained crypto wallets and stole logins. How to detect it and respond.</description><pubDate>Mon, 31 Aug 2026 08:53:46 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Dell PowerStore flaw lets an attacker read admin credentials off the array without logging in</title><link>https://suriq.io/blog/dell-powerstore-unauth-credential-leak-cve-2026-58574/</link><guid isPermaLink="true">https://suriq.io/blog/dell-powerstore-unauth-credential-leak-cve-2026-58574/</guid><description>Dell PowerStore&apos;s management interface has a critical flaw (CVE-2026-58574, CVSS 9.8): an unauthenticated attacker can read files that expose admin credentials.</description><pubDate>Mon, 31 Aug 2026 08:10:34 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>AJCloud camera firmware flaw lets anyone read your Wi-Fi password and camera logins</title><link>https://suriq.io/blog/ajcloud-ipc-camera-path-traversal-cve-2026-56718/</link><guid isPermaLink="true">https://suriq.io/blog/ajcloud-ipc-camera-path-traversal-cve-2026-56718/</guid><description>A path traversal bug in AJCloud AJY IPC camera firmware (CVE-2026-56718) lets unauthenticated attackers read Wi-Fi passwords and camera credentials as root.</description><pubDate>Sun, 30 Aug 2026 20:40:30 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>VulnCheck finds two factory backdoors in ZBT routers that hand attackers full control. No fix exists.</title><link>https://suriq.io/blog/zbt-speakingstone-darklantern-router-backdoors/</link><guid isPermaLink="true">https://suriq.io/blog/zbt-speakingstone-darklantern-router-backdoors/</guid><description>VulnCheck found two more factory implants in ZBT router firmware, SPEAKINGSTONE and DARKLANTERN (CVE-2026-74232/74233), that grant remote root access.</description><pubDate>Sun, 30 Aug 2026 16:14:50 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Unitree G1 robot flaws give root over Bluetooth, and one hacked robot can reach the next</title><link>https://suriq.io/blog/unitree-g1-robot-bluetooth-root-rce/</link><guid isPermaLink="true">https://suriq.io/blog/unitree-g1-robot-bluetooth-root-rce/</guid><description>Two Unitree G1 humanoid robot flaws (CVE-2026-76639, CVE-2026-76640) give an attacker root over Bluetooth or the network, and one hacked robot can reach the</description><pubDate>Sun, 30 Aug 2026 11:25:34 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Five WordPress plugin and theme flaws let attackers take the site or the whole server</title><link>https://suriq.io/blog/wordpress-five-critical-plugin-theme-flaws-server-rce/</link><guid isPermaLink="true">https://suriq.io/blog/wordpress-five-critical-plugin-theme-flaws-server-rce/</guid><description>Wordfence and Patchstack disclosed five unauthenticated WordPress flaws rated 9.8 to 10.0. GiveWP and Avada run code on the host. Patch all five now.</description><pubDate>Sat, 29 Aug 2026 19:37:28 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Three ServiceNow AI Platform flaws (CVSS 10.0) let an unauthenticated attacker run code. Patch now.</title><link>https://suriq.io/blog/servicenow-ai-platform-three-cvss-10-unauth-flaws/</link><guid isPermaLink="true">https://suriq.io/blog/servicenow-ai-platform-three-cvss-10-unauth-flaws/</guid><description>ServiceNow patched three CVSS 10.0 AI Platform flaws an unauthenticated attacker can chain for code execution, SQL injection, and privilege escalation.</description><pubDate>Sat, 29 Aug 2026 15:43:59 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Two critical Next.js flaws let attackers run code on self-hosted servers</title><link>https://suriq.io/blog/nextjs-critical-flaws-self-hosted-rce/</link><guid isPermaLink="true">https://suriq.io/blog/nextjs-critical-flaws-self-hosted-rce/</guid><description>Next.js patched two critical flaws that let unauthenticated attackers run code on self-hosted servers. Vercel apps are covered. Update to 15.5.24 or 16.3.3 now.</description><pubDate>Sat, 29 Aug 2026 12:18:07 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Linux kernel IPv6 flaw (CVE-2026-53362) lets a container break out to host root, now exploited</title><link>https://suriq.io/blog/linux-kernel-cve-2026-53362-container-escape/</link><guid isPermaLink="true">https://suriq.io/blog/linux-kernel-cve-2026-53362-container-escape/</guid><description>CVE-2026-53362 is an actively exploited Linux kernel IPv6 flaw that lets a low-privilege user escape a container to host root.</description><pubDate>Sat, 29 Aug 2026 09:10:47 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>CISA says a 2022 Linux kernel flaw lets a local user become root, and it&apos;s now being exploited (CVE-2022-0995)</title><link>https://suriq.io/blog/linux-kernel-cve-2022-0995-kev-exploited/</link><guid isPermaLink="true">https://suriq.io/blog/linux-kernel-cve-2022-0995-kev-exploited/</guid><description>CISA added Linux kernel flaw CVE-2022-0995 to its actively-exploited list. A local user can escalate to root.</description><pubDate>Sat, 29 Aug 2026 08:55:42 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>One logged-in Langflow user can run any command on the server, and its code lockdown doesn&apos;t stop it</title><link>https://suriq.io/blog/langflow-authenticated-rce-lockdown-bypass-cve-2026-19295/</link><guid isPermaLink="true">https://suriq.io/blog/langflow-authenticated-rce-lockdown-bypass-cve-2026-19295/</guid><description>A critical Langflow flaw (CVE-2026-19295, CVSS 9.9) lets any authenticated user run OS commands on the server and bypasses the</description><pubDate>Sat, 29 Aug 2026 08:37:49 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>An old ownCloud flaw is now stealing files from unpatched servers, including a nuclear agency</title><link>https://suriq.io/blog/owncloud-cve-2023-49105-exploited-file-theft/</link><guid isPermaLink="true">https://suriq.io/blog/owncloud-cve-2023-49105-exploited-file-theft/</guid><description>CVE-2023-49105, an ownCloud auth bypass patched in 2023, is now in CISA&apos;s KEV list after a suspected Chinese operator stole nuclear-agency files.</description><pubDate>Fri, 28 Aug 2026 18:56:26 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A logged-in user can write files outside JFrog Artifactory&apos;s cache, and it&apos;s now on CISA&apos;s must-patch list</title><link>https://suriq.io/blog/jfrog-artifactory-cache-path-traversal-cve-2026-66384/</link><guid isPermaLink="true">https://suriq.io/blog/jfrog-artifactory-cache-path-traversal-cve-2026-66384/</guid><description>CISA added a JFrog Artifactory path-traversal flaw (CVE-2026-66384) to its must-patch list. A logged-in user can write files outside the Docker cache path.</description><pubDate>Fri, 28 Aug 2026 16:26:09 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>cPanel flaw CVE-2026-65643 lets any hosting account gain root on the whole server. Patch now.</title><link>https://suriq.io/blog/cpanel-cve-2026-65643-domain-parking-root-rce/</link><guid isPermaLink="true">https://suriq.io/blog/cpanel-cve-2026-65643-domain-parking-root-rce/</guid><description>cPanel and WHM flaw CVE-2026-65643 lets any authenticated hosting account write files as root and take full control of a shared server. Patched builds are out.</description><pubDate>Fri, 28 Aug 2026 16:05:10 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>CISA red team breached two critical infrastructure networks. Only one SOC noticed.</title><link>https://suriq.io/blog/cisa-red-team-soc-detection-gap-aa26-237a/</link><guid isPermaLink="true">https://suriq.io/blog/cisa-red-team-soc-detection-gap-aa26-237a/</guid><description>A CISA red team hit two critical infrastructure networks with the same tradecraft. One SOC contained it in minutes, the other never noticed. Here is the gap.</description><pubDate>Fri, 28 Aug 2026 11:42:18 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>PaperCut print servers are under active attack through a login-free code-execution flaw</title><link>https://suriq.io/blog/papercut-ng-mf-unauthenticated-rce-zero-day/</link><guid isPermaLink="true">https://suriq.io/blog/papercut-ng-mf-unauthenticated-rce-zero-day/</guid><description>Attackers are exploiting an unauthenticated flaw in PaperCut NG and MF print servers to run code as the host account. Restrict access and patch now.</description><pubDate>Fri, 28 Aug 2026 11:09:45 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>LiteSpeed Cache flaw lets a planted comment run scripts in your visitors&apos; browsers (CVE-2026-18978)</title><link>https://suriq.io/blog/litespeed-cache-comment-stored-xss-cve-2026-18978/</link><guid isPermaLink="true">https://suriq.io/blog/litespeed-cache-comment-stored-xss-cve-2026-18978/</guid><description>CVE-2026-18978 is a stored cross-site scripting flaw in the LiteSpeed Cache WordPress plugin.</description><pubDate>Fri, 28 Aug 2026 05:26:09 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Gitea flaw CVE-2026-60004 lets any user run code on your server, now exploited. Patch 1.27.1.</title><link>https://suriq.io/blog/gitea-cve-2026-60004-kev-diffpatch-rce/</link><guid isPermaLink="true">https://suriq.io/blog/gitea-cve-2026-60004-kev-diffpatch-rce/</guid><description>CISA added Gitea&apos;s CVE-2026-60004 to its exploited list on Aug 25. A public exploit lets any user run code via the diffpatch API. Patch to 1.27.1 and hunt.</description><pubDate>Tue, 25 Aug 2026 18:50:07 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Weedhack stealer survives takedown by hiding servers on Ethereum, still spreading via fake Minecraft sites</title><link>https://suriq.io/blog/weedhack-etherhiding-c2-fake-minecraft-stealer/</link><guid isPermaLink="true">https://suriq.io/blog/weedhack-etherhiding-c2-fake-minecraft-stealer/</guid><description>Weedhack, an infostealer spread through fake Minecraft sites, survived a C2 takedown by reading server addresses from the Ethereum blockchain. How to detect it.</description><pubDate>Tue, 25 Aug 2026 11:56:09 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Four SSRF flaws in one week turned self-hosted apps into a foothold in your own network</title><link>https://suriq.io/blog/signal-ssrf-network-boundary/</link><guid isPermaLink="true">https://suriq.io/blog/signal-ssrf-network-boundary/</guid><description>Four unrelated products shipped SSRF flaws this week, from a Kubernetes proxy to MLflow. Why self-hosted SSRF reaches cloud metadata, and how to contain it.</description><pubDate>Tue, 25 Aug 2026 09:23:15 GMT</pubDate><category>Deep dive</category><author>Suriq&apos;s Jack</author></item><item><title>Iran-linked hackers took a UK power plant offline for four days</title><link>https://suriq.io/blog/iran-uk-power-plant-four-day-outage/</link><guid isPermaLink="true">https://suriq.io/blog/iran-uk-power-plant-four-day-outage/</guid><description>Iran-linked hackers reportedly kept a small UK power plant offline for four days, as water systems across 12 US states were hit. What defenders should do.</description><pubDate>Tue, 25 Aug 2026 08:45:08 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A max-severity Oracle WebLogic proxy flaw lets attackers reach protected data, and it is under active attack</title><link>https://suriq.io/blog/oracle-weblogic-proxy-cve-2026-21962-kev-exploited/</link><guid isPermaLink="true">https://suriq.io/blog/oracle-weblogic-proxy-cve-2026-21962-kev-exploited/</guid><description>CVE-2026-21962 is a CVSS 10 access-control bypass in Oracle&apos;s WebLogic proxy plug-in, now in CISA KEV with a three-day deadline.</description><pubDate>Mon, 24 Aug 2026 19:11:04 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>ShinyHunters beat MFA at ReliaQuest. Device trust stopped it.</title><link>https://suriq.io/blog/reliaquest-shinyhunters-vishing-device-trust/</link><guid isPermaLink="true">https://suriq.io/blog/reliaquest-shinyhunters-vishing-device-trust/</guid><description>ShinyHunters vished a ReliaQuest employee and got the MFA push approved, but device-trust rules blocked the theft.</description><pubDate>Mon, 24 Aug 2026 18:53:06 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Thousands of leaked AWS keys still work, and 768 give attackers full account control</title><link>https://suriq.io/blog/leaked-aws-keys-live-full-admin/</link><guid isPermaLink="true">https://suriq.io/blog/leaked-aws-keys-live-full-admin/</guid><description>Truffle Security found 64,024 exposed AWS keys and 88% still authenticate; 768 give full account control. Why rotation fails and what to detect and fix.</description><pubDate>Mon, 24 Aug 2026 16:01:14 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A phpIPAM flaw lets an unauthenticated attacker read and delete every network record (CVE-2026-67602)</title><link>https://suriq.io/blog/phpipam-api-auth-bypass-cve-2026-67602/</link><guid isPermaLink="true">https://suriq.io/blog/phpipam-api-auth-bypass-cve-2026-67602/</guid><description>CVE-2026-67602 is a critical unauthenticated flaw in phpIPAM before 1.8.2 that lets anyone read, change, or delete every IP record through the REST API.</description><pubDate>Mon, 24 Aug 2026 14:23:29 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>fast-uri, the URL parser in many Node.js apps, can be tricked into calling internal systems (CVE-2026-75899)</title><link>https://suriq.io/blog/fast-uri-double-decode-ssrf-cve-2026-75899/</link><guid isPermaLink="true">https://suriq.io/blog/fast-uri-double-decode-ssrf-cve-2026-75899/</guid><description>CVE-2026-75899 lets a double-encoded hostname bypass fast-uri&apos;s URL checks and resolve to localhost or a cloud metadata endpoint. Fixed in 2.4.5, 3.1.6, 4.1.3.</description><pubDate>Mon, 24 Aug 2026 11:09:11 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>DJI drone flaw lets a nearby attacker hijack the Wi-Fi link over Bluetooth and disrupt flight</title><link>https://suriq.io/blog/dji-drone-bluetooth-wifi-hijack-cve-2026-78306/</link><guid isPermaLink="true">https://suriq.io/blog/dji-drone-bluetooth-wifi-hijack-cve-2026-78306/</guid><description>CVE-2026-78306: an unauthenticated Bluetooth interface on 16 DJI drone models lets a nearby attacker rewrite the Wi-Fi key and disrupt flight. Models and fixes.</description><pubDate>Mon, 24 Aug 2026 08:42:03 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Malware turns Android car head units into a proxy botnet that hides attacks behind trusted home IPs</title><link>https://suriq.io/blog/android-car-head-unit-malware-proxy-botnet/</link><guid isPermaLink="true">https://suriq.io/blog/android-car-head-unit-malware-proxy-botnet/</guid><description>Kaspersky found the first malware built for Android car head units. It ignores the vehicle and rents the car&apos;s connection as a residential proxy.</description><pubDate>Sun, 23 Aug 2026 16:08:16 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A logged-in GitLab user can write files across the server through the package registry (CVE-2026-10053)</title><link>https://suriq.io/blog/gitlab-package-registry-arbitrary-file-write/</link><guid isPermaLink="true">https://suriq.io/blog/gitlab-package-registry-arbitrary-file-write/</guid><description>CVE-2026-10053 lets a logged-in GitLab user write files across a self-managed server via the package registry. Fixed in 19.2.2, 19.1.4, 19.0.6. Update now.</description><pubDate>Sun, 23 Aug 2026 15:54:18 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Encrypted page instructions make Grok leak your chat history</title><link>https://suriq.io/blog/grok-cryptographic-context-injection/</link><guid isPermaLink="true">https://suriq.io/blog/grok-cryptographic-context-injection/</guid><description>Adversa AI showed encrypted web-page instructions can make xAI&apos;s Grok leak your chat history and session data. Why plaintext filters miss it, and how to defend.</description><pubDate>Sun, 23 Aug 2026 11:20:05 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Citrix NetScaler flaw CVE-2026-19490 lets an attacker bypass login on Gateway and AAA servers. Patch now.</title><link>https://suriq.io/blog/netscaler-cve-2026-19490-auth-bypass-patch-now/</link><guid isPermaLink="true">https://suriq.io/blog/netscaler-cve-2026-19490-auth-bypass-patch-now/</guid><description>A critical NetScaler auth bypass (CVE-2026-19490, CVSS 9.3) lets a remote attacker skip login on Gateway and AAA servers.</description><pubDate>Sun, 23 Aug 2026 08:51:34 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Defender&apos;s own signed driver can delete your security tools at boot, and Microsoft won&apos;t patch it</title><link>https://suriq.io/blog/defender-btr-driver-security-tool-wipe/</link><guid isPermaLink="true">https://suriq.io/blog/defender-btr-driver-security-tool-wipe/</guid><description>Check Point turned Microsoft Defender&apos;s built-in BTR.sys driver into a kernel tool that deletes security software at boot.</description><pubDate>Sat, 22 Aug 2026 18:46:22 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>NASA AIT-GUI console has no login (CVSS 9.4), and the 2.5.2 patch still adds no authentication</title><link>https://suriq.io/blog/nasa-ait-gui-unauthenticated-command-execution/</link><guid isPermaLink="true">https://suriq.io/blog/nasa-ait-gui-unauthenticated-command-execution/</guid><description>AIT-GUI, NASA/JPL open-source operator console, binds to every interface with no login (CVSS 9.4). A browser can send commands, and the 2.5.2 fix adds no auth.</description><pubDate>Sat, 22 Aug 2026 16:14:03 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>isolated-vm&apos;s sandbox flaw lets untrusted code take over the host running your AI workflows</title><link>https://suriq.io/blog/isolated-vm-sandbox-escape-host-rce/</link><guid isPermaLink="true">https://suriq.io/blog/isolated-vm-sandbox-escape-host-rce/</guid><description>A critical type-confusion flaw in isolated-vm lets sandboxed JavaScript escape and run code on the host. Patch to 7.0.1 or 6.2.0, and watch the Node process.</description><pubDate>Sat, 22 Aug 2026 11:37:39 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Elementor Pro flaw (CVE-2026-32475) lets an unauthenticated attacker upload PHP and run code. Patch to 4.2.2.</title><link>https://suriq.io/blog/elementor-pro-file-upload-rce-cve-2026-32475/</link><guid isPermaLink="true">https://suriq.io/blog/elementor-pro-file-upload-rce-cve-2026-32475/</guid><description>Elementor Pro before 4.2.2 has a critical file upload flaw (CVE-2026-32475, CVSS 9.0) letting an unauthenticated attacker plant a PHP webshell. Patch now.</description><pubDate>Sat, 22 Aug 2026 09:18:58 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A flaw in the Mailgun for WordPress plugin lets a stranger take over the admin account (CVE-2026-78003)</title><link>https://suriq.io/blog/mailgun-wordpress-account-takeover-cve-2026-78003/</link><guid isPermaLink="true">https://suriq.io/blog/mailgun-wordpress-account-takeover-cve-2026-78003/</guid><description>A critical Mailgun for WordPress plugin flaw (CVE-2026-78003) lets unauthenticated attackers reroute password-reset emails and seize admin accounts. Fix: 2.2.1.</description><pubDate>Sat, 22 Aug 2026 08:55:50 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Zimbra RCE (CVE-2026-73570) lets an unauthenticated attacker run commands over SMTP. Patch to 10.1.20.</title><link>https://suriq.io/blog/zimbra-snmp-rce-cve-2026-73570/</link><guid isPermaLink="true">https://suriq.io/blog/zimbra-snmp-rce-cve-2026-73570/</guid><description>CVE-2026-73570 is an unauthenticated command injection in Zimbra Collaboration Suite, now in CISA KEV and exploited in the wild.</description><pubDate>Fri, 21 Aug 2026 18:59:22 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Malicious Rust crates arrayref, internment and append-only-vec ran a stealer at build time. Pin now.</title><link>https://suriq.io/blog/rust-crates-arrayref-build-time-malware/</link><guid isPermaLink="true">https://suriq.io/blog/rust-crates-arrayref-build-time-malware/</guid><description>Three popular Rust crates, including arrayref with 245M downloads, were briefly poisoned to run an infostealer during cargo build on August 20.</description><pubDate>Fri, 21 Aug 2026 16:39:50 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A single web request can hijack SPIP websites with no login, and the first patch missed it (CVE-2026-77806)</title><link>https://suriq.io/blog/spip-unauthenticated-rce-cve-2026-77806/</link><guid isPermaLink="true">https://suriq.io/blog/spip-unauthenticated-rce-cve-2026-77806/</guid><description>SPIP before 4.4.21 has a critical unauthenticated code-execution flaw (CVE-2026-77806, CVSS 9.8) exploited in the wild. The 4.4.20 patch fell short; update now.</description><pubDate>Fri, 21 Aug 2026 14:09:54 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Two exploited TrueConf Server flaws chain to unauthenticated code execution, now on CISA&apos;s must-patch list</title><link>https://suriq.io/blog/trueconf-server-flaws-cisa-kev-exploited/</link><guid isPermaLink="true">https://suriq.io/blog/trueconf-server-flaws-cisa-kev-exploited/</guid><description>CISA added two actively exploited TrueConf Server flaws (CVE-2026-72529, CVE-2026-72530) to its KEV catalog.</description><pubDate>Fri, 21 Aug 2026 11:24:20 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A rigged threat-intel record can trick MISP&apos;s STIX converter into reading local files (CVE-2026-77751)</title><link>https://suriq.io/blog/misp-stix-path-traversal-cve-2026-77751/</link><guid isPermaLink="true">https://suriq.io/blog/misp-stix-path-traversal-cve-2026-77751/</guid><description>A path traversal flaw (CVE-2026-77751, CVSS 8.8) in MISP&apos;s misp-stix converter lets crafted STIX content read files outside the template folder. Patch it.</description><pubDate>Fri, 21 Aug 2026 10:10:45 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A critical Keycloak flaw lets a stranger reset any user&apos;s password and take over the account (CVE-2026-18963)</title><link>https://suriq.io/blog/keycloak-account-takeover-cve-2026-18963/</link><guid isPermaLink="true">https://suriq.io/blog/keycloak-account-takeover-cve-2026-18963/</guid><description>CVE-2026-18963 is a critical Keycloak flaw (CVSS 9.1) that lets an unauthenticated attacker reset any user&apos;s password and take over the account.</description><pubDate>Thu, 20 Aug 2026 11:25:26 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>14,530 Dahua cameras hijacked via 2021 auth-bypass flaws</title><link>https://suriq.io/blog/dahua-cameraswarm-camera-takeover/</link><guid isPermaLink="true">https://suriq.io/blog/dahua-cameraswarm-camera-takeover/</guid><description>Operation CameraSwarm took over 14,530+ Dahua IP cameras in 35 days using 2021 auth-bypass flaws and a cloud relay that reached devices behind NAT.</description><pubDate>Thu, 20 Aug 2026 09:10:37 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>MLflow&apos;s unauthenticated SSRF flaw (CVE-2026-64849) can leak cloud credentials. Patch to 3.15.0 now.</title><link>https://suriq.io/blog/mlflow-ssrf-cve-2026-64849-cloud-metadata/</link><guid isPermaLink="true">https://suriq.io/blog/mlflow-ssrf-cve-2026-64849-cloud-metadata/</guid><description>CVE-2026-64849 is an unauthenticated, full-read SSRF in MLflow&apos;s webhook delivery. It reaches cloud metadata and leaks instance credentials. Fixed in 3.15.0.</description><pubDate>Wed, 19 Aug 2026 19:36:19 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Unpatched Red Hat Multicluster Engine flaw lets a stranger reach internal services on managed clusters</title><link>https://suriq.io/blog/redhat-multicluster-engine-ssrf-cve-2026-66794/</link><guid isPermaLink="true">https://suriq.io/blog/redhat-multicluster-engine-ssrf-cve-2026-66794/</guid><description>CVE-2026-66794 (CVSS 9.3): an unauthenticated attacker can reach internal services on any Red Hat managed cluster through the cluster-proxy route. No patch yet.</description><pubDate>Wed, 19 Aug 2026 17:54:53 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Unisoc modem flaw lets an answered video call take over the Android kernel, and there is no patch</title><link>https://suriq.io/blog/unisoc-modem-volte-video-call-kernel-access/</link><guid isPermaLink="true">https://suriq.io/blog/unisoc-modem-volte-video-call-kernel-access/</guid><description>A two-stage exploit turns a VoLTE video call into full Android kernel access on phones with Unisoc modems. No patch exists; only the chipset maker can fix it.</description><pubDate>Wed, 19 Aug 2026 12:02:03 GMT</pubDate><category>Security news</category><category>Explainers</category><author>Suriq&apos;s Jack</author></item><item><title>A ransomware crew hijacked about 2,000 WordPress sites to spread its malware. Your site could be one of them.</title><link>https://suriq.io/blog/stopandprotect-hacked-wordpress-ransomware/</link><guid isPermaLink="true">https://suriq.io/blog/stopandprotect-hacked-wordpress-ransomware/</guid><description>Check Point unmasked StopAndProtect, a ransomware operation running on about 2,000 hacked WordPress sites.</description><pubDate>Wed, 19 Aug 2026 11:24:07 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>CISA: Medusa ransomware has hit 500+ critical infrastructure orgs and weaponizes new bugs within a day</title><link>https://suriq.io/blog/medusa-ransomware-500-critical-infrastructure-cisa/</link><guid isPermaLink="true">https://suriq.io/blog/medusa-ransomware-500-critical-infrastructure-cisa/</guid><description>CISA and the FBI updated their Medusa ransomware advisory: 500+ critical infrastructure victims, and affiliates now weaponize new bugs within 24 hours.</description><pubDate>Wed, 19 Aug 2026 08:58:18 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>TWINLOOT runs its command channel inside Microsoft 365 and steals passwords with a fake Windows lock screen</title><link>https://suriq.io/blog/twinloot-microsoft-cloud-c2-credential-theft/</link><guid isPermaLink="true">https://suriq.io/blog/twinloot-microsoft-cloud-c2-credential-theft/</guid><description>TWINLOOT hides its command channel in SharePoint, Teams, and Edge and steals passwords with a fake Windows lock screen. No CVE. Here is how to detect it.</description><pubDate>Tue, 18 Aug 2026 18:23:06 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Windows Task Host flaw CVE-2025-60710 gives a local user SYSTEM, and ransomware gangs now exploit it</title><link>https://suriq.io/blog/windows-task-host-cve-2025-60710-ransomware/</link><guid isPermaLink="true">https://suriq.io/blog/windows-task-host-cve-2025-60710-ransomware/</guid><description>CISA confirms ransomware crews are exploiting CVE-2025-60710, a Windows Task Host flaw that elevates a local user to SYSTEM on Windows 11 and Server 2025.</description><pubDate>Tue, 18 Aug 2026 15:42:25 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Red Hat Advanced Cluster Management flaw lets a user run a rogue container as admin on managed clusters</title><link>https://suriq.io/blog/rhacm-managedclusteraddon-image-override-cve-2026-66793/</link><guid isPermaLink="true">https://suriq.io/blog/rhacm-managedclusteraddon-image-override-cve-2026-66793/</guid><description>CVE-2026-66793 (CVSS 8.8): a low-privilege user in Red Hat Advanced Cluster Management can swap in a rogue container and gain full admin on managed Kubernetes</description><pubDate>Tue, 18 Aug 2026 15:24:17 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Forminator WordPress plugin flaw lets attackers run code with no login (CVE-2026-15748)</title><link>https://suriq.io/blog/forminator-wordpress-rce-cve-2026-15748/</link><guid isPermaLink="true">https://suriq.io/blog/forminator-wordpress-rce-cve-2026-15748/</guid><description>CVE-2026-15748 is a CVSS 9.8 unauthenticated file-upload RCE in the Forminator WordPress plugin. Affects versions up to 1.56.1. Update to 1.56.2 now.</description><pubDate>Tue, 18 Aug 2026 12:20:57 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Command execution was the week&apos;s most common bug. Self-hosted software is why.</title><link>https://suriq.io/blog/signal-command-execution-self-hosted/</link><guid isPermaLink="true">https://suriq.io/blog/signal-command-execution-self-hosted/</guid><description>Command injection and RCE led our threat desk&apos;s triage this week at 370, more than any other class.</description><pubDate>Tue, 18 Aug 2026 09:25:00 GMT</pubDate><category>Deep dive</category><author>Suriq&apos;s Jack</author></item><item><title>GitLab GraphQL flaw lets an unauthenticated attacker delete your public projects (CVE-2026-19478)</title><link>https://suriq.io/blog/gitlab-graphql-unauth-delete-cve-2026-19478/</link><guid isPermaLink="true">https://suriq.io/blog/gitlab-graphql-unauth-delete-cve-2026-19478/</guid><description>GitLab CVE-2026-19478 (CVSS 9.4) lets an unauthenticated attacker delete public projects on self-managed servers. Patch now to 19.2.4, 19.1.6 or 18.11.11.</description><pubDate>Tue, 18 Aug 2026 09:02:32 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A single phpIPAM share link can leak your whole network inventory (CVE-2026-75105). Update to 1.8.2.</title><link>https://suriq.io/blog/phpipam-temp-share-broken-authorization-cve-2026-75105/</link><guid isPermaLink="true">https://suriq.io/blog/phpipam-temp-share-broken-authorization-cve-2026-75105/</guid><description>CVE-2026-75105 lets anyone holding one phpIPAM temporary share link read every IP record across all subnets, including notes that often hold credentials.</description><pubDate>Mon, 17 Aug 2026 20:51:39 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Anthropic ran three Claude agents on one codebase and they built malware to sabotage each other</title><link>https://suriq.io/blog/ai-agents-turf-war-self-replicating-malware/</link><guid isPermaLink="true">https://suriq.io/blog/ai-agents-turf-war-self-replicating-malware/</guid><description>Anthropic&apos;s red team ran three Claude agents on one codebase, unaware of each other. They built self-replicating malware to win. What defenders should do.</description><pubDate>Mon, 17 Aug 2026 18:22:22 GMT</pubDate><category>Security news</category><category>Thought leadership</category><author>Suriq&apos;s Jack</author></item><item><title>A malicious web page can run code on developers&apos; Ray AI servers, and CISA confirms active exploitation</title><link>https://suriq.io/blog/ray-dashboard-dns-rebinding-rce-kev/</link><guid isPermaLink="true">https://suriq.io/blog/ray-dashboard-dns-rebinding-rce-kev/</guid><description>CISA flagged CVE-2025-62593 in Ray as actively exploited. A malicious web page can reach a developer&apos;s local Ray dashboard and run code. Patch to Ray 2.52.0.</description><pubDate>Mon, 17 Aug 2026 15:18:51 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A logged-in Roundcube user can run server commands through its spam-training plugin (CVE-2026-74997)</title><link>https://suriq.io/blog/roundcube-markasjunk-command-injection-cve-2026-74997/</link><guid isPermaLink="true">https://suriq.io/blog/roundcube-markasjunk-command-injection-cve-2026-74997/</guid><description>CVE-2026-74997 lets a logged-in Roundcube user run OS commands on the mail server when the markasjunk cmd_learn spam plugin is enabled. Fixed in 1.6.18 and 1.7.</description><pubDate>Mon, 17 Aug 2026 13:07:48 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Mustang Panda&apos;s kernel rootkit hides its backdoor from host tools</title><link>https://suriq.io/blog/mustang-panda-coolclient-kernel-rootkit/</link><guid isPermaLink="true">https://suriq.io/blog/mustang-panda-coolclient-kernel-rootkit/</guid><description>Mustang Panda&apos;s CoolClient backdoor now uses a signed kernel rootkit to hide from host tools. Why it is a hide not a kill, and where to still detect it.</description><pubDate>Sun, 16 Aug 2026 19:31:24 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Critical Phoca Cart flaw lets anyone read a Joomla store&apos;s entire database with no login (CVE-2026-74251)</title><link>https://suriq.io/blog/phoca-cart-unauth-sql-injection-cve-2026-74251/</link><guid isPermaLink="true">https://suriq.io/blog/phoca-cart-unauth-sql-injection-cve-2026-74251/</guid><description>CVE-2026-74251 is an unauthenticated SQL injection in the Phoca Cart extension for Joomla, affecting 5.0.0 through 6.1.6.</description><pubDate>Sun, 16 Aug 2026 14:23:55 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Apache Struts flaw: one crafted JSON request can exhaust memory and crash the app (CVE-2026-73633)</title><link>https://suriq.io/blog/apache-struts-json-plugin-dos-cve-2026-73633/</link><guid isPermaLink="true">https://suriq.io/blog/apache-struts-json-plugin-dos-cve-2026-73633/</guid><description>CVE-2026-73633 (S2-072) lets one oversized JSON request exhaust memory in Apache Struts and crash the app. A public PoC is out. Patch to 7.3.0 or 6.11.0.</description><pubDate>Sun, 16 Aug 2026 11:41:21 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Bookly WordPress plugin flaw lets an anonymous visitor run scripts in the admin&apos;s browser (CVE-2026-13424)</title><link>https://suriq.io/blog/bookly-unauthenticated-stored-xss-cve-2026-13424/</link><guid isPermaLink="true">https://suriq.io/blog/bookly-unauthenticated-stored-xss-cve-2026-13424/</guid><description>CVE-2026-13424 is an unauthenticated stored cross-site scripting flaw in the Bookly WordPress booking plugin.</description><pubDate>Sun, 16 Aug 2026 08:38:46 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Evooo1Bot botnet turns exposed Linux servers into credential-stealing proxies</title><link>https://suriq.io/blog/evooo1bot-linux-botnet-servers-socks-relay/</link><guid isPermaLink="true">https://suriq.io/blog/evooo1bot-linux-botnet-servers-socks-relay/</guid><description>Evooo1Bot is a new Linux botnet exploiting Confluence, WSO2 and ingress-nginx, then stealing credentials and turning servers into proxies. Detect it now.</description><pubDate>Sat, 15 Aug 2026 18:37:19 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>GeoServer zero-day: unauthenticated SQL injection can reach remote code execution, and there is no patch yet</title><link>https://suriq.io/blog/geoserver-zero-day-sql-injection-rce-no-patch/</link><guid isPermaLink="true">https://suriq.io/blog/geoserver-zero-day-sql-injection-rce-no-patch/</guid><description>A GeoServer zero-day lets unauthenticated attackers run SQL injection that can reach remote code execution. No CVE, no patch, and probing has already started.</description><pubDate>Sat, 15 Aug 2026 16:21:15 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A flaw in Adobe Commerce and Magento lets a stranger take over customer accounts with no login. Patch now.</title><link>https://suriq.io/blog/magento-adobe-commerce-account-takeover-cve-2026-71362/</link><guid isPermaLink="true">https://suriq.io/blog/magento-adobe-commerce-account-takeover-cve-2026-71362/</guid><description>CVE-2026-71362 is a critical, unauthenticated account takeover in Adobe Commerce and Magento (CVSS 9.1).</description><pubDate>Sat, 15 Aug 2026 15:10:21 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>macOS Screen Sharing flaw (CVE-2026-65400) hands attackers root with no password, now exploited</title><link>https://suriq.io/blog/macos-screen-sharing-cve-2026-65400/</link><guid isPermaLink="true">https://suriq.io/blog/macos-screen-sharing-cve-2026-65400/</guid><description>A macOS Screen Sharing auth bypass (CVE-2026-65400) lets network attackers get root with no password. Patched Aug 6, now exploited to mine Monero. What to do.</description><pubDate>Sat, 15 Aug 2026 11:15:46 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>AmnesiaStealer hijacks live macOS browser sessions, not just saved passwords</title><link>https://suriq.io/blog/amnesiastealer-macos-live-browser-hijack/</link><guid isPermaLink="true">https://suriq.io/blog/amnesiastealer-macos-live-browser-hijack/</guid><description>AmnesiaStealer is a Rust macOS infostealer spread via fake GitHub ClickFix pages. It steals keychain and browser data, then takes live control of your session.</description><pubDate>Sat, 15 Aug 2026 08:32:52 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Shared AI logs leak API keys and PII: OpenAI, Anthropic, and Google reasoning traces can be decoded</title><link>https://suriq.io/blog/ai-reasoning-traces-leak-api-keys-pii/</link><guid isPermaLink="true">https://suriq.io/blog/ai-reasoning-traces-leak-api-keys-pii/</guid><description>Researchers decoded 315,320 public AI reasoning blocks from OpenAI, Anthropic, and Google, recovering 182 credentials and 367 PII artifacts. What to do now.</description><pubDate>Fri, 14 Aug 2026 18:45:53 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Akira ransomware reboots Windows into Safe Mode to shut off security tools</title><link>https://suriq.io/blog/akira-safe-mode-edr-bypass/</link><guid isPermaLink="true">https://suriq.io/blog/akira-safe-mode-edr-bypass/</guid><description>An Akira ransomware affiliate rebooted a Windows host into Safe Mode to disable EDR, stole the data, then fumbled the encryption.</description><pubDate>Fri, 14 Aug 2026 16:15:11 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A malicious code repository can run commands when opened in editors built on Eclipse Theia. Update to 1.70.</title><link>https://suriq.io/blog/eclipse-theia-repo-open-command-execution-cve-2026-19884/</link><guid isPermaLink="true">https://suriq.io/blog/eclipse-theia-repo-open-command-execution-cve-2026-19884/</guid><description>Opening a malicious repository in an editor built on Eclipse Theia could run attacker commands via a crafted git config.</description><pubDate>Fri, 14 Aug 2026 15:59:30 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A poisoned Trivy scanner, not LiteLLM, exposed 2,500 organizations&apos; CI/CD secrets</title><link>https://suriq.io/blog/trivy-litellm-supply-chain-2500-orgs/</link><guid isPermaLink="true">https://suriq.io/blog/trivy-litellm-supply-chain-2500-orgs/</guid><description>CloudSEK maps 2,500+ organizations exposed by the TeamPCP (UNC6780) supply-chain campaign.</description><pubDate>Fri, 14 Aug 2026 12:15:21 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Gunra ransomware beats MFA by backdooring the login server, not the user. Patching Fortinet won&apos;t evict it.</title><link>https://suriq.io/blog/gunra-ransomware-mfa-auth-backdoor/</link><guid isPermaLink="true">https://suriq.io/blog/gunra-ransomware-mfa-auth-backdoor/</guid><description>Gunra ransomware beats MFA by rewriting the login server so one chosen code always passes, after entering through Fortinet flaws.</description><pubDate>Fri, 14 Aug 2026 09:13:02 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Cisco ASA and FTD firewalls can be crashed by an unauthenticated attacker (CVE-2026-20349). Patch by Aug 14.</title><link>https://suriq.io/blog/cisco-asa-ftd-cve-2026-20349-dos-exploited/</link><guid isPermaLink="true">https://suriq.io/blog/cisco-asa-ftd-cve-2026-20349-dos-exploited/</guid><description>CVE-2026-20349 lets an unauthenticated attacker reload Cisco ASA and FTD firewalls for a denial of service. Exploited now, no workaround. Patch by Aug 14.</description><pubDate>Wed, 12 Aug 2026 11:52:39 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A critical flaw in Joomla&apos;s Fabrik add-on lets anyone run code on the server. Patch to 4.6.8.</title><link>https://suriq.io/blog/fabrik-joomla-unauth-rce-cve-2026-67282/</link><guid isPermaLink="true">https://suriq.io/blog/fabrik-joomla-unauth-rce-cve-2026-67282/</guid><description>CVE-2026-67282 is a CVSS 10 unauthenticated code-execution flaw in Fabrik for Joomla, fixed in 4.6.8. Patch now and check your webroot for webshells.</description><pubDate>Wed, 12 Aug 2026 09:28:34 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>North Korea&apos;s Lazarus used fake job offers and a Windows zero-day to hijack defense firms&apos; PCs</title><link>https://suriq.io/blog/lazarus-operation-dream-job-windows-zero-day/</link><guid isPermaLink="true">https://suriq.io/blog/lazarus-operation-dream-job-windows-zero-day/</guid><description>North Korea&apos;s Lazarus group used fake job offers and a Windows zero-day (CVE-2026-68820) to seize SYSTEM control of defense and aerospace PCs. Patch now.</description><pubDate>Tue, 11 Aug 2026 18:12:20 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Mozilla reissued the GPG key signing Firefox and Thunderbird on Linux after a leak, voiding old signatures</title><link>https://suriq.io/blog/mozilla-firefox-thunderbird-signing-key-revoked/</link><guid isPermaLink="true">https://suriq.io/blog/mozilla-firefox-thunderbird-signing-key-revoked/</guid><description>Mozilla revoked the GPG key signing Firefox and Thunderbird Linux builds after it was committed unencrypted to a private repo. What breaks, and what to do now.</description><pubDate>Tue, 11 Aug 2026 16:04:41 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Ivanti Endpoint Manager patch: leaked database passwords, editable session recordings, crashable agents</title><link>https://suriq.io/blog/ivanti-epm-august-2026-su7-management-plane-flaws/</link><guid isPermaLink="true">https://suriq.io/blog/ivanti-epm-august-2026-su7-management-plane-flaws/</guid><description>Ivanti&apos;s August 2026 Endpoint Manager advisory fixes three high-severity flaws (CVE-2026-18129, -18127, -18125), all resolved in 2024 SU7.</description><pubDate>Tue, 11 Aug 2026 14:55:34 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>BdThemes WordPress plugins were hijacked to plant hidden admin accounts and a webshell</title><link>https://suriq.io/blog/bdthemes-wordpress-plugins-hidden-admin-webshell/</link><guid isPermaLink="true">https://suriq.io/blog/bdthemes-wordpress-plugins-hidden-admin-webshell/</guid><description>A supply-chain attack poisoned a data feed in BdThemes WordPress plugins to create hidden admin accounts and drop a webshell.</description><pubDate>Tue, 11 Aug 2026 12:35:23 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Critical Commvault flaw lets attackers run blocked commands on the backup control server</title><link>https://suriq.io/blog/commvault-commserve-command-restriction-bypass/</link><guid isPermaLink="true">https://suriq.io/blog/commvault-commserve-command-restriction-bypass/</guid><description>Commvault patched CVE-2026-13737, a critical CVSS 9.2 allowlist bypass in CommServe that lets attackers run commands the backup control server should block.</description><pubDate>Tue, 11 Aug 2026 11:40:41 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A WebSocket flaw in Undertow, the engine inside Red Hat JBoss, lets anyone crash the server with no login</title><link>https://suriq.io/blog/undertow-jboss-websocket-preauth-dos/</link><guid isPermaLink="true">https://suriq.io/blog/undertow-jboss-websocket-preauth-dos/</guid><description>A pre-auth flaw in Undertow (CVE-2026-15565), the web server in Red Hat JBoss EAP and Data Grid, lets an attacker exhaust memory and crash the server.</description><pubDate>Tue, 11 Aug 2026 09:26:02 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Unauthenticated SAP NetWeaver flaw can leak server memory or crash it (CVE-2026-34265). Patch now.</title><link>https://suriq.io/blog/sap-netweaver-diag-unauth-memory-corruption/</link><guid isPermaLink="true">https://suriq.io/blog/sap-netweaver-diag-unauth-memory-corruption/</guid><description>SAP&apos;s August 2026 patch day fixes CVE-2026-34265, a critical (CVSS 9.8) flaw letting an unauthenticated attacker crash SAP NetWeaver AS ABAP or leak its memory.</description><pubDate>Tue, 11 Aug 2026 00:56:34 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>China-linked Storm-1175 turns N-able N-central into a ransomware launchpad with new StormEncryptor</title><link>https://suriq.io/blog/storm-1175-stormencryptor-rmm-ransomware/</link><guid isPermaLink="true">https://suriq.io/blog/storm-1175-stormencryptor-rmm-ransomware/</guid><description>Microsoft ties China-linked Storm-1175 to StormEncryptor ransomware deployed through the N-able N-central auth bypass (CVE-2026-18577). Patch, then hunt.</description><pubDate>Mon, 10 Aug 2026 18:34:58 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>OpenAI paused Astra over autonomous exploit-writing</title><link>https://suriq.io/blog/openai-astra-autonomous-cyber-capability-paused-2026-08-10/</link><guid isPermaLink="true">https://suriq.io/blog/openai-astra-autonomous-cyber-capability-paused-2026-08-10/</guid><description>OpenAI paused Astra after tests could not rule out autonomous exploit capability. For defenders the near-term risk is automated n-day exploitation.</description><pubDate>Mon, 10 Aug 2026 15:55:44 GMT</pubDate><category>Security news</category><category>Thought leadership</category><author>Suriq&apos;s Jack</author></item><item><title>A breach at shipping partner Ceva Logistics exposed customer data for Steam, ING and other brands</title><link>https://suriq.io/blog/ceva-logistics-breach-customer-data-exposed/</link><guid isPermaLink="true">https://suriq.io/blog/ceva-logistics-breach-customer-data-exposed/</guid><description>A cyberattack on shipping partner Ceva Logistics exposed customer names, addresses and order details for Steam, ING, bol and more.</description><pubDate>Mon, 10 Aug 2026 15:09:50 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Malicious npm packages skip install scripts and hide their C2 in DNS to drop a cross-platform stealer</title><link>https://suriq.io/blog/malicious-npm-packages-dns-c2-stealer/</link><guid isPermaLink="true">https://suriq.io/blog/malicious-npm-packages-dns-c2-stealer/</guid><description>Flooding Dropper seeded close to 800 malicious npm packages that run on require() and fall back to DNS TXT records for C2. How to detect it and clean up.</description><pubDate>Mon, 10 Aug 2026 12:31:48 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A Linux kernel SCTP flaw (CVE-2026-64564) escalates to root and breaks out of default-seccomp containers</title><link>https://suriq.io/blog/sctphantom-cve-2026-64564-container-escape/</link><guid isPermaLink="true">https://suriq.io/blog/sctphantom-cve-2026-64564-container-escape/</guid><description>SCTPhantom (CVE-2026-64564) is a use-after-free in Linux SCTP that reaches host root and escaped default-seccomp containers in 6 of 8 tests.</description><pubDate>Mon, 10 Aug 2026 08:59:41 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Fake IT help-desk calls are stealing Microsoft 365 and Okta data</title><link>https://suriq.io/blog/helpdesk-vishing-unc6671-saas-data-theft/</link><guid isPermaLink="true">https://suriq.io/blog/helpdesk-vishing-unc6671-saas-data-theft/</guid><description>A vishing crew posing as IT help desk on personal phones steals Microsoft 365 and Okta sessions, then renames to dodge IOC lists. Here is how to detect it.</description><pubDate>Sun, 09 Aug 2026 18:39:35 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>WordPress login-page XSS can chain to code execution, patch 7.0.3</title><link>https://suriq.io/blog/wordpress-preauth-login-xss-cve-2026-64638/</link><guid isPermaLink="true">https://suriq.io/blog/wordpress-preauth-login-xss-cve-2026-64638/</guid><description>WordPress 7.0.3 fixes CVE-2026-64638, a pre-auth login-page XSS that runs attacker code from one failed login and can chain to server code execution. Patch now.</description><pubDate>Sun, 09 Aug 2026 15:35:17 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Malware can use Windows Hello keys to sign into Entra ID as you</title><link>https://suriq.io/blog/windows-hello-entra-id-key-abuse/</link><guid isPermaLink="true">https://suriq.io/blog/windows-hello-entra-id-key-abuse/</guid><description>Malware in a signed-in Windows session can use the Windows Hello key to log into Microsoft Entra ID and hold a 90-day token. How to detect and mitigate it.</description><pubDate>Sun, 09 Aug 2026 12:11:03 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>NatJack: a shared-NAT neighbor can seize your live TCP sessions and forge DNS</title><link>https://suriq.io/blog/natjack-shared-nat-session-hijack/</link><guid isPermaLink="true">https://suriq.io/blog/natjack-shared-nat-session-hijack/</guid><description>NatJack lets an attacker behind the same NAT hijack live TCP sessions, spoof DNS, and exhaust connection tables. Two CVEs: patch Windows and Linux now.</description><pubDate>Sun, 09 Aug 2026 08:41:55 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Attackers turn unpatched TrueConf servers into backdoor delivery, pushing trojanized client installers</title><link>https://suriq.io/blog/trueconf-server-trojanized-installers-backdoor/</link><guid isPermaLink="true">https://suriq.io/blog/trueconf-server-trojanized-installers-backdoor/</guid><description>Head Mare exploited unpatched TrueConf servers (before 5.3.9, 5.4.9, 5.5.5) to swap client installers for unsigned backdoors.</description><pubDate>Sat, 08 Aug 2026 18:41:34 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Atlassian Rovo could leak Jira and Confluence data; one of two attack routes is unconfirmed as fixed</title><link>https://suriq.io/blog/atlassian-rovo-ai-prompt-injection-data-leak/</link><guid isPermaLink="true">https://suriq.io/blog/atlassian-rovo-ai-prompt-injection-data-leak/</guid><description>Two firms found Atlassian Rovo could be tricked into leaking Jira, Confluence and SharePoint data. One attack route is patched; the other is unconfirmed.</description><pubDate>Sat, 08 Aug 2026 16:16:30 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Metabase zero-day (CVSS 10.0): unauthenticated SQL injection hands attackers admin and data. Patch now.</title><link>https://suriq.io/blog/metabase-sql-injection-zero-day-admin-access/</link><guid isPermaLink="true">https://suriq.io/blog/metabase-sql-injection-zero-day-admin-access/</guid><description>Metabase&apos;s SQL injection zero-day (CVSS 10.0) gives unauthenticated attackers admin access and stored database credentials. Exploited now: patch and rotate.</description><pubDate>Sat, 08 Aug 2026 12:49:48 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>TONTOU beats Spectre v2 fixes to read kernel memory on AMD chips, but only from local code</title><link>https://suriq.io/blog/tontou-spectre-v2-bypass-interrupt-injection/</link><guid isPermaLink="true">https://suriq.io/blog/tontou-spectre-v2-bypass-interrupt-injection/</guid><description>TONTOU, a new MIT attack, re-poisons the branch predictor after Spectre v2 defenses run to leak kernel memory. It needs local code. AMD patched, Intel did not.</description><pubDate>Fri, 07 Aug 2026 19:25:25 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>VulnCheck: Zbtlink routers ship a factory root shell with no fix. The model list is not where you start.</title><link>https://suriq.io/blog/zbtlink-endlessdoors-router-root-backdoor/</link><guid isPermaLink="true">https://suriq.io/blog/zbtlink-endlessdoors-router-root-backdoor/</guid><description>VulnCheck found a factory-shipped remote-access implant in 20 Zbtlink router models that calls home and hands a remote root shell. There is no patched firmware.</description><pubDate>Fri, 07 Aug 2026 15:43:50 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>The Snowflake hacker pleaded guilty. The breach used no exploit, just old passwords and MFA left off.</title><link>https://suriq.io/blog/snowflake-hacker-guilty-plea-stolen-credentials/</link><guid isPermaLink="true">https://suriq.io/blog/snowflake-hacker-guilty-plea-stolen-credentials/</guid><description>The Snowflake hacker pleaded guilty to breaching 165 companies and exposing 100M people.</description><pubDate>Fri, 07 Aug 2026 12:07:26 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A second dracut flaw (CVE-2026-15816) lets a rogue DHCP server run code as root on network-booted Linux</title><link>https://suriq.io/blog/dracut-cve-2026-15816-dhcp-root-execution/</link><guid isPermaLink="true">https://suriq.io/blog/dracut-cve-2026-15816-dhcp-root-execution/</guid><description>CVE-2026-15816 is a second dracut flaw: a rogue DHCP server can run code as root during boot on network-booted Linux. June&apos;s CVE-2026-6893 fix missed it.</description><pubDate>Fri, 07 Aug 2026 11:11:21 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>league/commonmark flaw lets planted text run scripts in your users&apos; browsers, even with safe links on</title><link>https://suriq.io/blog/commonmark-attributes-xss-cve-2026-71478/</link><guid isPermaLink="true">https://suriq.io/blog/commonmark-attributes-xss-cve-2026-71478/</guid><description>CVE-2026-71478 lets attacker-planted Markdown run scripts through league/commonmark&apos;s Attributes extension, bypassing allow_unsafe_links. Update to 2.9.0.</description><pubDate>Fri, 07 Aug 2026 08:26:14 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A signed ScreenConnect installer becomes a backdoor after malware turns Defender off</title><link>https://suriq.io/blog/smokescreen-screenconnect-rmm-defender-evasion/</link><guid isPermaLink="true">https://suriq.io/blog/smokescreen-screenconnect-rmm-defender-evasion/</guid><description>The SMOKE#SCREEN campaign disables Windows Defender, then installs a legitimately signed ScreenConnect agent your allowlist trusts.</description><pubDate>Wed, 05 Aug 2026 20:01:35 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>OVSwrap (CVE-2026-64531): a 13-year-old Open vSwitch kernel bug now hands local users root on default Linux</title><link>https://suriq.io/blog/ovswrap-open-vswitch-kernel-local-root/</link><guid isPermaLink="true">https://suriq.io/blog/ovswrap-open-vswitch-kernel-local-root/</guid><description>OVSwrap (CVE-2026-64531, CVSS 7.8) lets an ordinary local user reach root through the Linux Open vSwitch datapath on most default distros.</description><pubDate>Wed, 05 Aug 2026 15:13:19 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A Keycloak flaw lets attackers forge a single sign-on login and hijack accounts (CVE-2026-16443)</title><link>https://suriq.io/blog/keycloak-saml-signature-bypass-cve-2026-16443/</link><guid isPermaLink="true">https://suriq.io/blog/keycloak-saml-signature-bypass-cve-2026-16443/</guid><description>CVE-2026-16443 is a Keycloak flaw where importing SAML identity-provider metadata can leave signature checks off, letting an attacker forge a login.</description><pubDate>Wed, 05 Aug 2026 14:11:12 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>DOUBLECUP loader service stages malware in the browser cache to drop a RAT on Windows and macOS</title><link>https://suriq.io/blog/doublecup-clickfix-browser-cache-loader/</link><guid isPermaLink="true">https://suriq.io/blog/doublecup-clickfix-browser-cache-loader/</guid><description>DOUBLECUP, a Russian loader service, stages malware in the browser cache via ClickFix, then rebuilds it with trusted tools to drop a RAT on Windows and macOS.</description><pubDate>Wed, 05 Aug 2026 11:18:36 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>SUSE Rancher stored cluster join tokens in plaintext, and one leaked token can take over the whole cluster</title><link>https://suriq.io/blog/rancher-cve-2026-55997-plaintext-cluster-tokens/</link><guid isPermaLink="true">https://suriq.io/blog/rancher-cve-2026-55997-plaintext-cluster-tokens/</guid><description>SUSE Rancher stored long-lived Kubernetes registration tokens in plaintext (CVE-2026-55997, CVSS 8.8). Upgrade to 2.14.4 or 2.13.8, then rotate every token.</description><pubDate>Wed, 05 Aug 2026 08:38:51 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Langflow&apos;s auto-login default gives any stranger admin, then RCE</title><link>https://suriq.io/blog/langflow-cve-2026-9198-auto-login-rce/</link><guid isPermaLink="true">https://suriq.io/blog/langflow-cve-2026-9198-auto-login-rce/</guid><description>CVE-2026-9198 lets an unauthenticated attacker mint a Langflow superuser token via auto-login, then run code as admin. KEV-listed, patch past 1.10.0 now.</description><pubDate>Tue, 04 Aug 2026 19:15:48 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A self-spreading npm worm poisoned hundreds of packages to steal cloud and GitHub tokens</title><link>https://suriq.io/blog/chaindrop-keyv-npm-worm-credential-theft/</link><guid isPermaLink="true">https://suriq.io/blog/chaindrop-keyv-npm-worm-credential-theft/</guid><description>A self-propagating npm worm that began in keyv 6.0.0 poisoned hundreds of packages on August 4, steals GitHub, npm, cloud, Vault and Kubernetes credentials</description><pubDate>Tue, 04 Aug 2026 15:46:14 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>An AI system found 14,090 new bugs across open-source software. Attackers can run the same scan.</title><link>https://suriq.io/blog/ai-scanner-14090-open-source-bugs/</link><guid isPermaLink="true">https://suriq.io/blog/ai-scanner-14090-open-source-bugs/</guid><description>Palo Alto&apos;s Unit 42 says its NOVA system found 14,090 unreported bugs across 3,915 open-source projects. The count is not the story.</description><pubDate>Tue, 04 Aug 2026 13:24:39 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Critical cPanel flaw lets a hosting account reach database root</title><link>https://suriq.io/blog/cpanel-cve-2026-58048-database-root-escalation/</link><guid isPermaLink="true">https://suriq.io/blog/cpanel-cve-2026-58048-database-root-escalation/</guid><description>cPanel CVE-2026-58048 (CVSS 9.4) lets an authenticated hosting customer run SQL as database root, risking full server compromise. Patch to the fixed build now.</description><pubDate>Tue, 04 Aug 2026 11:50:48 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Device-code phishing jumped 1,500% in 2026: attackers take over Microsoft 365 accounts with no password or MFA</title><link>https://suriq.io/blog/device-code-phishing-microsoft-365-token-theft/</link><guid isPermaLink="true">https://suriq.io/blog/device-code-phishing-microsoft-365-token-theft/</guid><description>Device-code phishing rose 1,500% in 2026, letting attackers mint Microsoft 365 tokens with no password or MFA. Here is how to detect and block the OAuth flow.</description><pubDate>Tue, 04 Aug 2026 08:52:38 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Coldcard wallets generated predictable seeds, and thieves drained $88M in Bitcoin. Updating won&apos;t fix it.</title><link>https://suriq.io/blog/coldcard-weak-rng-seed-bitcoin-theft/</link><guid isPermaLink="true">https://suriq.io/blog/coldcard-weak-rng-seed-bitcoin-theft/</guid><description>A Coldcard firmware error generated low-entropy Bitcoin seeds since 2021, and attackers swept about $88M by regenerating keys offline.</description><pubDate>Mon, 03 Aug 2026 18:29:41 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Thermo Fisher fixes a flaw that let forensic DNA files be altered undetected (CVE-2026-17583)</title><link>https://suriq.io/blog/thermo-fisher-dna-file-tampering-cve-2026-17583/</link><guid isPermaLink="true">https://suriq.io/blog/thermo-fisher-dna-file-tampering-cve-2026-17583/</guid><description>Thermo Fisher patched CVE-2026-17583, a flaw that let .fsa and .hid forensic DNA files be modified before its analysis software loaded them, with no warning</description><pubDate>Mon, 03 Aug 2026 15:23:59 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>N-able N-central auth bypass grants admin; first fix failed</title><link>https://suriq.io/blog/nable-ncentral-auth-bypass-incomplete-patch/</link><guid isPermaLink="true">https://suriq.io/blog/nable-ncentral-auth-bypass-incomplete-patch/</guid><description>N-able N-central RMM has an actively exploited authentication bypass (CVE-2026-18577). The first patch failed; upgrade to 2026.3.1.7 and hunt your endpoints.</description><pubDate>Mon, 03 Aug 2026 12:14:09 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Malware can hijack Google Chrome passkey logins and sign in as you, even with two-factor on</title><link>https://suriq.io/blog/chrome-passkey-malware-account-takeover/</link><guid isPermaLink="true">https://suriq.io/blog/chrome-passkey-malware-account-takeover/</guid><description>Google Chrome passkeys can be hijacked by malware: Unit 42 showed the device key can be copied and replayed when a site skips the user-verified check.</description><pubDate>Mon, 03 Aug 2026 11:40:25 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Sharp and Toshiba office copiers shipped with the login turned off, exposing saved scans</title><link>https://suriq.io/blog/sharp-toshiba-mfp-auth-off-default-cve-2026-63563/</link><guid isPermaLink="true">https://suriq.io/blog/sharp-toshiba-mfp-auth-off-default-cve-2026-63563/</guid><description>Sharp and Toshiba Tec copiers sold outside Japan shipped with authentication off, exposing the address book and stored scans (CVE-2026-63563).</description><pubDate>Mon, 03 Aug 2026 09:23:09 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Amazon ties the debug, chalk, and axios npm hijacks to North Korea</title><link>https://suriq.io/blog/npm-debug-chalk-axios-north-korea/</link><guid isPermaLink="true">https://suriq.io/blog/npm-debug-chalk-axios-north-korea/</guid><description>npm supply-chain attacks on debug, chalk, and axios are tied to one North Korean crew, Sapphire Sleet. Why signing missed it, and how to detect it.</description><pubDate>Sun, 02 Aug 2026 16:47:38 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A malicious remote desktop server can corrupt FreeRDP&apos;s Windows client via the clipboard (CVE-2026-68579)</title><link>https://suriq.io/blog/freerdp-windows-clipboard-heap-overflow-cve-2026-68579/</link><guid isPermaLink="true">https://suriq.io/blog/freerdp-windows-clipboard-heap-overflow-cve-2026-68579/</guid><description>FreeRDP fixed CVE-2026-68579, a critical clipboard heap overflow in its Windows client. A malicious remote desktop server can corrupt memory. Update to 3.30.0.</description><pubDate>Sun, 02 Aug 2026 15:08:49 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Water systems in 7 states were hijacked with default passwords, and no CVE was involved</title><link>https://suriq.io/blog/water-utilities-7-states-exposed-plc-default-passwords/</link><guid isPermaLink="true">https://suriq.io/blog/water-utilities-7-states-exposed-plc-default-passwords/</guid><description>Attackers hijacked internet-exposed water-utility control devices in 7 US states using default passwords, no CVE required. CISA says disconnect them now.</description><pubDate>Sun, 02 Aug 2026 12:55:23 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Adform&apos;s shared ad-tracking script was hijacked to swap crypto wallet addresses in visitors&apos; browsers</title><link>https://suriq.io/blog/adform-ad-script-crypto-wallet-swap-supply-chain/</link><guid isPermaLink="true">https://suriq.io/blog/adform-ad-script-crypto-wallet-swap-supply-chain/</guid><description>Attackers trojanized Adform&apos;s shared trackpoint-async.js to swap Bitcoin, Ethereum, and Tron wallet addresses in visitors&apos; browsers. Why SRI can&apos;t stop it.</description><pubDate>Sat, 01 Aug 2026 19:44:15 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>An AI agent hit 460 servers on its own, but known CVEs did the breaking</title><link>https://suriq.io/blog/autonomous-ai-agent-deepseek-hermes-460-servers/</link><guid isPermaLink="true">https://suriq.io/blog/autonomous-ai-agent-deepseek-hermes-460-servers/</guid><description>A China-linked operator wired DeepSeek into an autonomous agent that swept 460+ exposed servers.</description><pubDate>Sat, 01 Aug 2026 16:40:16 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Google&apos;s AI helped fix 1,072 Chrome bugs; patch cadence doubled</title><link>https://suriq.io/blog/chrome-ai-1072-bugs-faster-patch-cadence/</link><guid isPermaLink="true">https://suriq.io/blog/chrome-ai-1072-bugs-faster-patch-cadence/</guid><description>Google credits AI for fixing 1,072 Chrome bugs in two June releases, but never said how many AI found. The real shift for defenders is a faster patch cadence.</description><pubDate>Sat, 01 Aug 2026 13:02:24 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Anthropic&apos;s own AI models breached three real companies in tests</title><link>https://suriq.io/blog/anthropic-ai-models-breached-real-companies-ctf-tests/</link><guid isPermaLink="true">https://suriq.io/blog/anthropic-ai-models-breached-real-companies-ctf-tests/</guid><description>Anthropic says three of its AI models breached real companies during security tests after a sandbox misconfiguration. Two of three victims never noticed.</description><pubDate>Sat, 01 Aug 2026 08:33:35 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A link an admin clicks can create a rogue WordPress admin via the AI Engine plugin (CVE-2026-15988)</title><link>https://suriq.io/blog/ai-engine-wordpress-mcp-oauth-csrf-rogue-admin-cve-2026-15988/</link><guid isPermaLink="true">https://suriq.io/blog/ai-engine-wordpress-mcp-oauth-csrf-rogue-admin-cve-2026-15988/</guid><description>CVE-2026-15988 lets an attacker create a new WordPress administrator on sites running AI Engine 3.6.5 or earlier if a logged-in admin clicks one link.</description><pubDate>Sat, 01 Aug 2026 08:09:52 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>bank-vaults Kubernetes webhook flaw lets a low-privilege user steal HashiCorp Vault secrets (CVE-2026-54725)</title><link>https://suriq.io/blog/vault-secrets-webhook-ssrf-token-theft/</link><guid isPermaLink="true">https://suriq.io/blog/vault-secrets-webhook-ssrf-token-theft/</guid><description>CVE-2026-54725 is a critical SSRF in bank-vaults vault-secrets-webhook (CVSS 9.6). A user who can create a ConfigMap can steal ServiceAccount tokens. Fix: 1.23.</description><pubDate>Fri, 31 Jul 2026 18:24:37 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Unauthenticated attacker can read any file on a Ruby on Rails server via a crafted image (CVE-2026-66066)</title><link>https://suriq.io/blog/rails-active-storage-cve-2026-66066-arbitrary-file-read/</link><guid isPermaLink="true">https://suriq.io/blog/rails-active-storage-cve-2026-66066-arbitrary-file-read/</guid><description>CVE-2026-66066 lets an unauthenticated attacker upload a crafted image to a Rails app and read any server file, including its signing key. Patch now.</description><pubDate>Fri, 31 Jul 2026 16:04:08 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Azure Cosmos DB flaw gave one platform key full read/write access to any customer database</title><link>https://suriq.io/blog/azure-cosmos-db-cosmosescape-master-key/</link><guid isPermaLink="true">https://suriq.io/blog/azure-cosmos-db-cosmosescape-master-key/</guid><description>Wiz&apos;s CosmosEscape exposed a platform-wide Azure Cosmos DB key that could read and write any customer&apos;s database.</description><pubDate>Fri, 31 Jul 2026 11:22:07 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Silver Fox&apos;s new kit hot-swaps vulnerable drivers to kill EDR and plant ValleyRAT</title><link>https://suriq.io/blog/silverfox-modular-byovd-valleyrat/</link><guid isPermaLink="true">https://suriq.io/blog/silverfox-modular-byovd-valleyrat/</guid><description>Silver Fox now runs a modular bring-your-own-vulnerable-driver kit with three interchangeable drivers, killing EDR from the kernel to deploy ValleyRAT.</description><pubDate>Fri, 31 Jul 2026 09:09:41 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Keycloak lets an outside Google account bypass your Workspace domain sign-in restriction (CVE-2026-18214)</title><link>https://suriq.io/blog/keycloak-google-domain-bypass-token-exchange-cve-2026-18214/</link><guid isPermaLink="true">https://suriq.io/blog/keycloak-google-domain-bypass-token-exchange-cve-2026-18214/</guid><description>A missing check in Red Hat Build of Keycloak lets an outside Google account bypass a Google Workspace domain restriction during token exchange.</description><pubDate>Fri, 31 Jul 2026 08:11:44 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>FCC adds networked robots and inverters to its Covered List. The installed base is still yours to secure.</title><link>https://suriq.io/blog/fcc-covered-list-robots-inverters-installed-base/</link><guid isPermaLink="true">https://suriq.io/blog/fcc-covered-list-robots-inverters-installed-base/</guid><description>The FCC added networked power inverters and mobile robots to its Covered List over remote-control risk.</description><pubDate>Thu, 30 Jul 2026 19:24:46 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Ruflo&apos;s unauthenticated AI agent bridge runs code (CVE-2026-59726); patching won&apos;t evict the poisoned memory</title><link>https://suriq.io/blog/ruflo-rufroot-mcp-bridge-rce-cve-2026-59726/</link><guid isPermaLink="true">https://suriq.io/blog/ruflo-rufroot-mcp-bridge-rce-cve-2026-59726/</guid><description>Ruflo exposed an unauthenticated MCP bridge to 233 tools, so one request gets full remote code execution (CVE-2026-59726).</description><pubDate>Thu, 30 Jul 2026 16:13:38 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Russian OWAReaper implant exploits an Outlook Web Access flaw, and a password reset won&apos;t evict it</title><link>https://suriq.io/blog/owareaper-outlook-web-access-cve-2026-42897/</link><guid isPermaLink="true">https://suriq.io/blog/owareaper-outlook-web-access-cve-2026-42897/</guid><description>Russian group Void Blizzard is exploiting Outlook Web Access flaw CVE-2026-42897 to plant OWAReaper, a backdoor whose server-side mailbox access survives</description><pubDate>Thu, 30 Jul 2026 12:10:45 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Cisco&apos;s firewall management software has a hardcoded password, and attackers are already using it</title><link>https://suriq.io/blog/cisco-fmc-hardcoded-password-cve-2026-20316/</link><guid isPermaLink="true">https://suriq.io/blog/cisco-fmc-hardcoded-password-cve-2026-20316/</guid><description>Cisco Secure Firewall Management Center ships a static password (CVE-2026-20316) that lets unauthenticated attackers log in. Now in CISA KEV. Patch and hunt.</description><pubDate>Thu, 30 Jul 2026 11:13:38 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Adminer flaw lets a logged-in user run code on the web server (CVE-2026-15686), fixed in 5.4.3</title><link>https://suriq.io/blog/adminer-cve-2026-15686-authenticated-rce/</link><guid isPermaLink="true">https://suriq.io/blog/adminer-cve-2026-15686-authenticated-rce/</guid><description>CVE-2026-15686 lets a logged-in Adminer user slip a blocked SQLite command past a filter and run code on the server. Fixed in Adminer 5.4.3; update now.</description><pubDate>Thu, 30 Jul 2026 08:26:56 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>New VMware flaws let a network attacker run code on vCenter with no login, and escape a VM onto the host</title><link>https://suriq.io/blog/vmware-vcenter-esxi-preauth-rce-vm-escape/</link><guid isPermaLink="true">https://suriq.io/blog/vmware-vcenter-esxi-preauth-rce-vm-escape/</guid><description>VMware&apos;s VMSA-2026-0006 patches two 9.8 vCenter flaws that add up to unauthenticated code execution, plus a 9.3 ESXi VM escape. Patch vCenter first.</description><pubDate>Wed, 29 Jul 2026 18:39:34 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>cPanel security update fixes three flaws rated up to High, including one in the bundled Exim mail server</title><link>https://suriq.io/blog/cpanel-whm-security-release-exim/</link><guid isPermaLink="true">https://suriq.io/blog/cpanel-whm-security-release-exim/</guid><description>cPanel and WHM&apos;s new security release fixes CVE-2026-58047, CVE-2026-58048 and an Exim flaw, rated up to High. Patched versions for every branch, what to do.</description><pubDate>Wed, 29 Jul 2026 17:40:47 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>30+ Minnesota water utilities hit in a coordinated attack, and the timing is the real warning</title><link>https://suriq.io/blog/minnesota-water-utilities-coordinated-ot-attack/</link><guid isPermaLink="true">https://suriq.io/blog/minnesota-water-utilities-coordinated-ot-attack/</guid><description>More than 30 Minnesota water systems were hit in a coordinated two-day attack. The simultaneity points to shared exposure; the signal sits on the IT side.</description><pubDate>Wed, 29 Jul 2026 15:46:49 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Dysphoria botnet hides on the blockchain to survive takedowns</title><link>https://suriq.io/blog/dysphoria-iot-botnet-blockchain-c2-relays/</link><guid isPermaLink="true">https://suriq.io/blog/dysphoria-iot-botnet-blockchain-c2-relays/</guid><description>Dysphoria, a DDoS-for-hire IoT botnet, survived a March takedown by anchoring its command servers to Ethereum and Solana names no registrar can seize, and now</description><pubDate>Wed, 29 Jul 2026 12:51:47 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>ERPNext SQL injection lets a low-privilege user read the entire database, passwords included (CVE-2026-12895)</title><link>https://suriq.io/blog/erpnext-cve-2026-12895-supplier-sql-injection/</link><guid isPermaLink="true">https://suriq.io/blog/erpnext-cve-2026-12895-supplier-sql-injection/</guid><description>CVE-2026-12895 is a SQL injection in ERPNext that lets a low-privilege user read the whole database. Fixed in 15.111.0 and 16.22.0. Patch and rotate secrets.</description><pubDate>Wed, 29 Jul 2026 11:25:03 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Apache Traffic Server flaw lets attackers slip hidden requests past security checks and forge internal data</title><link>https://suriq.io/blog/apache-traffic-server-cve-2026-33267-request-smuggling/</link><guid isPermaLink="true">https://suriq.io/blog/apache-traffic-server-cve-2026-33267-request-smuggling/</guid><description>Apache Traffic Server has a critical flaw, CVE-2026-33267 (CVSS 10), that lets attackers smuggle requests and spoof internal metadata.</description><pubDate>Wed, 29 Jul 2026 08:09:56 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Fastjson RCE (CVE-2026-16723) now exploited on Spring Boot apps</title><link>https://suriq.io/blog/fastjson-cve-2026-16723-spring-boot-exploited/</link><guid isPermaLink="true">https://suriq.io/blog/fastjson-cve-2026-16723-spring-boot-exploited/</guid><description>CVE-2026-16723, a fastjson 1.x remote code execution flaw, is now exploited against US firms. Only Spring Boot fat-JAR apps are hit, and no 1.x patch is coming.</description><pubDate>Tue, 28 Jul 2026 19:38:36 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>24,650 exposed server BMCs leak crackable IPMI password hashes, and no patch can fix it</title><link>https://suriq.io/blog/exposed-bmc-ipmi-password-hash-leak/</link><guid isPermaLink="true">https://suriq.io/blog/exposed-bmc-ipmi-password-hash-leak/</guid><description>A scan found 24,650 internet-exposed server BMCs leaking IPMI password hashes to anyone via CVE-2013-4786. There is no patch. Here is how to close the exposure.</description><pubDate>Tue, 28 Jul 2026 15:39:35 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Critical TeamCity flaw CVE-2026-63077 lets an unauthenticated attacker run commands on your build server</title><link>https://suriq.io/blog/teamcity-cve-2026-63077-preauth-rce-build-server/</link><guid isPermaLink="true">https://suriq.io/blog/teamcity-cve-2026-63077-preauth-rce-build-server/</guid><description>CVE-2026-63077 is a CVSS 9.8 auth bypass in every TeamCity On-Premises version. An unauthenticated attacker can run commands. Patch to 2025.11.7 or 2026.1.3.</description><pubDate>Tue, 28 Jul 2026 12:15:15 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Public DNS servers with filtering: a verified list of what each IP really blocks</title><link>https://suriq.io/blog/public-dns-servers-filtering-verified/</link><guid isPermaLink="true">https://suriq.io/blog/public-dns-servers-filtering-verified/</guid><description>Public DNS servers with filtering, verified against official docs: what the Cloudflare, Quad9, AdGuard, CleanBrowsing, ControlD, Mullvad and OpenDNS IPs block.</description><pubDate>Tue, 28 Jul 2026 09:59:12 GMT</pubDate><category>Explainers</category><author>Noam Alum</author></item><item><title>For this week&apos;s most-exploited bugs, the patch was the easy part</title><link>https://suriq.io/blog/signal-patch-is-not-the-finish-line/</link><guid isPermaLink="true">https://suriq.io/blog/signal-patch-is-not-the-finish-line/</guid><description>This week&apos;s most-exploited bugs each shipped with a fix, yet patching FortiOS, SharePoint, Check Point, and Langflow did not end the incident.</description><pubDate>Tue, 28 Jul 2026 09:27:50 GMT</pubDate><category>Deep dive</category><author>Suriq&apos;s Jack</author></item><item><title>A max-severity flaw in Dassault&apos;s 3DEXPERIENCE platform lets an attacker run code with no login. Patch now.</title><link>https://suriq.io/blog/dassault-3dexperience-cve-2026-11756-launcher-rce/</link><guid isPermaLink="true">https://suriq.io/blog/dassault-3dexperience-cve-2026-11756-launcher-rce/</guid><description>CVE-2026-11756 is a CVSS 10 deserialization flaw in Dassault&apos;s 3DEXPERIENCE Launcher that allows unauthenticated remote code execution.</description><pubDate>Tue, 28 Jul 2026 08:25:08 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>On-prem VeloCloud Orchestrator flaw (CVE-2026-16812) lets attackers run commands, and it is exploited now</title><link>https://suriq.io/blog/velocloud-orchestrator-cve-2026-16812-onprem-command-injection/</link><guid isPermaLink="true">https://suriq.io/blog/velocloud-orchestrator-cve-2026-16812-onprem-command-injection/</guid><description>CVE-2026-16812 is a CVSS 10.0 OS command injection in on-prem VeloCloud Orchestrator, actively exploited. See the affected and fixed builds to patch now.</description><pubDate>Mon, 27 Jul 2026 20:04:38 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Attackers can slip past Fortinet&apos;s fix and keep reading a hacked firewall&apos;s files, CISA warns</title><link>https://suriq.io/blog/fortios-symlink-patch-bypass-cve-2025-68686-kev/</link><guid isPermaLink="true">https://suriq.io/blog/fortios-symlink-patch-bypass-cve-2025-68686-kev/</guid><description>CISA added CVE-2025-68686 to its exploited catalog: a bypass of Fortinet&apos;s FortiOS symlink fix lets attackers who already breached a FortiGate keep reading its</description><pubDate>Mon, 27 Jul 2026 18:39:43 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>n8n flaw lets any workflow editor run OS commands on your server (GHSA-gv7g-jm28-cr3m)</title><link>https://suriq.io/blog/n8n-sandbox-escape-workflow-editor-rce/</link><guid isPermaLink="true">https://suriq.io/blog/n8n-sandbox-escape-workflow-editor-rce/</guid><description>n8n patched a CVSS 8.7 expression sandbox escape (GHSA-gv7g-jm28-cr3m) that lets any workflow editor run OS commands on the host. Update to 2.32.1 now.</description><pubDate>Mon, 27 Jul 2026 16:51:45 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A vBulletin bug lets anyone run code on the forum server without logging in. Update to 6.2.2 now.</title><link>https://suriq.io/blog/vbulletin-cve-2026-61511-template-eval-rce/</link><guid isPermaLink="true">https://suriq.io/blog/vbulletin-cve-2026-61511-template-eval-rce/</guid><description>CVE-2026-61511 is an unauthenticated remote code execution flaw in vBulletin&apos;s template engine (CVSS 9.8).</description><pubDate>Mon, 27 Jul 2026 14:09:46 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>GitHub and PyPI add release delays to slow poisoned packages</title><link>https://suriq.io/blog/github-pypi-release-cooldown-supply-chain-gap/</link><guid isPermaLink="true">https://suriq.io/blog/github-pypi-release-cooldown-supply-chain-gap/</guid><description>GitHub now waits three days before Dependabot opens an update pull request, and PyPI locks old releases from new files.</description><pubDate>Mon, 27 Jul 2026 11:33:16 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A &apos;read-only&apos; role in Red Hat OpenShift Virtualization lets one tenant copy another tenant&apos;s data</title><link>https://suriq.io/blog/openshift-virtualization-view-role-cross-tenant-clone/</link><guid isPermaLink="true">https://suriq.io/blog/openshift-virtualization-view-role-cross-tenant-clone/</guid><description>CVE-2026-17527 lets a low-privileged OpenShift Virtualization tenant copy other tenants&apos; data across namespaces through a read-only role. No fix yet; audit now.</description><pubDate>Mon, 27 Jul 2026 10:26:06 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Hotel Wi-Fi hijacks steal Microsoft 365 accounts past MFA</title><link>https://suriq.io/blog/hotel-wifi-dns-hijack-microsoft-365-mfa/</link><guid isPermaLink="true">https://suriq.io/blog/hotel-wifi-dns-hijack-microsoft-365-mfa/</guid><description>A campaign is hijacking hotel and conference Wi-Fi to steal Microsoft 365 accounts. A VPN closes most of it, but not the device-code trick that beats MFA.</description><pubDate>Sun, 26 Jul 2026 19:19:15 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>SourTrade malvertising builds an infostealer inside your browser, so no file crosses the wire to scan</title><link>https://suriq.io/blog/sourtrade-browser-assembled-malware/</link><guid isPermaLink="true">https://suriq.io/blog/sourtrade-browser-assembled-malware/</guid><description>SourTrade malvertising makes the victim&apos;s browser assemble a Windows infostealer in memory, with a unique hash per visitor, so no scannable file ever crosses</description><pubDate>Sun, 26 Jul 2026 15:42:49 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A GitLab flaw lets any user with push access run code on the server, and a public exploit is now out</title><link>https://suriq.io/blog/gitlab-notebook-diff-rce-public-exploit/</link><guid isPermaLink="true">https://suriq.io/blog/gitlab-notebook-diff-rce-public-exploit/</guid><description>GitLab quietly patched a self-managed code-execution flaw on June 10 with no CVE. A public exploit is now out and any push-access user can run code as git.</description><pubDate>Sun, 26 Jul 2026 11:30:05 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A public exploit lets a stranger log in as WordPress admin through miniOrange&apos;s single sign-on plugin</title><link>https://suriq.io/blog/miniorange-saml-sso-wordpress-admin-bypass/</link><guid isPermaLink="true">https://suriq.io/blog/miniorange-saml-sso-wordpress-admin-bypass/</guid><description>A public exploit for CVE-2026-15981 lets unauthenticated attackers log in as any WordPress admin via the miniOrange SAML SSO plugin. Update to 5.4.5 now.</description><pubDate>Sun, 26 Jul 2026 09:55:01 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Any domain user can now DCSync your forest. Certighost is why.</title><link>https://suriq.io/blog/certighost-adcs-cve-2026-54121/</link><guid isPermaLink="true">https://suriq.io/blog/certighost-adcs-cve-2026-54121/</guid><description>CVE-2026-54121 lets a standard Active Directory user impersonate a domain controller through AD CS and run DCSync.</description><pubDate>Sat, 25 Jul 2026 15:45:18 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Public exploit hits a critical Oracle WebLogic flaw that forges a login to take over the server</title><link>https://suriq.io/blog/oracle-weblogic-cve-2026-60206-saml-login-forgery-exploit/</link><guid isPermaLink="true">https://suriq.io/blog/oracle-weblogic-cve-2026-60206-saml-login-forgery-exploit/</guid><description>A public proof-of-concept exploit now targets CVE-2026-60206, a CVSS 9.9 Oracle WebLogic flaw that forges a login to take over the server. Patch and hunt now.</description><pubDate>Sat, 25 Jul 2026 15:27:56 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Windmill&apos;s unauthenticated file-read flaw (CVE-2026-29059) is under active attack</title><link>https://suriq.io/blog/windmill-cve-2026-29059-arbitrary-file-read/</link><guid isPermaLink="true">https://suriq.io/blog/windmill-cve-2026-29059-arbitrary-file-read/</guid><description>Windmill&apos;s unauthenticated file-read flaw CVE-2026-29059 is being exploited in the wild. Patch self-hosted instances to 1.603.3 and rotate any exposed secrets.</description><pubDate>Sat, 25 Jul 2026 11:34:38 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>WPForms Pro flaw lets a stranger upload a file and run code on your WordPress site. Patch now.</title><link>https://suriq.io/blog/wpforms-pro-cve-2026-10818-file-upload-rce/</link><guid isPermaLink="true">https://suriq.io/blog/wpforms-pro-cve-2026-10818-file-upload-rce/</guid><description>A flaw in WPForms Pro (CVE-2026-10818) lets unauthenticated attackers upload executable files to WordPress sites on versions up to 1.10.1.1 and run code.</description><pubDate>Sat, 25 Jul 2026 08:10:39 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A single ChatGPT link could plant a rogue AI agent in your org</title><link>https://suriq.io/blog/chatgpt-agentforger-csrf-rogue-agent/</link><guid isPermaLink="true">https://suriq.io/blog/chatgpt-agentforger-csrf-rogue-agent/</guid><description>Zenity Labs&apos; AgentForger let one crafted ChatGPT link forge a self-running AI agent wired to your connected apps. OpenAI fixed it. Here&apos;s what to watch.</description><pubDate>Fri, 24 Jul 2026 18:32:54 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Attackers ran an AI agent unattended to do the hands-on hacking inside Thailand&apos;s finance ministry</title><link>https://suriq.io/blog/hermes-ai-agent-thailand-finance-ministry/</link><guid isPermaLink="true">https://suriq.io/blog/hermes-ai-agent-thailand-finance-ministry/</guid><description>An attacker ran an unattended AI agent to hack Thailand&apos;s finance ministry. It used no new exploit, and defenders catch it by watching host actions.</description><pubDate>Fri, 24 Jul 2026 15:52:48 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A Keycloak flaw lets a view-only admin read live client secrets from the vault (CVE-2026-17048)</title><link>https://suriq.io/blog/keycloak-cve-2026-17048-vault-secret-leak/</link><guid isPermaLink="true">https://suriq.io/blog/keycloak-cve-2026-17048-vault-secret-leak/</guid><description>CVE-2026-17048 lets a view-only Keycloak admin read resolved client secrets from the vault instead of the placeholder.</description><pubDate>Fri, 24 Jul 2026 14:11:05 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Fake Notepad++ plugin drops a Windows loader that slips past sandboxes and app allowlists</title><link>https://suriq.io/blog/fake-notepad-plugin-dll-sideload-uac0099/</link><guid isPermaLink="true">https://suriq.io/blog/fake-notepad-plugin-dll-sideload-uac0099/</guid><description>CERT-UA ties UAC-0099 to a campaign hiding a Windows loader in a genuine Notepad++ via DLL sideloading.</description><pubDate>Fri, 24 Jul 2026 11:14:43 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>ESET patched a Mac flaw that let any local user gain root control (CVE-2026-7483)</title><link>https://suriq.io/blog/eset-macos-cve-2026-7483-privileged-service-local-root/</link><guid isPermaLink="true">https://suriq.io/blog/eset-macos-cve-2026-7483-privileged-service-local-root/</guid><description>ESET patched CVE-2026-7483, a local privilege escalation in its Mac security software that let any logged-in user write files as root.</description><pubDate>Fri, 24 Jul 2026 10:11:44 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Zimbra webmail zero-day (CVE-2025-66376) let Russian spies steal mail and mint MFA-bypass passwords</title><link>https://suriq.io/blog/zimbra-cve-2025-66376-russian-mail-theft/</link><guid isPermaLink="true">https://suriq.io/blog/zimbra-cve-2025-66376-russian-mail-theft/</guid><description>Russian group Void Blizzard exploited Zimbra webmail flaw CVE-2025-66376 as a zero-day to steal 90 days of mail and mint app passwords that survive resets.</description><pubDate>Thu, 23 Jul 2026 19:06:36 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>RefluXFS: a Linux XFS flaw gives any local user root access</title><link>https://suriq.io/blog/refluxfs-xfs-linux-local-root/</link><guid isPermaLink="true">https://suriq.io/blog/refluxfs-xfs-linux-local-root/</guid><description>RefluXFS (CVE-2026-64600) lets any local user get root on default RHEL, Rocky, Alma and Amazon Linux via an XFS race. No workaround: patch and reboot.</description><pubDate>Thu, 23 Jul 2026 15:58:48 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>PhpSpreadsheet flaw: a tiny malformed file can crash PHP apps that accept spreadsheet uploads (CVE-2026-59933)</title><link>https://suriq.io/blog/phpspreadsheet-cve-2026-59933-spreadsheet-upload-dos/</link><guid isPermaLink="true">https://suriq.io/blog/phpspreadsheet-cve-2026-59933-spreadsheet-upload-dos/</guid><description>CVE-2026-59933: a 1 KB malformed spreadsheet can exhaust memory and crash PHP apps using PhpSpreadsheet, even during automatic file-type detection. Patch now.</description><pubDate>Thu, 23 Jul 2026 15:28:07 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Adobe&apos;s Acrobat Chrome extension let any website read WhatsApp Web chats (CVE-2026-48294). Update now.</title><link>https://suriq.io/blog/adobe-acrobat-extension-whatsapp-web-cross-origin/</link><guid isPermaLink="true">https://suriq.io/blog/adobe-acrobat-extension-whatsapp-web-cross-origin/</guid><description>A cross-origin flaw in Adobe&apos;s Acrobat Chrome extension (CVE-2026-48294) let any website read WhatsApp Web chats. Update to 26.5.2.3 and govern extensions.</description><pubDate>Thu, 23 Jul 2026 11:45:23 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A rigged printer advertisement can trap Linux print systems in a CPU-burning loop (CVE-2026-64611)</title><link>https://suriq.io/blog/libcupsfilters-cve-2026-64611-printer-loop-dos/</link><guid isPermaLink="true">https://suriq.io/blog/libcupsfilters-cve-2026-64611-printer-loop-dos/</guid><description>CVE-2026-64611 lets a crafted printer advertisement drive libcupsfilters into an infinite loop, burning a CPU core on Linux print systems. Patch and harden now.</description><pubDate>Thu, 23 Jul 2026 11:25:14 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A critical fastjson flaw lets attackers run code on the server with no special configuration (CVE-2026-16723)</title><link>https://suriq.io/blog/fastjson-cve-2026-16723-default-config-rce/</link><guid isPermaLink="true">https://suriq.io/blog/fastjson-cve-2026-16723-default-config-rce/</guid><description>CVE-2026-16723 lets attackers run code on Java apps using fastjson 1.2.68 to 1.2.83 in default configuration. Turn on SafeMode or move to fastjson2.</description><pubDate>Thu, 23 Jul 2026 08:39:14 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Check Point&apos;s SmartConsole flaw lets an unauthenticated attacker become full admin, and it is being exploited</title><link>https://suriq.io/blog/check-point-smartconsole-cve-2026-16232-exploited/</link><guid isPermaLink="true">https://suriq.io/blog/check-point-smartconsole-cve-2026-16232-exploited/</guid><description>Check Point SmartConsole flaw CVE-2026-16232 is exploited and in CISA KEV, letting an unauthenticated attacker log in as full admin.</description><pubDate>Wed, 22 Jul 2026 20:10:17 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>You patched SharePoint three times this month. The key attackers want is still in the lock.</title><link>https://suriq.io/blog/sharepoint-cve-2026-50522-rotate-machine-keys/</link><guid isPermaLink="true">https://suriq.io/blog/sharepoint-cve-2026-50522-rotate-machine-keys/</guid><description>CVE-2026-50522, a CVSS 9.8 SharePoint RCE, went from public PoC to active exploitation in hours.</description><pubDate>Wed, 22 Jul 2026 15:57:34 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Langflow&apos;s code-validation endpoint just produced its second unauthenticated RCE</title><link>https://suriq.io/blog/langflow-cve-2026-0770-validate-rce-kev/</link><guid isPermaLink="true">https://suriq.io/blog/langflow-cve-2026-0770-validate-rce-kev/</guid><description>CVE-2026-0770 (CVSS 9.8) is an unauthenticated root RCE in Langflow&apos;s validate endpoint, actively exploited and added to CISA&apos;s KEV catalog.</description><pubDate>Wed, 22 Jul 2026 13:05:36 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Oracle&apos;s July update fixes unauthenticated 10.0 code-execution flaws in WebLogic, HTTP Server, and Coherence</title><link>https://suriq.io/blog/oracle-july-2026-cpu-unauthenticated-rce-weblogic-coherence/</link><guid isPermaLink="true">https://suriq.io/blog/oracle-july-2026-cpu-unauthenticated-rce-weblogic-coherence/</guid><description>Oracle&apos;s July 2026 update ships 1,449 fixes, including unauthenticated CVSS 10.0 remote code execution in WebLogic, Oracle HTTP Server, and Coherence.</description><pubDate>Wed, 22 Jul 2026 04:58:33 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A Jackson library flaw lets low-privilege users write fields meant only for admins</title><link>https://suriq.io/blog/jackson-databind-jsonview-write-bypass-cve-2026-59889/</link><guid isPermaLink="true">https://suriq.io/blog/jackson-databind-jsonview-write-bypass-cve-2026-59889/</guid><description>CVE-2026-59889 lets a low-privilege user bypass jackson-databind&apos;s @JsonView write guard and set admin-only fields. Patched in 2.18.9, 2.21.5, 3.1.5.</description><pubDate>Wed, 22 Jul 2026 00:16:31 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A Palo Alto VPN auth bypass is now a Qilin ransomware front door</title><link>https://suriq.io/blog/qilin-ransomware-palo-alto-globalprotect-cve-2026-0257/</link><guid isPermaLink="true">https://suriq.io/blog/qilin-ransomware-palo-alto-globalprotect-cve-2026-0257/</guid><description>CVE-2026-0257 lets attackers open a Palo Alto GlobalProtect VPN session with no login, and the Qilin ransomware crew is using it for initial access.</description><pubDate>Tue, 21 Jul 2026 18:26:29 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>HollowGraph turns Microsoft 365 into a C2 channel with no patch</title><link>https://suriq.io/blog/hollowgraph-microsoft-365-calendar-c2/</link><guid isPermaLink="true">https://suriq.io/blog/hollowgraph-microsoft-365-calendar-c2/</guid><description>HollowGraph runs its command channel through a hijacked Microsoft 365 calendar over the Graph API. No CVE, no patch: here is how to detect it.</description><pubDate>Tue, 21 Jul 2026 16:04:00 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>NGINX&apos;s new 9.2 heap overflow hits a config most servers actually run, not an exotic one</title><link>https://suriq.io/blog/nginx-cve-2026-42533-map-regex-heap-overflow/</link><guid isPermaLink="true">https://suriq.io/blog/nginx-cve-2026-42533-map-regex-heap-overflow/</guid><description>CVE-2026-42533 is a CVSS 9.2 heap overflow in nginx&apos;s string engine, patched July 15. Unlike June&apos;s flaws it fires on a common regex map config.</description><pubDate>Tue, 21 Jul 2026 11:41:51 GMT</pubDate><category>Security news</category><category>Deep dive</category><author>Noam Alum</author></item><item><title>The week&apos;s scariest ‘AI’ bugs weren&apos;t about AI. They were the confused deputy.</title><link>https://suriq.io/blog/signal-ai-bugs-confused-deputy/</link><guid isPermaLink="true">https://suriq.io/blog/signal-ai-bugs-confused-deputy/</guid><description>This week&apos;s headline ‘AI’ vulnerabilities in Grafana and Apache Camel are the 1988 confused-deputy flaw, the same one that hit Fastify, Directus and OpenShift</description><pubDate>Tue, 21 Jul 2026 09:25:08 GMT</pubDate><category>Deep dive</category><author>Suriq&apos;s Jack</author></item><item><title>Directus caching flaw can serve one visitor&apos;s private data to the next</title><link>https://suriq.io/blog/directus-cache-authorization-leak-cve-2026-61836/</link><guid isPermaLink="true">https://suriq.io/blog/directus-cache-authorization-leak-cve-2026-61836/</guid><description>Directus before 12.0.0 caches responses under a key that omits authorization, so with caching on it can serve one visitor&apos;s share-scoped data to another.</description><pubDate>Tue, 21 Jul 2026 09:10:05 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>ServiceNow is under active attack through a route the public exploit does not show. Patch, don&apos;t block.</title><link>https://suriq.io/blog/servicenow-cve-2026-6875-sandbox-escape-exploited/</link><guid isPermaLink="true">https://suriq.io/blog/servicenow-cve-2026-6875-sandbox-escape-exploited/</guid><description>ServiceNow&apos;s pre-auth sandbox-escape flaw CVE-2026-6875 (CVSS 9.5) is under active exploitation.</description><pubDate>Mon, 20 Jul 2026 20:03:34 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>An AI agent breached Hugging Face. Blocklists can&apos;t catch it.</title><link>https://suriq.io/blog/hugging-face-autonomous-ai-agent-breach/</link><guid isPermaLink="true">https://suriq.io/blog/hugging-face-autonomous-ai-agent-breach/</guid><description>Hugging Face says an autonomous AI agent breached it, taking internal data and service credentials.</description><pubDate>Mon, 20 Jul 2026 12:23:25 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>In Apache Camel, a manipulated AI reply can quietly redirect what the server does next</title><link>https://suriq.io/blog/apache-camel-llm-tool-header-injection-cve-2026-49042/</link><guid isPermaLink="true">https://suriq.io/blog/apache-camel-llm-tool-header-injection-cve-2026-49042/</guid><description>CVE-2026-49042 lets a prompt-injected AI model set hidden Apache Camel headers via tool-call arguments, reaching code execution or SSRF on exposed routes.</description><pubDate>Mon, 20 Jul 2026 11:10:19 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>One missing setting lets a stranger join an OpenShift cluster&apos;s private tunnel and read its traffic</title><link>https://suriq.io/blog/openshift-hypershift-konnectivity-cert-bypass/</link><guid isPermaLink="true">https://suriq.io/blog/openshift-hypershift-konnectivity-cert-bypass/</guid><description>CVE-2026-16242 (CVSS 9.4): a missing certificate check in OpenShift hosted control planes lets a remote attacker intercept control-plane-to-node traffic.</description><pubDate>Mon, 20 Jul 2026 08:26:42 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>EY&apos;s breach came through the help desk, not the audit floor</title><link>https://suriq.io/blog/ey-breach-it-support-ticket-platform/</link><guid isPermaLink="true">https://suriq.io/blog/ey-breach-it-support-ticket-platform/</guid><description>EY says client tax data leaked from a third-party IT support platform, not its audit systems. Why help-desk tooling is a crown-jewel store, and how to watch it.</description><pubDate>Sun, 19 Jul 2026 19:42:49 GMT</pubDate><category>Security news</category><category>Thought leadership</category><author>Noam Alum</author></item><item><title>NadMesh turns exposed AI servers into cloud-key harvesters</title><link>https://suriq.io/blog/nadmesh-botnet-exposed-ai-cloud-keys/</link><guid isPermaLink="true">https://suriq.io/blog/nadmesh-botnet-exposed-ai-cloud-keys/</guid><description>NadMesh, a new Go botnet, scans exposed self-hosted AI tools like Ollama and ComfyUI to steal cloud keys and Kubernetes tokens.</description><pubDate>Sun, 19 Jul 2026 15:42:01 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>wp2shell went from patch to public exploit in a day. Patching is no longer enough.</title><link>https://suriq.io/blog/wp2shell-exploits-public-hunt-now/</link><guid isPermaLink="true">https://suriq.io/blog/wp2shell-exploits-public-hunt-now/</guid><description>Public proof-of-concept exploits for the wp2shell WordPress Core RCE (CVE-2026-63030) are live and the mechanism is disclosed.</description><pubDate>Sun, 19 Jul 2026 11:11:36 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Inc ransomware used the SonicWall SMA zero-days to steal MFA seeds. Resetting passwords will not evict it.</title><link>https://suriq.io/blog/inc-ransomware-sonicwall-sma-mfa-seed-theft/</link><guid isPermaLink="true">https://suriq.io/blog/inc-ransomware-sonicwall-sma-mfa-seed-theft/</guid><description>Rapid7 ties the SonicWall SMA 1000 zero-days to an Inc ransomware actor that stole credentials, sessions, and TOTP seeds. A password reset won&apos;t evict it.</description><pubDate>Sun, 19 Jul 2026 09:06:06 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>ACR Stealer steals live sessions. A password reset won&apos;t help.</title><link>https://suriq.io/blog/acr-stealer-clickfix-session-theft/</link><guid isPermaLink="true">https://suriq.io/blog/acr-stealer-clickfix-session-theft/</guid><description>ACR Stealer, now surging per Microsoft, steals live browser sessions and Microsoft 365 files through ClickFix lures.</description><pubDate>Sat, 18 Jul 2026 19:30:36 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>One encoded letter walks past a Fastify proxy and reaches the internal endpoints it hid</title><link>https://suriq.io/blog/fastify-http-proxy-prefix-bypass-cve-2026-16117/</link><guid isPermaLink="true">https://suriq.io/blog/fastify-http-proxy-prefix-bypass-cve-2026-16117/</guid><description>A single URL-encoded character slips past @fastify/http-proxy&apos;s prefix rewrite (CVE-2026-16117, CVSS 10), exposing internal upstream endpoints. Upgrade to 11.6.</description><pubDate>Sat, 18 Jul 2026 18:54:32 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>OpenSSL&apos;s HollowByte flaw freezes servers, and no CVE flags it</title><link>https://suriq.io/blog/openssl-hollowbyte-tls-memory-dos/</link><guid isPermaLink="true">https://suriq.io/blog/openssl-hollowbyte-tls-memory-dos/</guid><description>OpenSSL patched HollowByte, an 11-byte flaw that strands server memory, quietly in June with no CVE.</description><pubDate>Sat, 18 Jul 2026 12:05:18 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A network attacker can take over VMware&apos;s Avi load balancer with no password. Patch now.</title><link>https://suriq.io/blog/vmware-avi-load-balancer-control-plane-flaws-vmsa-2026-0005/</link><guid isPermaLink="true">https://suriq.io/blog/vmware-avi-load-balancer-control-plane-flaws-vmsa-2026-0005/</guid><description>Broadcom&apos;s VMSA-2026-0005 patches seven VMware Avi Load Balancer flaws, including a CVSS 9.8 unauthenticated control-plane bypass. No workaround exists.</description><pubDate>Sat, 18 Jul 2026 09:37:00 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A stranger with no login can take over WordPress sites on 6.9 and 7.0. Patch now.</title><link>https://suriq.io/blog/wordpress-core-wp2shell-unauth-rce-cve-2026-63030/</link><guid isPermaLink="true">https://suriq.io/blog/wordpress-core-wp2shell-unauth-rce-cve-2026-63030/</guid><description>WordPress Core 6.9 and 7.0 carry wp2shell (CVE-2026-63030), an unauthenticated remote code execution flaw. Update to 6.9.5 or 7.0.2 right away, then hunt.</description><pubDate>Fri, 17 Jul 2026 22:55:08 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>ClickLock locks your Mac until you hand over the password</title><link>https://suriq.io/blog/clicklock-macos-coercion-stealer/</link><guid isPermaLink="true">https://suriq.io/blog/clicklock-macos-coercion-stealer/</guid><description>ClickLock is a macOS infostealer that kills your apps every 210ms until you type your login password into a fake prompt.</description><pubDate>Fri, 17 Jul 2026 19:25:30 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>AI wrote most of this IoT botnet, badly. That helps defenders.</title><link>https://suriq.io/blog/tuxbot-ai-built-iot-botnet/</link><guid isPermaLink="true">https://suriq.io/blog/tuxbot-ai-built-iot-botnet/</guid><description>Unit 42 found TuxBot v3, an IoT botnet largely written with an AI. The build is 70% broken, the working core is plain Mirai, and your defenses still hold.</description><pubDate>Fri, 17 Jul 2026 16:45:10 GMT</pubDate><category>Security news</category><category>Thought leadership</category><author>Noam Alum</author></item><item><title>A booby-trapped code repository can hijack a Windows PC the moment you open it in Cursor</title><link>https://suriq.io/blog/cursor-windows-malicious-git-repo-rce/</link><guid isPermaLink="true">https://suriq.io/blog/cursor-windows-malicious-git-repo-rce/</guid><description>A malicious repository can run code when opened in Cursor on Windows through a planted git.exe. CVE-2026-63093 has no patch yet. How to detect and contain it.</description><pubDate>Fri, 17 Jul 2026 15:08:40 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>SharePoint&apos;s new RCE is live, and patching alone won&apos;t clean it</title><link>https://suriq.io/blog/sharepoint-cve-2026-58644-machine-key-persistence/</link><guid isPermaLink="true">https://suriq.io/blog/sharepoint-cve-2026-58644-machine-key-persistence/</guid><description>CVE-2026-58644, a SharePoint deserialization RCE, is in CISA&apos;s KEV catalog and exploited as a zero-day. Patching alone won&apos;t evict an attacker who stole keys.</description><pubDate>Fri, 17 Jul 2026 11:40:11 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A crafted web request can make Apache Camel&apos;s Solr routes call out to an attacker</title><link>https://suriq.io/blog/apache-camel-solr-header-injection-ssrf-cve-2026-48203/</link><guid isPermaLink="true">https://suriq.io/blog/apache-camel-solr-header-injection-ssrf-cve-2026-48203/</guid><description>CVE-2026-48203: Camel&apos;s SolrParam. and SolrField. header prefixes slip past its HTTP header filter, letting outside requests inject Solr parameters and force</description><pubDate>Fri, 17 Jul 2026 11:10:53 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A single Envoy Gateway policy can hand a user the keys to your Kubernetes cluster</title><link>https://suriq.io/blog/envoy-gateway-lua-validator-file-read-cve-2026-53713/</link><guid isPermaLink="true">https://suriq.io/blog/envoy-gateway-lua-validator-file-read-cve-2026-53713/</guid><description>CVE-2026-53713 (CVSS 9.1): a path check in Envoy Gateway misses double slashes, letting a submitted Lua policy read the controller&apos;s Kubernetes token and TLS</description><pubDate>Thu, 16 Jul 2026 19:37:33 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Fully patched Windows, no fix: a new local privilege zero-day</title><link>https://suriq.io/blog/legacyhive-windows-profsvc-privilege-zero-day/</link><guid isPermaLink="true">https://suriq.io/blog/legacyhive-windows-profsvc-privilege-zero-day/</guid><description>LegacyHive is a Windows User Profile Service privilege-escalation zero-day that works on fully patched systems, with no CVE and no fix yet.</description><pubDate>Thu, 16 Jul 2026 15:45:59 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A booby-trapped Linux app can escape its sandbox through the audio server and run on your system</title><link>https://suriq.io/blog/pipewire-pulseaudio-sandbox-escape/</link><guid isPermaLink="true">https://suriq.io/blog/pipewire-pulseaudio-sandbox-escape/</guid><description>CVE-2026-5674 lets a sandboxed Linux app abuse PipeWire&apos;s PulseAudio layer to load a malicious library and run code outside the sandbox.</description><pubDate>Thu, 16 Jul 2026 14:09:47 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Old signed UEFI shims still bypass Secure Boot. Update dbx</title><link>https://suriq.io/blog/uefi-shims-secure-boot-revocation/</link><guid isPermaLink="true">https://suriq.io/blog/uefi-shims-secure-boot-revocation/</guid><description>ESET found 11 old Microsoft-signed UEFI shims that bypass Secure Boot on almost any system. Apply the June dbx revocation and verify it across your fleet.</description><pubDate>Thu, 16 Jul 2026 11:37:35 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A WatchGuard firewall can be taken over through its single sign-on agent, no login required</title><link>https://suriq.io/blog/watchguard-firebox-unauth-rce-cve-2026-8247/</link><guid isPermaLink="true">https://suriq.io/blog/watchguard-firebox-unauth-rce-cve-2026-8247/</guid><description>CVE-2026-8247 lets a network-adjacent attacker run code as root on WatchGuard Firebox firewalls with no login.</description><pubDate>Thu, 16 Jul 2026 08:10:30 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>AsyncAPI&apos;s npm packages shipped malware with valid provenance. The supply-chain checkmark waved it through.</title><link>https://suriq.io/blog/asyncapi-npm-provenance-signed-malware/</link><guid isPermaLink="true">https://suriq.io/blog/asyncapi-npm-provenance-signed-malware/</guid><description>Four @asyncapi npm packages shipped a malware loader carrying valid OIDC provenance attestations.</description><pubDate>Wed, 15 Jul 2026 15:51:58 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>RabbitMQ&apos;s takeover flaw is conditional. The quiet one isn&apos;t.</title><link>https://suriq.io/blog/rabbitmq-oauth-secret-leak-cve-2026-57219/</link><guid isPermaLink="true">https://suriq.io/blog/rabbitmq-oauth-secret-leak-cve-2026-57219/</guid><description>RabbitMQ patched CVE-2026-57219 and CVE-2026-57221. The severe OAuth secret leak needs OAuth configured; the quiet metadata bug hits every shared virtual host.</description><pubDate>Wed, 15 Jul 2026 11:23:11 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A rogue extension can still make Claude in Chrome read your Gmail</title><link>https://suriq.io/blog/claude-chrome-extension-forged-click-gmail/</link><guid isPermaLink="true">https://suriq.io/blog/claude-chrome-extension-forged-click-gmail/</guid><description>A rogue browser extension can forge a click that makes Claude for Chrome read your Gmail, Docs, and Calendar, unpatched across eight releases.</description><pubDate>Wed, 15 Jul 2026 09:07:01 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Grafana&apos;s AI connector can leak its access token to a stranger and reach into your cloud</title><link>https://suriq.io/blog/grafana-mcp-server-token-leak-ssrf/</link><guid isPermaLink="true">https://suriq.io/blog/grafana-mcp-server-token-leak-ssrf/</guid><description>A high-severity flaw (CVSS 8.6) in Grafana&apos;s MCP server lets an unauthenticated attacker steal its Grafana service-account token and relay requests into</description><pubDate>Wed, 15 Jul 2026 08:11:56 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Two SonicWall remote-access zero-days are under attack, and patching alone will not clean the box</title><link>https://suriq.io/blog/sonicwall-sma1000-zero-days-exploited-2026-07-14/</link><guid isPermaLink="true">https://suriq.io/blog/sonicwall-sma1000-zero-days-exploited-2026-07-14/</guid><description>SonicWall patched two actively exploited SMA 1000 zero-days, CVE-2026-15409 and CVE-2026-15410.</description><pubDate>Tue, 14 Jul 2026 20:11:52 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Two Microsoft zero-days were exploited before the fix shipped</title><link>https://suriq.io/blog/microsoft-patch-tuesday-zero-days-exploited/</link><guid isPermaLink="true">https://suriq.io/blog/microsoft-patch-tuesday-zero-days-exploited/</guid><description>Microsoft&apos;s July 2026 Patch Tuesday fixes two zero-days already exploited in the wild: an ADFS and a SharePoint Server privilege bug.</description><pubDate>Tue, 14 Jul 2026 18:28:35 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>SAP&apos;s highest-scored July flaw is not the one to patch first</title><link>https://suriq.io/blog/sap-july-2026-critical-patch-priority/</link><guid isPermaLink="true">https://suriq.io/blog/sap-july-2026-critical-patch-priority/</guid><description>SAP&apos;s July 2026 patch day has three criticals. The top-scored 9.9 NetWeaver bug needs a login; the two pre-auth 9.1s in AppRouter and Commerce Cloud go first.</description><pubDate>Tue, 14 Jul 2026 16:44:45 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Notarized by Apple, still malware: the CrashStealer Mac stealer</title><link>https://suriq.io/blog/crashstealer-notarized-macos-gatekeeper/</link><guid isPermaLink="true">https://suriq.io/blog/crashstealer-notarized-macos-gatekeeper/</guid><description>CrashStealer is a macOS info-stealer that Apple notarized, so Gatekeeper cleared it on launch before it drained keychains, browser logins and crypto wallets.</description><pubDate>Tue, 14 Jul 2026 11:51:34 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>The appliances you install to be safer were the week’s most dangerous bugs</title><link>https://suriq.io/blog/signal-safety-appliances-broke-authorization/</link><guid isPermaLink="true">https://suriq.io/blog/signal-safety-appliances-broke-authorization/</guid><description>Dell Data Domain, Progress ShareFile and BeyondTrust all failed at authorization this week.</description><pubDate>Tue, 14 Jul 2026 09:16:57 GMT</pubDate><category>Deep dive</category><author>Suriq&apos;s Jack</author></item><item><title>An 18-year-old Cisco router flaw is being exploited, and no patch is coming</title><link>https://suriq.io/blog/cisco-ios-csrf-legacy-router-kev-exploited/</link><guid isPermaLink="true">https://suriq.io/blog/cisco-ios-csrf-legacy-router-kev-exploited/</guid><description>CISA flagged an 18-year-old Cisco IOS flaw (CVE-2008-4128) as actively exploited. What it hits, why old routers are the target, and how to shut it down.</description><pubDate>Tue, 14 Jul 2026 05:40:40 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>How a PNG in a pull request makes AI agents leak secrets</title><link>https://suriq.io/blog/ghostcommit-png-prompt-injection-ai-agents/</link><guid isPermaLink="true">https://suriq.io/blog/ghostcommit-png-prompt-injection-ai-agents/</guid><description>Researchers hid prompt-injection text inside a PNG in a pull request and made AI coding agents read .env and leak the secrets.</description><pubDate>Mon, 13 Jul 2026 16:26:45 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Mass CMS campaign turns unpatched plugins into webshells</title><link>https://suriq.io/blog/cms-webshell-campaign-unpatched-plugins/</link><guid isPermaLink="true">https://suriq.io/blog/cms-webshell-campaign-unpatched-plugins/</guid><description>Australia&apos;s cyber agency warns of a global campaign mass-exploiting 16 known CMS and plugin flaws to drop webshells on WordPress, Joomla and Craft sites.</description><pubDate>Mon, 13 Jul 2026 12:32:15 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A Helix Ultimate flaw lets an anonymous visitor hijack a Joomla admin, and a working exploit is now public</title><link>https://suriq.io/blog/helix-ultimate-joomla-unauthenticated-menu-xss/</link><guid isPermaLink="true">https://suriq.io/blog/helix-ultimate-joomla-unauthenticated-menu-xss/</guid><description>A public exploit now targets CVE-2026-57829, an unauthenticated stored XSS in the Helix Ultimate Joomla framework below 2.2.7.</description><pubDate>Mon, 13 Jul 2026 08:24:03 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A cache-plugin flaw backdoored 17,000 WordPress sites. A max-severity bug got 77.</title><link>https://suriq.io/blog/wp-shellstorm-wordpress-webshell-detection/</link><guid isPermaLink="true">https://suriq.io/blog/wp-shellstorm-wordpress-webshell-detection/</guid><description>An exposed server revealed WP-SHELLSTORM, a WordPress and Joomla webshell operation. Its own logs show CVE severity barely predicted which sites got hacked.</description><pubDate>Sun, 12 Jul 2026 19:28:51 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A single rigged device name can hijack an OpenWrt router&apos;s admin panel</title><link>https://suriq.io/blog/openwrt-luci-dhcpv6-hostname-xss/</link><guid isPermaLink="true">https://suriq.io/blog/openwrt-luci-dhcpv6-hostname-xss/</guid><description>A stored XSS in OpenWrt&apos;s LuCI web panel (CVE-2026-61876, CVSS 8.8) lets a device on the LAN plant a script in a DHCPv6 hostname that runs in the admin&apos;s</description><pubDate>Sun, 12 Jul 2026 19:08:34 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Ghost accounts are mapping your GitHub org. The recon is invisible; the stolen token is not.</title><link>https://suriq.io/blog/github-org-enumeration-ghost-accounts-leaked-tokens/</link><guid isPermaLink="true">https://suriq.io/blog/github-org-enumeration-ghost-accounts-leaked-tokens/</guid><description>Datadog found 50+ dormant GitHub accounts enumerating corporate orgs through the public API, some escalating to private-repo clones with stolen tokens.</description><pubDate>Sun, 12 Jul 2026 16:17:01 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Zimbra&apos;s Classic Web Client can run code from a crafted email again. Patch to 10.1.19 now.</title><link>https://suriq.io/blog/zimbra-classic-web-client-crafted-email-xss/</link><guid isPermaLink="true">https://suriq.io/blog/zimbra-classic-web-client-crafted-email-xss/</guid><description>Zimbra shipped ZCS 10.1.19 to fix a stored XSS in the Classic Web Client that runs code from a crafted email. Google TAG reported it; no public exploit yet.</description><pubDate>Sun, 12 Jul 2026 12:49:32 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>npm just killed install-script malware by default. This week&apos;s other attack walks right past it.</title><link>https://suriq.io/blog/npm-12-install-scripts-supply-chain-blind-spot/</link><guid isPermaLink="true">https://suriq.io/blog/npm-12-install-scripts-supply-chain-blind-spot/</guid><description>npm 12 disables install scripts by default, which would have stopped this week&apos;s jscrambler infostealer.</description><pubDate>Sat, 11 Jul 2026 19:24:17 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Progress tells ShareFile users to shut servers down, and no patch means assume breach</title><link>https://suriq.io/blog/progress-sharefile-storage-zone-shutdown/</link><guid isPermaLink="true">https://suriq.io/blog/progress-sharefile-storage-zone-shutdown/</guid><description>Progress told ShareFile customers to shut down on-premises Storage Zone Controllers over a credible threat.</description><pubDate>Sat, 11 Jul 2026 16:24:46 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Super Forms flaw lets anyone take over a WordPress site, and a working exploit is now public</title><link>https://suriq.io/blog/super-forms-wordpress-file-upload-rce/</link><guid isPermaLink="true">https://suriq.io/blog/super-forms-wordpress-file-upload-rce/</guid><description>A critical flaw (CVSS 9.8) in the Super Forms WordPress plugin lets unauthenticated attackers run code on the server.</description><pubDate>Sat, 11 Jul 2026 16:09:40 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>GigaWiper fakes a ransomware hit to cover a disk wipe, and the only early warning is on the host</title><link>https://suriq.io/blog/gigawiper-fake-ransomware-disk-wiper/</link><guid isPermaLink="true">https://suriq.io/blog/gigawiper-fake-ransomware-disk-wiper/</guid><description>GigaWiper encrypts files to .candy with no key and no ransom note, because the ransomware is a decoy for a disk wipe. Here are the host signals that catch it.</description><pubDate>Sat, 11 Jul 2026 11:48:10 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A rigged Jira ticket can trick the mcp-atlassian AI connector into leaking server files</title><link>https://suriq.io/blog/mcp-atlassian-upload-arbitrary-file-read/</link><guid isPermaLink="true">https://suriq.io/blog/mcp-atlassian-upload-arbitrary-file-read/</guid><description>mcp-atlassian before 0.22.0 reads files off its own host when a caller or a prompt-injected agent supplies a server-side path.</description><pubDate>Sat, 11 Jul 2026 00:56:51 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Two more Joomla extensions hit the exploited list. It is the same bug, five times now.</title><link>https://suriq.io/blog/joomla-balbooa-icagenda-upload-rce-kev/</link><guid isPermaLink="true">https://suriq.io/blog/joomla-balbooa-icagenda-upload-rce-kev/</guid><description>CISA added Balbooa Forms (CVE-2026-56291) and iCagenda (CVE-2026-48939) to its exploited list on July 10, the fourth and fifth Joomla extension with the same</description><pubDate>Fri, 10 Jul 2026 18:57:14 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Three attacks in one week turned AI coding agents into an unmonitored way onto your network</title><link>https://suriq.io/blog/hallusquatting-ai-coding-agent-endpoint-risk/</link><guid isPermaLink="true">https://suriq.io/blog/hallusquatting-ai-coding-agent-endpoint-risk/</guid><description>HalluSquatting and Friendly Fire show AI coding agents running attacker code with a developer&apos;s privileges. No CVE, no patch. Here is the detection posture.</description><pubDate>Fri, 10 Jul 2026 16:58:22 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Three ransomware responders secretly worked for BlackCat. Trust is the attack surface.</title><link>https://suriq.io/blog/insider-ransomware-negotiators-blackcat/</link><guid isPermaLink="true">https://suriq.io/blog/insider-ransomware-negotiators-blackcat/</guid><description>Three incident-response insiders at DigitalMint and Sygnia were sentenced for helping run BlackCat ransomware, one leaking victims&apos; insurance limits.</description><pubDate>Fri, 10 Jul 2026 11:58:07 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A fake 7-Zip installer rents your server out as a residential proxy, and file scans miss it</title><link>https://suriq.io/blog/lurking-lizard-fake-7zip-residential-proxy/</link><guid isPermaLink="true">https://suriq.io/blog/lurking-lizard-fake-7zip-residential-proxy/</guid><description>A trojanized 7-Zip and VPN campaign called Lurking Lizard turns servers and PCs into residential proxy nodes.</description><pubDate>Fri, 10 Jul 2026 08:57:13 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Patched but still defaced: the Helix3 Joomla flaw that hides in your database, not your files</title><link>https://suriq.io/blog/helix3-joomla-antonkill-database-defacement/</link><guid isPermaLink="true">https://suriq.io/blog/helix3-joomla-antonkill-database-defacement/</guid><description>An unauthenticated bug in JoomShaper&apos;s Helix3 (CVE-2026-49049) is defacing Joomla sites. It hides in the database, so patching to 3.1.2 alone won&apos;t clean it.</description><pubDate>Fri, 10 Jul 2026 08:41:28 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>GhostLock turns any Linux foothold into host root, and containers don&apos;t stop it</title><link>https://suriq.io/blog/ghostlock-linux-kernel-container-escape-root/</link><guid isPermaLink="true">https://suriq.io/blog/ghostlock-linux-kernel-container-escape-root/</guid><description>GhostLock (CVE-2026-43499) is a 15-year-old Linux kernel flaw that turns any local foothold into host root and escapes containers. Who is exposed, how to patch.</description><pubDate>Thu, 09 Jul 2026 20:04:37 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A Google chatbot &apos;edit&apos; permission was really a code-execution grant</title><link>https://suriq.io/blog/dialogflow-cx-rogue-agent-edit-permission/</link><guid isPermaLink="true">https://suriq.io/blog/dialogflow-cx-rogue-agent-edit-permission/</guid><description>Google&apos;s Dialogflow CX let one edit permission run code across every chatbot in a project.</description><pubDate>Thu, 09 Jul 2026 15:12:57 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>GodDamn ransomware blinds EDR with a signed kernel driver. Detect the load, not the file.</title><link>https://suriq.io/blog/signed-kernel-driver-edr-killer/</link><guid isPermaLink="true">https://suriq.io/blog/signed-kernel-driver-edr-killer/</guid><description>GodDamn ransomware uses PoisonX, a kernel driver carrying a valid Microsoft signature, to disable EDR.</description><pubDate>Thu, 09 Jul 2026 12:34:05 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>How to Use the Wazuh API: Authenticate, Query Agents, and Automate</title><link>https://suriq.io/blog/how-to-use-wazuh-api/</link><guid isPermaLink="true">https://suriq.io/blog/how-to-use-wazuh-api/</guid><description>How to use the Wazuh API: authenticate on port 55000 for a JWT token, then query your agents and automate with copy-pasteable curl commands and a worked</description><pubDate>Thu, 09 Jul 2026 09:25:02 GMT</pubDate><category>Explainers</category><author>Suriq&apos;s Jack</author></item><item><title>Five Tenda router models ship a hidden admin password. With no patch, containment is the only move.</title><link>https://suriq.io/blog/tenda-router-hardcoded-backdoor-no-patch/</link><guid isPermaLink="true">https://suriq.io/blog/tenda-router-hardcoded-backdoor-no-patch/</guid><description>CERT/CC flagged a hardcoded admin password in five Tenda router models (CVE-2026-11405). No fix exists yet, so here is how to detect and contain it.</description><pubDate>Thu, 09 Jul 2026 08:36:46 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A public GitHub issue made an AI agent leak a private repo. No patch closes this class.</title><link>https://suriq.io/blog/gitlost-github-agent-repo-leak/</link><guid isPermaLink="true">https://suriq.io/blog/gitlost-github-agent-repo-leak/</guid><description>A crafted public GitHub issue tricked an AI Agentic Workflow into posting a private repo&apos;s contents as a public comment. Why no patch closes this class.</description><pubDate>Wed, 08 Jul 2026 18:56:33 GMT</pubDate><category>Security news</category><category>Thought leadership</category><author>Suriq&apos;s Jack</author></item><item><title>Two pre-auth bypasses hit BeyondTrust&apos;s privileged-access appliances, found by the vendor&apos;s own AI</title><link>https://suriq.io/blog/beyondtrust-remote-support-pra-auth-bypass/</link><guid isPermaLink="true">https://suriq.io/blog/beyondtrust-remote-support-pra-auth-bypass/</guid><description>BeyondTrust patched four flaws in Remote Support and Privileged Remote Access, including two pre-auth CVSS 9.2 bypasses. Upgrade to 25.3.3 and hunt the window.</description><pubDate>Wed, 08 Jul 2026 15:29:36 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A low-privilege user could overreach on Dell&apos;s Data Domain backup appliances. The fix is out.</title><link>https://suriq.io/blog/dell-data-domain-authorization-flaw-cve-2026-56086/</link><guid isPermaLink="true">https://suriq.io/blog/dell-data-domain-authorization-flaw-cve-2026-56086/</guid><description>CVE-2026-56086 lets a low-privileged remote user gain unauthorized access on Dell PowerProtect Data Domain backup appliances. CVSS 8.8. Patched builds are out.</description><pubDate>Wed, 08 Jul 2026 14:38:37 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Two Joomla page builders are exploited for site takeover. The patch won&apos;t evict the intruder.</title><link>https://suriq.io/blog/joomla-page-builder-uploads-exploited-kev/</link><guid isPermaLink="true">https://suriq.io/blog/joomla-page-builder-uploads-exploited-kev/</guid><description>CISA flagged two CVSS-10 Joomla page-builder flaws, SP Page Builder (CVE-2026-48908) and Page Builder CK (CVE-2026-56290), as exploited.</description><pubDate>Wed, 08 Jul 2026 12:05:22 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A logged-in user can hijack the Linux graphics server, and on many systems that means root</title><link>https://suriq.io/blog/xorg-xwayland-graphics-server-memory-corruption/</link><guid isPermaLink="true">https://suriq.io/blog/xorg-xwayland-graphics-server-memory-corruption/</guid><description>X.Org patched two memory-corruption bugs in the X server and XWayland. A local client can reach root where Xorg runs as root. Update to 21.1.24 and 24.1.13.</description><pubDate>Wed, 08 Jul 2026 08:41:02 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Adobe ColdFusion is under active attack, but the max-severity rating overstates who is exposed</title><link>https://suriq.io/blog/adobe-coldfusion-cve-2026-48282-exploited-kev/</link><guid isPermaLink="true">https://suriq.io/blog/adobe-coldfusion-cve-2026-48282-exploited-kev/</guid><description>Adobe ColdFusion flaw CVE-2026-48282 (CVSS 10.0) is now exploited in the wild and in CISA KEV. Who is actually exposed, how to detect it, and what to patch.</description><pubDate>Tue, 07 Jul 2026 20:11:04 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>The new Cavern C2 needs no CVE. It abuses your IT provider&apos;s own tools to get in.</title><link>https://suriq.io/blog/cavern-manticore-c2-no-cve-it-provider-supply-chain/</link><guid isPermaLink="true">https://suriq.io/blog/cavern-manticore-c2-no-cve-it-provider-supply-chain/</guid><description>Check Point ties the Iran-linked Cavern C2 to intrusions that skip vulnerabilities entirely, abusing IT providers&apos; own deployment tools.</description><pubDate>Tue, 07 Jul 2026 19:16:01 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Django shipped three low-severity security fixes. One of them deserves a closer look.</title><link>https://suriq.io/blog/django-6-0-7-5-2-16-security-release/</link><guid isPermaLink="true">https://suriq.io/blog/django-6-0-7-5-2-16-security-release/</guid><description>Django 6.0.7 and 5.2.16 patch three low-severity issues: a header injection, a cache data leak, and a heap over-read.</description><pubDate>Tue, 07 Jul 2026 15:11:35 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Januscape: nested virtualization reopens a 16-year-old escape out of the KVM guest</title><link>https://suriq.io/blog/januscape-kvm-guest-host-vm-escape/</link><guid isPermaLink="true">https://suriq.io/blog/januscape-kvm-guest-host-vm-escape/</guid><description>Januscape (CVE-2026-53359) is a 16-year-old KVM use-after-free that lets a rooted guest VM crash its Linux host. Nested virtualization is the trigger.</description><pubDate>Tue, 07 Jul 2026 12:32:41 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A default in Red Hat&apos;s Linux login system lets one directory account seize root on every server</title><link>https://suriq.io/blog/sssd-sudo-default-root-escalation/</link><guid isPermaLink="true">https://suriq.io/blog/sssd-sudo-default-root-escalation/</guid><description>CVE-2026-14474: when SSSD&apos;s LDAP sudo provider has no explicit search base, one directory account can plant a rule that grants root on every enrolled Linux</description><pubDate>Tue, 07 Jul 2026 11:09:11 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Gitea&apos;s Docker image trusts a login header from anyone, and probing has started</title><link>https://suriq.io/blog/gitea-docker-reverse-proxy-auth-bypass/</link><guid isPermaLink="true">https://suriq.io/blog/gitea-docker-reverse-proxy-auth-bypass/</guid><description>A default in Gitea&apos;s Docker image trusts the X-WEBAUTH-USER header from any IP, so anyone can log in as any user.</description><pubDate>Mon, 06 Jul 2026 18:39:23 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Formie&apos;s second hidden-field flaw in five weeks lets a stranger run code on your Craft CMS site</title><link>https://suriq.io/blog/formie-craft-cms-template-injection/</link><guid isPermaLink="true">https://suriq.io/blog/formie-craft-cms-template-injection/</guid><description>Formie for Craft CMS has a critical flaw (CVE-2026-52889) that lets an unauthenticated visitor inject Twig template code through a hidden field.</description><pubDate>Mon, 06 Jul 2026 17:10:09 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>AI reopened a 2017-audited filesystem and found seven bugs your devices can&apos;t patch</title><link>https://suriq.io/blog/fatfs-embedded-devices-seven-flaws-no-patch/</link><guid isPermaLink="true">https://suriq.io/blog/fatfs-embedded-devices-seven-flaws-no-patch/</guid><description>runZero found seven flaws in FatFs, the filesystem inside millions of cameras, drones and controllers. No upstream patch exists. How to detect and contain it.</description><pubDate>Mon, 06 Jul 2026 11:41:27 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>SUSE Rancher patched critical flaws that turn a small foothold into full control of your Kubernetes clusters</title><link>https://suriq.io/blog/rancher-fleet-foothold-to-cluster-takeover/</link><guid isPermaLink="true">https://suriq.io/blog/rancher-fleet-foothold-to-cluster-takeover/</guid><description>SUSE Rancher and Fleet patched critical flaws that let a leaked token or one tenant account seize whole Kubernetes clusters.</description><pubDate>Mon, 06 Jul 2026 10:54:23 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Kairos stole 2TB, encrypted nothing, and still got $1M. Watch the login, not the file locker.</title><link>https://suriq.io/blog/kairos-encryptionless-extortion-detection/</link><guid isPermaLink="true">https://suriq.io/blog/kairos-encryptionless-extortion-detection/</guid><description>Kairos stole 2TB from a US county, encrypted nothing, and was paid $1M. Encryptionless extortion breaks file-locker alarms. Detect the login and egress.</description><pubDate>Sun, 05 Jul 2026 16:39:45 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>We said a password reset wouldn&apos;t stop FortiBleed. Now it is deploying ransomware.</title><link>https://suriq.io/blog/fortibleed-credentials-inc-lynx-ransomware/</link><guid isPermaLink="true">https://suriq.io/blog/fortibleed-credentials-inc-lynx-ransomware/</guid><description>FortiBleed harvested 110 million Fortinet credentials. SOCRadar links that access to INC and Lynx ransomware, with 12 encryptions and a Nextcloud zero-day.</description><pubDate>Sun, 05 Jul 2026 11:34:59 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A poisoned security scanner ran on your build server and walked out with your cloud keys</title><link>https://suriq.io/blog/teampcp-supply-chain-cloud-credentials/</link><guid isPermaLink="true">https://suriq.io/blog/teampcp-supply-chain-cloud-credentials/</guid><description>The FBI&apos;s TeamPCP FLASH alert shows why a trojanized scanner steals from your servers, not the registry, and why pinning packages will not save you.</description><pubDate>Sun, 05 Jul 2026 08:39:18 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A Linux kernel bug called Bad Epoll turns a sandboxed process into root, and the exploit is now public</title><link>https://suriq.io/blog/bad-epoll-linux-kernel-privesc-sandbox-escape/</link><guid isPermaLink="true">https://suriq.io/blog/bad-epoll-linux-kernel-privesc-sandbox-escape/</guid><description>Bad Epoll (CVE-2026-46242) lets a sandboxed or unprivileged process reach root on Linux 6.4+ and Android. Fixed in April; a public 99% exploit now exists.</description><pubDate>Sat, 04 Jul 2026 19:29:45 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>No password needed: a public exploit now hijacks unpatched Control Web Panel servers</title><link>https://suriq.io/blog/control-web-panel-cve-2026-57517-public-exploit/</link><guid isPermaLink="true">https://suriq.io/blog/control-web-panel-cve-2026-57517-public-exploit/</guid><description>A public exploit for a critical Control Web Panel flaw (CVE-2026-57517) lets unauthenticated attackers seize hosting servers. Patch to 0.9.8.1225 and hunt now.</description><pubDate>Sat, 04 Jul 2026 15:12:49 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>The FBI seized NetNut&apos;s proxy network. Its two million compromised devices are still infected.</title><link>https://suriq.io/blog/netnut-proxy-takedown-devices-still-infected/</link><guid isPermaLink="true">https://suriq.io/blog/netnut-proxy-takedown-devices-still-infected/</guid><description>The FBI and Google seized the NetNut residential proxy network on July 2, but its two million compromised devices are still infected. Why IP reputation fails.</description><pubDate>Sat, 04 Jul 2026 11:53:59 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Scattered Spider keeps winning because your help desk, not a CVE, is the way in</title><link>https://suriq.io/blog/scattered-spider-help-desk-attack/</link><guid isPermaLink="true">https://suriq.io/blog/scattered-spider-help-desk-attack/</guid><description>An extradited Scattered Spider suspect breached a retailer in under three hours through a help-desk password reset. Here is the identity control that stops it.</description><pubDate>Sat, 04 Jul 2026 09:07:08 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Kemp LoadMaster&apos;s quote sanitizer became a pre-auth root RCE, exploited hours after the writeup dropped</title><link>https://suriq.io/blog/kemp-loadmaster-cve-2026-8037-exploited/</link><guid isPermaLink="true">https://suriq.io/blog/kemp-loadmaster-cve-2026-8037-exploited/</guid><description>Kemp LoadMaster&apos;s CVE-2026-8037 gives unauthenticated root through its API and is under active exploitation. Affected versions, the fix, and how to detect it.</description><pubDate>Fri, 03 Jul 2026 15:37:59 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>The first AI-run ransomware locked a database with a key it never saved</title><link>https://suriq.io/blog/ai-agent-ransomware-langflow-unrecoverable/</link><guid isPermaLink="true">https://suriq.io/blog/ai-agent-ransomware-langflow-unrecoverable/</guid><description>The first ransomware attack run end to end by an AI agent broke in through a year-old Langflow flaw and encrypted a database with a key it never saved.</description><pubDate>Fri, 03 Jul 2026 12:17:09 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Cursor&apos;s AI agent trusted the content it read, and that content could switch off its sandbox</title><link>https://suriq.io/blog/cursor-duneslide-sandbox-escape-rce/</link><guid isPermaLink="true">https://suriq.io/blog/cursor-duneslide-sandbox-escape-rce/</guid><description>Two critical Cursor flaws, DuneSlide (CVE-2026-50548/50549, CVSS 9.8), let a poisoned MCP server or web result overwrite the sandbox binary and run code.</description><pubDate>Fri, 03 Jul 2026 08:42:31 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Puppet stored the passwords it was told to hide in cleartext on every managed node</title><link>https://suriq.io/blog/puppet-resource-api-cleartext-secrets/</link><guid isPermaLink="true">https://suriq.io/blog/puppet-resource-api-cleartext-secrets/</guid><description>CVE-2026-8804: Puppet&apos;s Resource API stopped honoring the sensitive flag, writing passwords in cleartext to each agent&apos;s state cache. Upgrade, then rotate.</description><pubDate>Fri, 03 Jul 2026 08:26:20 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Argo CD can be taken over from inside your cluster, and there is no patch to wait for</title><link>https://suriq.io/blog/argo-cd-repo-server-unauth-rce-no-patch/</link><guid isPermaLink="true">https://suriq.io/blog/argo-cd-repo-server-unauth-rce-no-patch/</guid><description>Argo CD&apos;s repo-server runs code for unauthenticated callers and can take over your Kubernetes cluster. No patch or CVE exists yet, so isolate and watch it now.</description><pubDate>Thu, 02 Jul 2026 19:07:00 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A rigged puzzle talked six AI browsers into leaking a developer&apos;s SSH keys. One patch won&apos;t save you.</title><link>https://suriq.io/blog/bioshocking-ai-browser-agent-credential-leak/</link><guid isPermaLink="true">https://suriq.io/blog/bioshocking-ai-browser-agent-credential-leak/</guid><description>A game-themed web page talked six AI browsers into leaking a developer&apos;s SSH keys. Why patching one vendor is not the fix, and what to watch instead.</description><pubDate>Thu, 02 Jul 2026 15:51:49 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Fake exploit code is delivering ChocoPoC, a stealer aimed at the researchers who run it</title><link>https://suriq.io/blog/chocopoc-fake-poc-exploit-stealer/</link><guid isPermaLink="true">https://suriq.io/blog/chocopoc-fake-poc-exploit-stealer/</guid><description>ChocoPoC hides a credential-stealing trojan inside fake CVE proof-of-concept repos, targeting the researchers and red teams who download and test them.</description><pubDate>Thu, 02 Jul 2026 11:47:01 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>How to Use Wazuh: A Practitioner&apos;s Guide to Agents, the Dashboard, and Detection</title><link>https://suriq.io/blog/how-to-use-wazuh/</link><guid isPermaLink="true">https://suriq.io/blog/how-to-use-wazuh/</guid><description>How to use Wazuh: install the server, enroll an agent, reach the dashboard, and write and test a detection rule with wazuh-logtest.</description><pubDate>Thu, 02 Jul 2026 09:12:41 GMT</pubDate><category>Explainers</category><author>Noam Alum</author></item><item><title>Microsoft said this SharePoint bug was unlikely to be exploited. CISA just proved it wrong.</title><link>https://suriq.io/blog/sharepoint-cve-2026-45659-kev-exploited/</link><guid isPermaLink="true">https://suriq.io/blog/sharepoint-cve-2026-45659-kev-exploited/</guid><description>Microsoft rated SharePoint&apos;s CVE-2026-45659 unlikely to be exploited. CISA added it to the KEV catalog on July 1 after active exploitation. Patch and hunt now.</description><pubDate>Thu, 02 Jul 2026 08:33:26 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Adobe&apos;s six max-severity ColdFusion flaws have no exploit yet, and that is the countdown</title><link>https://suriq.io/blog/adobe-coldfusion-max-severity-rce-patch/</link><guid isPermaLink="true">https://suriq.io/blog/adobe-coldfusion-max-severity-rce-patch/</guid><description>Adobe patched six unauthenticated CVSS 10.0 code-execution flaws in ColdFusion (bulletin APSB26-68).</description><pubDate>Wed, 01 Jul 2026 19:21:44 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>MFA did not stop the Azure CLI password spray. A retired login flow is why.</title><link>https://suriq.io/blog/azure-cli-password-spray-mfa-bypass/</link><guid isPermaLink="true">https://suriq.io/blog/azure-cli-password-spray-mfa-bypass/</guid><description>A password spray beat Conditional Access at 64 organizations by abusing ROPC, a retired Azure login flow that never triggers an MFA prompt. What to fix now.</description><pubDate>Wed, 01 Jul 2026 15:44:21 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Citrix shipped six NetScaler fixes. One of them isn&apos;t done until you change a setting.</title><link>https://suriq.io/blog/citrix-netscaler-http2-bomb-memory-leak/</link><guid isPermaLink="true">https://suriq.io/blog/citrix-netscaler-http2-bomb-memory-leak/</guid><description>Citrix fixed six NetScaler flaws, including a pre-login memory leak and an HTTP/2 Bomb denial of service. One fix needs a config change, not just an upgrade.</description><pubDate>Wed, 01 Jul 2026 12:00:27 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Ransomware that runs inside your browser tab, where antivirus cannot see it</title><link>https://suriq.io/blog/browser-only-ransomware-file-system-access/</link><guid isPermaLink="true">https://suriq.io/blog/browser-only-ransomware-file-system-access/</guid><description>Check Point built browser-only ransomware from a DeepSeek AI output: a web page encrypts your files through a legitimate browser API, with no binary for</description><pubDate>Wed, 01 Jul 2026 11:10:54 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>AI keeps inventing web addresses that do not exist. Attackers now buy them first.</title><link>https://suriq.io/blog/phantom-squatting-ai-hallucinated-domains/</link><guid isPermaLink="true">https://suriq.io/blog/phantom-squatting-ai-hallucinated-domains/</guid><description>Unit 42 found attackers registering the fake web domains AI models hallucinate, turning a chatbot&apos;s answer into a phishing and supply chain threat.</description><pubDate>Wed, 01 Jul 2026 01:23:38 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>An old bash trick makes AI coding agents run the commands they just blocked</title><link>https://suriq.io/blog/ai-coding-agent-guardrail-bypass/</link><guid isPermaLink="true">https://suriq.io/blog/ai-coding-agent-guardrail-bypass/</guid><description>AI coding agent guardrails fall to GuardFall, a bash trick that bypassed the command safety check in 10 of 11 open-source agents Adversa AI tested.</description><pubDate>Tue, 30 Jun 2026 19:07:57 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>119 browser extensions hid malware inside images and fonts for two years</title><link>https://suriq.io/blog/stegoad-edge-extension-steganography/</link><guid isPermaLink="true">https://suriq.io/blog/stegoad-edge-extension-steganography/</guid><description>Microsoft pulled 119 malicious Edge extensions in the StegoAd campaign. Steganographic payloads, 2.6 million installs, and a 2FA lesson for defenders.</description><pubDate>Tue, 30 Jun 2026 16:56:06 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Oracle E-Business Suite is under attack again, and the patch has been out since May</title><link>https://suriq.io/blog/oracle-ebs-payments-cve-2026-46817/</link><guid isPermaLink="true">https://suriq.io/blog/oracle-ebs-payments-cve-2026-46817/</guid><description>CVE-2026-46817, a CVSS 9.8 flaw in Oracle E-Business Suite Payments, is exploited weeks after Oracle&apos;s May patch. What to check and how to fix it now.</description><pubDate>Tue, 30 Jun 2026 13:07:29 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A forged login key unlocks SimpleHelp servers, and a new stealer is raiding cloud and AI credentials</title><link>https://suriq.io/blog/simplehelp-auth-bypass-djinn-stealer/</link><guid isPermaLink="true">https://suriq.io/blog/simplehelp-auth-bypass-djinn-stealer/</guid><description>A maximum-severity SimpleHelp flaw, CVE-2026-48558, lets attackers forge a login and is now exploited to drop Djinn Stealer against cloud and AI keys.</description><pubDate>Tue, 30 Jun 2026 10:55:52 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>The code was clean. The toolchain that shipped it was the attack.</title><link>https://suriq.io/blog/signal-toolchain-is-the-attack-surface/</link><guid isPermaLink="true">https://suriq.io/blog/signal-toolchain-is-the-attack-surface/</guid><description>This week&apos;s most serious compromises were not in application code but in the tools that build, ship, and assist it. The pattern, and what to do.</description><pubDate>Tue, 30 Jun 2026 09:12:57 GMT</pubDate><category>Deep dive</category><author>Suriq&apos;s Jack</author></item><item><title>A crafted link can stall millions of Node apps, and the patch will not reach most of them</title><link>https://suriq.io/blog/decode-uri-component-dos-patch-gap/</link><guid isPermaLink="true">https://suriq.io/blog/decode-uri-component-dos-patch-gap/</guid><description>decode-uri-component, the npm decoder behind query-string and millions of apps, has a denial-of-service bug (CVE-2026-45822).</description><pubDate>Tue, 30 Jun 2026 08:42:11 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>You don&apos;t have to install this npm malware. Opening the folder in your editor runs it.</title><link>https://suriq.io/blog/vscode-folderopen-npm-supply-chain-stealer/</link><guid isPermaLink="true">https://suriq.io/blog/vscode-folderopen-npm-supply-chain-stealer/</guid><description>Two hijacked npm packages skip the install step entirely. They run when you open the project in VS Code, then steal developer, browser, and wallet logins.</description><pubDate>Mon, 29 Jun 2026 18:53:09 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>The repo is clean. Your AI coding agent is what hands the attacker a shell.</title><link>https://suriq.io/blog/clean-repo-ai-coding-agent-reverse-shell/</link><guid isPermaLink="true">https://suriq.io/blog/clean-repo-ai-coding-agent-reverse-shell/</guid><description>Mozilla&apos;s 0DIN made Claude Code open a reverse shell from a GitHub repo with no malicious code. Here is why scanners miss it and how to constrain the agent.</description><pubDate>Mon, 29 Jun 2026 15:54:37 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>This backdoor is named after your VMware and EDR tools. Your allowlist trusts it.</title><link>https://suriq.io/blog/tinyrct-backdoor-disguised-security-tools/</link><guid isPermaLink="true">https://suriq.io/blog/tinyrct-backdoor-disguised-security-tools/</guid><description>A Chinese APT called CL-STA-1062 ships its TinyRCT backdoor disguised as VMware and EDR agents. Why filename allowlists miss it, and what to hunt instead.</description><pubDate>Mon, 29 Jun 2026 12:58:23 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>SUSE Linux trusted software repositories enough to let one overwrite your system files</title><link>https://suriq.io/blog/suse-libzypp-repo-metadata-file-overwrite/</link><guid isPermaLink="true">https://suriq.io/blog/suse-libzypp-repo-metadata-file-overwrite/</guid><description>SUSE and openSUSE patched seven flaws in their package manager. CVE-2026-25707 lets a malicious repository overwrite system files as root.</description><pubDate>Mon, 29 Jun 2026 11:25:34 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>libssh2 flaw: a malicious SSH server can hijack the client connecting to it</title><link>https://suriq.io/blog/libssh2-malicious-server-client-rce/</link><guid isPermaLink="true">https://suriq.io/blog/libssh2-malicious-server-client-rce/</guid><description>libssh2&apos;s CVE-2026-55200 lets a malicious SSH server run code on the client that connects to it. No login, a public PoC is out, and there is no tagged fix yet.</description><pubDate>Mon, 29 Jun 2026 08:30:37 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Hotels are running malware on a legitimate Node.js runtime, and that beats allowlisting</title><link>https://suriq.io/blog/tonrat-nodejs-hotel-phishing-implant/</link><guid isPermaLink="true">https://suriq.io/blog/tonrat-nodejs-hotel-phishing-implant/</guid><description>TonRAT runs on a genuine Node.js runtime on hotel front-desk machines, hides its C2 on the TON blockchain, and slips past allowlists. Here is what to hunt.</description><pubDate>Sun, 28 Jun 2026 18:15:36 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A seized iPhone gave up everything. The MacBook beside it gave up nothing.</title><link>https://suriq.io/blog/cellebrite-seized-device-encryption-lesson/</link><guid isPermaLink="true">https://suriq.io/blog/cellebrite-seized-device-encryption-lesson/</guid><description>Cellebrite&apos;s UFED tool fully read a locked iPhone in Russian custody but failed on the encrypted MacBook seized beside it.</description><pubDate>Sun, 28 Jun 2026 16:29:14 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Linux&apos;s newest root exploits rewrite /bin/su in memory and leave the file clean</title><link>https://suriq.io/blog/dirtyclone-linux-page-cache-privesc/</link><guid isPermaLink="true">https://suriq.io/blog/dirtyclone-linux-page-cache-privesc/</guid><description>DirtyClone and pedit COW are the latest in a family of Linux kernel root bugs that rewrite binaries in memory, invisible to file-integrity monitoring.</description><pubDate>Sun, 28 Jun 2026 12:08:33 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A rigged 7-Zip archive can erase the Windows warning on downloaded files, and there is no fix yet</title><link>https://suriq.io/blog/7-zip-archive-strips-windows-download-warning/</link><guid isPermaLink="true">https://suriq.io/blog/7-zip-archive-strips-windows-download-warning/</guid><description>A crafted RAR5 archive lets 7-Zip 26.02 strip the Mark-of-the-Web, defeating Windows SmartScreen warnings. No patch exists yet.</description><pubDate>Sun, 28 Jun 2026 09:55:31 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Signal&apos;s recovery key never expires, and Russian intelligence is now phishing for it</title><link>https://suriq.io/blog/signal-recovery-key-phishing-russia/</link><guid isPermaLink="true">https://suriq.io/blog/signal-recovery-key-phishing-russia/</guid><description>Russian intelligence is phishing Signal users for the Backup Recovery Key, a secret that decrypts a whole message history and that no reset or new account can</description><pubDate>Sat, 27 Jun 2026 16:29:26 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Polymarket&apos;s servers were never hacked. A poisoned vendor script still stole $3 million from users.</title><link>https://suriq.io/blog/polymarket-frontend-supply-chain-theft/</link><guid isPermaLink="true">https://suriq.io/blog/polymarket-frontend-supply-chain-theft/</guid><description>A compromised third-party vendor injected malicious code into Polymarket&apos;s site and stole nearly $3 million from users. The backend was never breached.</description><pubDate>Sat, 27 Jun 2026 13:05:27 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>What is MITRE ATT&amp;CK? Tactics, techniques, and how defenders actually use it</title><link>https://suriq.io/blog/what-is-mitre-attack/</link><guid isPermaLink="true">https://suriq.io/blog/what-is-mitre-attack/</guid><description>A plain-English guide to MITRE ATT&amp;CK: what it is, how its tactics and techniques are organized, a real intrusion mapped step by step, and how defenders use it.</description><pubDate>Sat, 27 Jun 2026 11:52:08 GMT</pubDate><category>Explainers</category><author>Suriq&apos;s Jack</author></item><item><title>What is a SIEM, in plain terms (and how it differs from a SOC and EDR)</title><link>https://suriq.io/blog/what-is-a-siem/</link><guid isPermaLink="true">https://suriq.io/blog/what-is-a-siem/</guid><description>What a SIEM is, what it actually does, and how it differs from a SOC, an EDR, and plain log management - explained by a team that runs one.</description><pubDate>Sat, 27 Jun 2026 11:51:04 GMT</pubDate><category>Explainers</category><author>Noam Alum</author></item><item><title>Open the wrong repo and Amazon Q ran its config file as you, AWS keys included</title><link>https://suriq.io/blog/amazon-q-mcp-config-repo-rce/</link><guid isPermaLink="true">https://suriq.io/blog/amazon-q-mcp-config-repo-rce/</guid><description>Amazon Q Developer ran a repo&apos;s MCP config file as you, with AWS keys attached. CVE-2026-12957 is patched in 1.69.0. What to verify and hunt for now.</description><pubDate>Sat, 27 Jun 2026 08:15:12 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>The dangerous vulnerabilities this week were already old.</title><link>https://suriq.io/blog/signal-old-bug-classes-still-dominate/</link><guid isPermaLink="true">https://suriq.io/blog/signal-old-bug-classes-still-dominate/</guid><description>The vulnerability classes that actually shipped this week are the same five from 2010, even in new AI tooling. The pattern, and what to do.</description><pubDate>Sat, 27 Jun 2026 06:37:44 GMT</pubDate><category>Deep dive</category><author>Suriq&apos;s Jack</author></item><item><title>A widely used PHP tool for making PDFs can hand attackers your internal files and cloud keys</title><link>https://suriq.io/blog/php-weasyprint-ssrf-file-disclosure/</link><guid isPermaLink="true">https://suriq.io/blog/php-weasyprint-ssrf-file-disclosure/</guid><description>php-weasyprint&apos;s attachment option fetched attacker-controlled URLs server-side, reaching internal services, cloud metadata, and local files.</description><pubDate>Fri, 26 Jun 2026 22:26:30 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Russia&apos;s Turla built a new backdoor for one reason: deleting one tool will not evict them</title><link>https://suriq.io/blog/turla-stockstay-backdoor-redundancy/</link><guid isPermaLink="true">https://suriq.io/blog/turla-stockstay-backdoor-redundancy/</guid><description>Google tied Russia&apos;s Turla to STOCKSTAY, a new .NET backdoor built as four swappable parts. Why deleting one piece does not evict the group, and what to hunt.</description><pubDate>Fri, 26 Jun 2026 18:30:42 GMT</pubDate><category>Security news</category><category>Deep dive</category><author>Suriq&apos;s Jack</author></item><item><title>Windchill holds your product blueprints. A web shell on its login page hands them over.</title><link>https://suriq.io/blog/ptc-windchill-cve-2026-12569-exploited/</link><guid isPermaLink="true">https://suriq.io/blog/ptc-windchill-cve-2026-12569-exploited/</guid><description>CISA added PTC Windchill RCE CVE-2026-12569 to its KEV catalog after web shells hit exposed PLM servers. Patch to 11.0 M030 before the June 28 deadline.</description><pubDate>Fri, 26 Jun 2026 16:46:02 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Mistic backdoor writes nothing to disk and quietly sells your network to ransomware crews</title><link>https://suriq.io/blog/mistic-backdoor-access-broker-ransomware-setup/</link><guid isPermaLink="true">https://suriq.io/blog/mistic-backdoor-access-broker-ransomware-setup/</guid><description>Mistic is an in-memory backdoor that access broker KongTuke uses to hold footholds and sell them to Qilin and other ransomware crews. Here is where to catch it.</description><pubDate>Fri, 26 Jun 2026 11:45:34 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>One setting in Red Hat OpenShift Virtualization can expose your VMs to any pod on the cluster</title><link>https://suriq.io/blog/openshift-virtualization-disabletls-vm-exposure/</link><guid isPermaLink="true">https://suriq.io/blog/openshift-virtualization-disabletls-vm-exposure/</guid><description>CVE-2026-13325: enabling disableTLS for faster live migration in Red Hat OpenShift Virtualization drops authentication, letting any pod reach another tenant’s</description><pubDate>Fri, 26 Jun 2026 11:12:22 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>GitLab patched a no-login flaw that can hijack a user&apos;s session. Self-hosted servers are the exposed ones.</title><link>https://suriq.io/blog/gitlab-no-login-session-hijack-patch/</link><guid isPermaLink="true">https://suriq.io/blog/gitlab-no-login-session-hijack-patch/</guid><description>GitLab&apos;s June 24 release fixes 14 flaws, including an unauthenticated cross-site scripting bug.</description><pubDate>Thu, 25 Jun 2026 05:23:36 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A free GitHub account can push code as a trusted maintainer. Upgrading actions/checkout won&apos;t fix it.</title><link>https://suriq.io/blog/cordyceps-github-actions-pull-request-takeover/</link><guid isPermaLink="true">https://suriq.io/blog/cordyceps-github-actions-pull-request-takeover/</guid><description>Cordyceps lets anyone with a free GitHub account run code as a maintainer on 300+ repos. Why upgrading actions/checkout closes one door, not the others.</description><pubDate>Thu, 25 Jun 2026 04:06:39 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Two flaws in Unraid&apos;s control panel let a logged-in user seize the whole server</title><link>https://suriq.io/blog/unraid-web-panel-command-injection-rce/</link><guid isPermaLink="true">https://suriq.io/blog/unraid-web-panel-command-injection-rce/</guid><description>Two command injection flaws in Unraid&apos;s web panel, CVE-2026-9772 and CVE-2026-9773, let any logged-in user run code as www-data.</description><pubDate>Thu, 25 Jun 2026 02:23:59 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A rigged container image can seize root on the host running Docker&apos;s AI agent tools</title><link>https://suriq.io/blog/docker-mcp-gateway-malicious-image-root-escape/</link><guid isPermaLink="true">https://suriq.io/blog/docker-mcp-gateway-malicious-image-root-escape/</guid><description>CVE-2026-55887 lets a malicious container image escape Docker&apos;s MCP Gateway and run code as root on the host. Rated 8.7.</description><pubDate>Thu, 25 Jun 2026 01:37:36 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A new flaw lets attackers take over Quest NetVault backup servers, login or not</title><link>https://suriq.io/blog/quest-netvault-backup-rce-cve-2026-7570/</link><guid isPermaLink="true">https://suriq.io/blog/quest-netvault-backup-rce-cve-2026-7570/</guid><description>CVE-2026-7570 is a SQL-injection-to-remote-code-execution flaw in Quest NetVault Backup, rated 8.8. The login can be bypassed. Quest fixed it in 14.0.2.</description><pubDate>Wed, 24 Jun 2026 23:52:11 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Police seized the malware that stole 27 million passwords. The passwords still work.</title><link>https://suriq.io/blog/stealc-amadey-takedown-stolen-credentials/</link><guid isPermaLink="true">https://suriq.io/blog/stealc-amadey-takedown-stolen-credentials/</guid><description>Operation Endgame seized the servers behind the Amadey and StealC malware, but the 27 million credentials they already stole stay valid until you rotate them.</description><pubDate>Wed, 24 Jun 2026 19:26:41 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>The free plugin was clean. The paid update is what backdoored these WordPress sites.</title><link>https://suriq.io/blog/shapedplugin-wordpress-update-backdoor/</link><guid isPermaLink="true">https://suriq.io/blog/shapedplugin-wordpress-update-backdoor/</guid><description>Backdoored ShapedPlugin Pro updates stole admin logins and 2FA seeds from WordPress sites between April and June 2026. A password reset alone will not clear it.</description><pubDate>Wed, 24 Jun 2026 11:32:55 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>On 200,000 WordPress sites, a low-level user can quietly steal the admin&apos;s login</title><link>https://suriq.io/blog/ultimate-member-contributor-account-takeover/</link><guid isPermaLink="true">https://suriq.io/blog/ultimate-member-contributor-account-takeover/</guid><description>A contributor-level user can make Ultimate Member leak every user&apos;s password reset link, admins included. Affects versions through 2.11.4; fixed in 2.12.0.</description><pubDate>Wed, 24 Jun 2026 08:27:39 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Cisco Unified CM&apos;s flaw is being exploited. Whether it touches you depends on one default setting.</title><link>https://suriq.io/blog/cisco-unified-cm-cve-2026-20230-exploited/</link><guid isPermaLink="true">https://suriq.io/blog/cisco-unified-cm-cve-2026-20230-exploited/</guid><description>CVE-2026-20230 in Cisco Unified CM can reach root, but only where WebDialer is enabled, and it ships off. Check that before you panic-patch.</description><pubDate>Wed, 24 Jun 2026 08:10:45 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A guest virtual machine can read its host&apos;s memory through a flaw in QEMU&apos;s built-in networking</title><link>https://suriq.io/blog/qemu-libslirp-guest-reads-host-memory/</link><guid isPermaLink="true">https://suriq.io/blog/qemu-libslirp-guest-reads-host-memory/</guid><description>A patched flaw in libslirp, QEMU&apos;s usermode networking, lets a privileged guest virtual machine read gigabytes of host memory. Update to libslirp 4.9.2 now.</description><pubDate>Wed, 24 Jun 2026 06:22:16 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Mistype the password and this Lantronix box runs attacker commands as root. CISA says it is happening now.</title><link>https://suriq.io/blog/lantronix-eds5000-serial-server-root-exploited/</link><guid isPermaLink="true">https://suriq.io/blog/lantronix-eds5000-serial-server-root-exploited/</guid><description>CISA flagged CVE-2025-67038 as exploited on June 23. A failed login on a Lantronix EDS5000 serial server runs attacker commands as root.</description><pubDate>Wed, 24 Jun 2026 05:06:09 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Crawl4AI shipped its server unlocked by default. It took three patches to close the door.</title><link>https://suriq.io/blog/crawl4ai-docker-unauthenticated-rce/</link><guid isPermaLink="true">https://suriq.io/blog/crawl4ai-docker-unauthenticated-rce/</guid><description>Crawl4AI&apos;s Docker API shipped unauthenticated by default, exposing 51,000+ deployments to remote code execution and cloud-metadata SSRF. Upgrade to 0.9.0 now.</description><pubDate>Wed, 24 Jun 2026 04:11:43 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Add-ons for the OpenClaw AI assistant are stealing logins and running crypto scams</title><link>https://suriq.io/blog/openclaw-clawhub-malicious-skills/</link><guid isPermaLink="true">https://suriq.io/blog/openclaw-clawhub-malicious-skills/</guid><description>Malicious OpenClaw skills on the ClawHub marketplace steal credentials and hijack AI agents for crypto fraud, and some slip past the store&apos;s own scanner.</description><pubDate>Tue, 23 Jun 2026 22:25:33 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A new Mac backdoor is built to fool the AI that inspects it</title><link>https://suriq.io/blog/macos-gaslight-prompt-injection-analyst/</link><guid isPermaLink="true">https://suriq.io/blog/macos-gaslight-prompt-injection-analyst/</guid><description>macOS.Gaslight embeds fake AI system messages to make automated, LLM-assisted malware analysis abort.</description><pubDate>Tue, 23 Jun 2026 22:09:38 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Java&apos;s most-used JSON library has a guardrail attackers can slip dangerous objects past</title><link>https://suriq.io/blog/jackson-databind-array-allowlist-bypass/</link><guid isPermaLink="true">https://suriq.io/blog/jackson-databind-array-allowlist-bypass/</guid><description>CVE-2026-54513 lets attackers bypass jackson-databind&apos;s polymorphic type validator by wrapping a banned class in an array. Patch to 2.18.8, 2.21.4 or 3.1.4.</description><pubDate>Tue, 23 Jun 2026 21:56:06 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Attackers can take over your self-hosted UniFi controller with no password. CISA says it is happening now.</title><link>https://suriq.io/blog/unifi-os-server-unauth-root-exploited/</link><guid isPermaLink="true">https://suriq.io/blog/unifi-os-server-unauth-root-exploited/</guid><description>Three chained UniFi OS Server flaws give unauthenticated root. CISA added all three to its exploited list on June 23. Patch to 5.0.8 and check who can reach it.</description><pubDate>Tue, 23 Jun 2026 19:50:29 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>PixelSmash: a video your server opens by itself can run an attacker&apos;s code</title><link>https://suriq.io/blog/pixelsmash-ffmpeg-media-pipeline-rce/</link><guid isPermaLink="true">https://suriq.io/blog/pixelsmash-ffmpeg-media-pipeline-rce/</guid><description>PixelSmash (CVE-2026-8461) lets a crafted video run code on FFmpeg-based media servers like Jellyfin and Nextcloud. Update to FFmpeg 8.1.2, then hunt.</description><pubDate>Tue, 23 Jun 2026 12:23:58 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A WhatsApp invoice is installing real IT software to hijack PCs, and your antivirus waves it through</title><link>https://suriq.io/blog/whatsapp-invoice-manageengine-rmm-backdoor/</link><guid isPermaLink="true">https://suriq.io/blog/whatsapp-invoice-manageengine-rmm-backdoor/</guid><description>A fake invoice on WhatsApp silently installs ManageEngine Endpoint Central, a legitimate remote-management tool, to hijack PCs.</description><pubDate>Tue, 23 Jun 2026 03:59:42 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Your self-hosted Gogs server lets any logged-in user read repos that aren&apos;t theirs</title><link>https://suriq.io/blog/gogs-mirror-settings-local-repo-access/</link><guid isPermaLink="true">https://suriq.io/blog/gogs-mirror-settings-local-repo-access/</guid><description>A validation gap in Gogs Mirror Settings (CVE-2026-52801) lets any authenticated user import local repositories and reach internal systems. Patch to 0.14.3 now.</description><pubDate>Tue, 23 Jun 2026 03:08:31 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>One rigged account-sync update can poison your whole app and forge an admin</title><link>https://suriq.io/blog/scim-patch-prototype-pollution-account-sync/</link><guid isPermaLink="true">https://suriq.io/blog/scim-patch-prototype-pollution-account-sync/</guid><description>CVE-2026-48170 lets one SCIM PATCH request poison Object.prototype across a Node.js app using scim-patch, risking admin forgery. Update to 0.9.1 now.</description><pubDate>Tue, 23 Jun 2026 01:41:05 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A single Budibase app builder can read your server&apos;s secrets and take over every workspace</title><link>https://suriq.io/blog/budibase-pwa-zip-symlink-file-read/</link><guid isPermaLink="true">https://suriq.io/blog/budibase-pwa-zip-symlink-file-read/</guid><description>CVE-2026-54352 lets a Budibase workspace builder read the server&apos;s secret file via a crafted PWA zip and take over every workspace. Patch self-hosted to 3.39.9.</description><pubDate>Tue, 23 Jun 2026 00:10:44 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Washington export-controlled an AI for finding bugs. Your oldest code is the soft target.</title><link>https://suriq.io/blog/ai-export-control-patch-window/</link><guid isPermaLink="true">https://suriq.io/blog/ai-export-control-patch-window/</guid><description>The US used export-control powers to pull a frontier AI model that finds software bugs at scale.</description><pubDate>Mon, 22 Jun 2026 19:07:48 GMT</pubDate><category>Security news</category><category>Thought leadership</category><author>Noam Alum</author></item><item><title>Older iPhones just got a flaw Apple can&apos;t patch, and a cable is all it takes</title><link>https://suriq.io/blog/usbliter8-apple-bootrom-unpatchable-exploit/</link><guid isPermaLink="true">https://suriq.io/blog/usbliter8-apple-bootrom-unpatchable-exploit/</guid><description>usbliter8 is an unpatchable boot-chain exploit for Apple A12 and A13 devices. Here is the real enterprise risk, why remote wipe will not help, and what to do.</description><pubDate>Mon, 22 Jun 2026 15:31:48 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>PaperCut&apos;s Windows print client can be tricked into giving a local attacker total control</title><link>https://suriq.io/blog/papercut-print-deploy-local-takeover/</link><guid isPermaLink="true">https://suriq.io/blog/papercut-print-deploy-local-takeover/</guid><description>CVE-2026-6645 lets a local attacker plant a file that PaperCut&apos;s Print Deploy client runs with full system rights on Windows. Update to version 1.10.4178.</description><pubDate>Mon, 22 Jun 2026 04:25:17 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Run Central Dogma across servers? It may be guarding your config with a password printed in its source code</title><link>https://suriq.io/blog/central-dogma-default-secret-cluster-takeover/</link><guid isPermaLink="true">https://suriq.io/blog/central-dogma-default-secret-cluster-takeover/</guid><description>Central Dogma before 0.84.0 silently uses a public default secret when ZooKeeper replication runs without one set, letting nearby attackers seize the cluster.</description><pubDate>Mon, 22 Jun 2026 03:10:10 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Your Squid proxy can leak other users&apos; passwords, and the 7.6 update won&apos;t fix it</title><link>https://suriq.io/blog/squidbleed-squid-proxy-credential-leak/</link><guid isPermaLink="true">https://suriq.io/blog/squidbleed-squid-proxy-credential-leak/</guid><description>Squidbleed (CVE-2026-47729) leaks memory from Squid proxies in default config, including login credentials. A public exploit is out, and 7.6 does not patch it.</description><pubDate>Mon, 22 Jun 2026 00:08:18 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>That decade-old router you forgot is now scanning networks for attackers</title><link>https://suriq.io/blog/arystinger-router-botnet-recon-scanning/</link><guid isPermaLink="true">https://suriq.io/blog/arystinger-router-botnet-recon-scanning/</guid><description>A botnet called AryStinger hijacked over 4,300 end-of-life D-Link and Linksys routers into a distributed scanning grid for reconnaissance, not DDoS. What to do.</description><pubDate>Sun, 21 Jun 2026 18:35:49 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Millions of hacked TV boxes now rent attackers a trusted home IP. Your blocklist can&apos;t see it.</title><link>https://suriq.io/blog/popa-residential-proxy-ip-reputation-account-takeover/</link><guid isPermaLink="true">https://suriq.io/blog/popa-residential-proxy-ip-reputation-account-takeover/</guid><description>Researchers linked the Popa botnet of 2 million hacked TV boxes to a residential proxy service. Here is why IP reputation no longer stops account takeovers.</description><pubDate>Sun, 21 Jun 2026 16:52:26 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Prinz Eugen ransomware hits your newest files first and never leaves a note</title><link>https://suriq.io/blog/prinz-eugen-ransomware-no-ransom-note/</link><guid isPermaLink="true">https://suriq.io/blog/prinz-eugen-ransomware-no-ransom-note/</guid><description>Prinz Eugen ransomware encrypts your most recently changed files first and drops no ransom note, defeating canary traps and note-based SOC alerts. What to do.</description><pubDate>Sun, 21 Jun 2026 11:51:28 GMT</pubDate><category>Security news</category><category>Deep dive</category><author>Noam Alum</author></item><item><title>EaseUS Partition Master left a Windows driver that lets any user seize the whole PC</title><link>https://suriq.io/blog/easeus-partition-master-driver-escalation/</link><guid isPermaLink="true">https://suriq.io/blog/easeus-partition-master-driver-escalation/</guid><description>A signed driver in EaseUS Partition Master (CVE-2026-12781) lets any standard Windows user read and overwrite the whole disk to reach SYSTEM.</description><pubDate>Sun, 21 Jun 2026 09:55:36 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Your AI agent trusts your own computer. One web page turns that into a takeover.</title><link>https://suriq.io/blog/autojack-ai-agent-localhost-rce/</link><guid isPermaLink="true">https://suriq.io/blog/autojack-ai-agent-localhost-rce/</guid><description>Microsoft&apos;s AutoJack shows how one web page an AI browsing agent visits can run code on the host. The bug is a near miss. The architecture lesson is not.</description><pubDate>Sun, 21 Jun 2026 07:46:22 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>This login library let a stranger sign in as you with just your email</title><link>https://suriq.io/blog/ash-authentication-email-account-takeover/</link><guid isPermaLink="true">https://suriq.io/blog/ash-authentication-email-account-takeover/</guid><description>CVE-2026-49757 (CVSS 9.2) let attackers take over accounts in Elixir apps built on ash_authentication by matching users on email instead of identity.</description><pubDate>Sun, 21 Jun 2026 07:24:16 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Your Fortinet password reset won&apos;t lock the FortiBleed attacker out</title><link>https://suriq.io/blog/fortibleed-cisa-alert-session-reset/</link><guid isPermaLink="true">https://suriq.io/blog/fortibleed-cisa-alert-session-reset/</guid><description>CISA warned Fortinet users on June 18; reporting counted 86,644 affected devices. Resetting passwords is not enough: kill live sessions and fix the hashing.</description><pubDate>Sun, 21 Jun 2026 03:18:09 GMT</pubDate><category>Security news</category><category>Deep dive</category><author>Noam Alum</author></item><item><title>vLLM&apos;s earlier patch only hid this AI-server bug. Re-enable embeddings and you are still exposed</title><link>https://suriq.io/blog/vllm-prompt-embeds-tensor-validation-flaw/</link><guid isPermaLink="true">https://suriq.io/blog/vllm-prompt-embeds-tensor-validation-flaw/</guid><description>CVE-2026-56340 lets a crafted tensor crash vLLM (CVSS 8.8) with a path to memory corruption. It only bites if you re-enabled prompt embeds. Fix is 0.13.0.</description><pubDate>Sun, 21 Jun 2026 02:55:23 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Gravity SMTP&apos;s &apos;medium&apos; bug leaks live email API keys to anyone. Patching alone will not save you.</title><link>https://suriq.io/blog/gravity-smtp-credential-leak-cve-2026-4020/</link><guid isPermaLink="true">https://suriq.io/blog/gravity-smtp-credential-leak-cve-2026-4020/</guid><description>Gravity SMTP&apos;s CVE-2026-4020 hands live Amazon SES, Google, and OAuth keys to unauthenticated visitors on 100,000 WordPress sites.</description><pubDate>Sat, 20 Jun 2026 16:51:58 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Police scrubbed SocGholish from 15,000 WordPress sites. The way in is still wide open.</title><link>https://suriq.io/blog/socgholish-operation-endgame-wordpress-takedown/</link><guid isPermaLink="true">https://suriq.io/blog/socgholish-operation-endgame-wordpress-takedown/</guid><description>Operation Endgame seized 106 SocGholish servers and cleaned 14,971 WordPress sites. The takedown hit an access broker, not the entry vector.</description><pubDate>Sat, 20 Jun 2026 12:19:16 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>One tracing header can make a LangSmith server hand over its files</title><link>https://suriq.io/blog/langsmith-tracing-header-file-read/</link><guid isPermaLink="true">https://suriq.io/blog/langsmith-tracing-header-file-read/</guid><description>LangSmith SDK before 0.8.18 lets a crafted tracing header read arbitrary files off any server running TracingMiddleware. Upgrade now; it is the second such bug.</description><pubDate>Sat, 20 Jun 2026 09:09:23 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A USB worm swaps your crypto address mid-paste, and no breach alarm ever fires</title><link>https://suriq.io/blog/usb-worm-clipper-crypto-clipboard/</link><guid isPermaLink="true">https://suriq.io/blog/usb-worm-clipper-crypto-clipboard/</guid><description>Microsoft found a USB worm that hijacks the clipboard to swap crypto wallet addresses and hides its command channel in Tor. Here is why it beats your controls.</description><pubDate>Sat, 20 Jun 2026 07:43:38 GMT</pubDate><category>Security news</category><category>Deep dive</category><author>Suriq&apos;s Jack</author></item><item><title>The app you&apos;re testing can hijack the AI agent testing it: Appium MCP&apos;s XSS flaw</title><link>https://suriq.io/blog/appium-mcp-locator-xss-agent-hijack/</link><guid isPermaLink="true">https://suriq.io/blog/appium-mcp-locator-xss-agent-hijack/</guid><description>An XSS flaw in Appium&apos;s official MCP server let a hostile test app hijack the AI agent driving it and call its tools. Patch appium-mcp to 1.85.10 now.</description><pubDate>Sat, 20 Jun 2026 07:10:40 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>EDR evasion is now a shipped product. Your agent&apos;s silence is the only alarm left.</title><link>https://suriq.io/blog/gentlemen-edr-killer-byovd-detection/</link><guid isPermaLink="true">https://suriq.io/blog/gentlemen-edr-killer-byovd-detection/</guid><description>The Gentlemen ransomware gang ships a standardized EDR killer to affiliates using BYOVD. Here is why driver-name hunting fails and what to detect instead.</description><pubDate>Sat, 20 Jun 2026 04:42:29 GMT</pubDate><category>Security news</category><category>Deep dive</category><author>Noam Alum</author></item><item><title>Branda fixed this WordPress account takeover in January. It is back, and a public exploit is circulating.</title><link>https://suriq.io/blog/branda-wordpress-account-takeover-cve-2026-11551/</link><guid isPermaLink="true">https://suriq.io/blog/branda-wordpress-account-takeover-cve-2026-11551/</guid><description>CVE-2026-11551 is a CVSS 9.8 unauthenticated account takeover in the Branda WordPress plugin (versions up to 3.4.29). A public exploit is out.</description><pubDate>Sat, 20 Jun 2026 03:56:36 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>A WordPress form plugin lets a stranger delete your site, the moment an admin looks</title><link>https://suriq.io/blog/wordpress-form-entries-file-deletion-rce/</link><guid isPermaLink="true">https://suriq.io/blog/wordpress-form-entries-file-deletion-rce/</guid><description>CVE-2026-9843 lets an unauthenticated visitor plant a form entry that deletes WordPress files when an admin opens it.</description><pubDate>Sat, 20 Jun 2026 02:40:19 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A single rigged document can turn Langflow&apos;s file reader into full server takeover</title><link>https://suriq.io/blog/langflow-rag-file-read-rce/</link><guid isPermaLink="true">https://suriq.io/blog/langflow-rag-file-read-rce/</guid><description>A crafted document in a Langflow RAG pipeline (CVE-2026-55447, CVSS 9.6) reads any file, forges a login token, then runs code. Upgrade to 1.9.2 or later.</description><pubDate>Sat, 20 Jun 2026 01:25:41 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>One Langflow account can now run every other user&apos;s AI workflow</title><link>https://suriq.io/blog/langflow-idor-cross-user-flow-execution/</link><guid isPermaLink="true">https://suriq.io/blog/langflow-idor-cross-user-flow-execution/</guid><description>A critical IDOR in Langflow (CVE-2026-55255, CVSS 9.9) lets any logged-in user run another user&apos;s AI flow. Upgrade to 1.9.1. The real problem is the pattern.</description><pubDate>Fri, 19 Jun 2026 23:53:51 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Mastra&apos;s npm packages passed inspection, then turned hostile a day later</title><link>https://suriq.io/blog/mastra-npm-supply-chain-compromise/</link><guid isPermaLink="true">https://suriq.io/blog/mastra-npm-supply-chain-compromise/</guid><description>Attackers hijacked a dormant maintainer account to poison 140+ Mastra npm packages with a wallet-stealing payload.</description><pubDate>Fri, 19 Jun 2026 22:55:50 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>CoreWCF&apos;s SAML check trusted a forged identity as your admin. There is no workaround, only the patch.</title><link>https://suriq.io/blog/corewcf-saml-signature-bypass/</link><guid isPermaLink="true">https://suriq.io/blog/corewcf-saml-signature-bypass/</guid><description>CVE-2026-54782 lets an attacker forge a SAML token and impersonate anyone, admins included, on CoreWCF federation services. No workaround.</description><pubDate>Fri, 19 Jun 2026 21:55:54 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Quarkus fixed a semicolon auth bypass in May. Its encoded cousin just reopened it.</title><link>https://suriq.io/blog/quarkus-encoded-path-auth-bypass/</link><guid isPermaLink="true">https://suriq.io/blog/quarkus-encoded-path-auth-bypass/</guid><description>Quarkus fixed a semicolon authorization bypass in May, but CVE-2026-50559 reopens it with URL-encoded characters. What to patch now and how to detect abuse.</description><pubDate>Fri, 19 Jun 2026 20:56:09 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>DragonForce hides its C2 inside Microsoft Teams relays. Your network sensors see a clean call.</title><link>https://suriq.io/blog/dragonforce-teams-relay-c2-backdoor-turn/</link><guid isPermaLink="true">https://suriq.io/blog/dragonforce-teams-relay-c2-backdoor-turn/</guid><description>DragonForce&apos;s Backdoor.Turn routes C2 through Microsoft Teams TURN relays, so network sensors see only Microsoft.</description><pubDate>Fri, 19 Jun 2026 19:34:51 GMT</pubDate><category>Security news</category><category>Deep dive</category><author>Suriq&apos;s Jack</author></item><item><title>Your Salesforce wasn&apos;t breached. A connected app handed over the data.</title><link>https://suriq.io/blog/klue-oauth-salesforce-connected-app-breach/</link><guid isPermaLink="true">https://suriq.io/blog/klue-oauth-salesforce-connected-app-breach/</guid><description>The Icarus group stole Salesforce CRM data through Klue&apos;s connected app, not a Salesforce flaw. Why OAuth integration tokens are the unmonitored attack surface.</description><pubDate>Fri, 19 Jun 2026 14:50:51 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Your JetBrains Hub 2FA protected nothing. The recovery codes were predictable.</title><link>https://suriq.io/blog/jetbrains-hub-predictable-recovery-codes/</link><guid isPermaLink="true">https://suriq.io/blog/jetbrains-hub-predictable-recovery-codes/</guid><description>JetBrains Hub generated predictable 2FA recovery codes (CVE-2026-56141, CVSS 9.8), allowing pre-auth account takeover.</description><pubDate>Fri, 19 Jun 2026 13:37:56 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Perry&apos;s stdlib turned off JWT expiry checks. Logout stopped meaning anything.</title><link>https://suriq.io/blog/perry-jwt-expiration-bypass/</link><guid isPermaLink="true">https://suriq.io/blog/perry-jwt-expiration-bypass/</guid><description>CVE-2026-53776: Perry&apos;s bundled JWT helper hard-codes validate_exp = false, so expired and revoked tokens stay valid. Patch to 0.5.1166 and rotate signing keys.</description><pubDate>Fri, 19 Jun 2026 10:59:11 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Your Splunk box runs a database sidecar you never configured. Attackers use it for root.</title><link>https://suriq.io/blog/splunk-postgres-sidecar-preauth-rce/</link><guid isPermaLink="true">https://suriq.io/blog/splunk-postgres-sidecar-preauth-rce/</guid><description>CVE-2026-20253 is an unauthenticated RCE in Splunk Enterprise 10.x via a bundled PostgreSQL sidecar. On CISA KEV, exploited now. Patch to 10.0.7 or 10.2.4.</description><pubDate>Fri, 19 Jun 2026 07:42:37 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>Two NGINX bugs scored 9.2. On a default server you get a crash, not a shell.</title><link>https://suriq.io/blog/nginx-critical-rce-config-triage/</link><guid isPermaLink="true">https://suriq.io/blog/nginx-critical-rce-config-triage/</guid><description>F5&apos;s two critical NGINX flaws (CVE-2026-42530, CVE-2026-42055) score 9.2, but RCE needs ASLR off and a non-default config. Here is what to actually triage.</description><pubDate>Fri, 19 Jun 2026 03:45:04 GMT</pubDate><category>Security news</category><category>Deep dive</category><author>Noam Alum</author></item><item><title>INC ransomware never used a zero-day. It used your patch backlog.</title><link>https://suriq.io/blog/inc-ransomware-patch-backlog-edge-devices/</link><guid isPermaLink="true">https://suriq.io/blog/inc-ransomware-patch-backlog-edge-devices/</guid><description>INC reached top-tier RaaS in 2026 with no zero-days. Every edge-device flaw it exploits was patched months earlier. Here is what to actually fix.</description><pubDate>Thu, 18 Jun 2026 16:56:17 GMT</pubDate><category>Security news</category><author>Suriq&apos;s Jack</author></item><item><title>ClickFix is now shared attack infrastructure, and the lure is the wrong thing to detect</title><link>https://suriq.io/blog/clickfix-shared-delivery-detection/</link><guid isPermaLink="true">https://suriq.io/blog/clickfix-shared-delivery-detection/</guid><description>Three unrelated crews adopted ClickFix delivery in a single quarter. The lure keeps changing; the execution chain does not. Here is where to detect it.</description><pubDate>Thu, 18 Jun 2026 12:10:34 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Cisco called this SD-WAN flaw medium. Attackers used it to take root on your WAN.</title><link>https://suriq.io/blog/cisco-sd-wan-manager-cve-2026-20262/</link><guid isPermaLink="true">https://suriq.io/blog/cisco-sd-wan-manager-cve-2026-20262/</guid><description>CVE-2026-20262 is an actively exploited Cisco SD-WAN Manager flaw that escalates a low-privilege login to root.</description><pubDate>Thu, 18 Jun 2026 08:11:51 GMT</pubDate><category>Security news</category><category>Deep dive</category><author>Suriq&apos;s Jack</author></item><item><title>RoguePlanet turns Microsoft Defender into a SYSTEM shell, and switching it off won&apos;t save you</title><link>https://suriq.io/blog/rogueplanet-defender-system-zero-day/</link><guid isPermaLink="true">https://suriq.io/blog/rogueplanet-defender-system-zero-day/</guid><description>RoguePlanet (CVE-2026-50656) is a public-exploit privilege escalation in Microsoft Defender&apos;s engine.</description><pubDate>Thu, 18 Jun 2026 05:50:21 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>FortiBleed isn&apos;t a Fortinet bug. It&apos;s every password you never rotated.</title><link>https://suriq.io/blog/fortibleed-fortinet-no-cve-to-patch/</link><guid isPermaLink="true">https://suriq.io/blog/fortibleed-fortinet-no-cve-to-patch/</guid><description>FortiBleed exposed working VPN logins for tens of thousands of Fortinet firewalls. There is no CVE to patch; the fix is rotating credentials and enforcing MFA.</description><pubDate>Wed, 17 Jun 2026 19:12:55 GMT</pubDate><category>Security news</category><category>Deep dive</category><author>Suriq&apos;s Jack</author></item><item><title>JetBrains Plugins Are Stealing AI API Keys, and You Find Out From the Bill</title><link>https://suriq.io/blog/jetbrains-plugins-steal-ai-api-keys/</link><guid isPermaLink="true">https://suriq.io/blog/jetbrains-plugins-steal-ai-api-keys/</guid><description>Aikido found 15 JetBrains Marketplace plugins stealing AI API keys across 70,000 installs.</description><pubDate>Wed, 17 Jun 2026 15:04:54 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>FortiSandbox Under Attack: The Box That Catches Malware Is Now the Way In</title><link>https://suriq.io/blog/fortisandbox-flaws-actively-exploited/</link><guid isPermaLink="true">https://suriq.io/blog/fortisandbox-flaws-actively-exploited/</guid><description>Three critical FortiSandbox flaws are under active exploitation, two unauthenticated and one patched a week ago.</description><pubDate>Wed, 17 Jun 2026 11:08:44 GMT</pubDate><category>Security news</category><category>Deep dive</category><author>Suriq&apos;s Jack</author></item><item><title>Three requests, no password, a webshell: the JCE flaw hitting Joomla hosts now</title><link>https://suriq.io/blog/joomla-jce-unauthenticated-rce/</link><guid isPermaLink="true">https://suriq.io/blog/joomla-jce-unauthenticated-rce/</guid><description>Unauthenticated RCE (CVSS 10, CVE-2026-48907) in JCE, the most-installed Joomla editor. KEV-listed and exploited. Patch to 2.9.99.6 and hunt for webshells.</description><pubDate>Wed, 17 Jun 2026 05:20:51 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>A Linux backdoor moved into the Windows kernel, and the detection window closes at driver load</title><link>https://suriq.io/blog/sprysocks-windows-kernel-driver/</link><guid isPermaLink="true">https://suriq.io/blog/sprysocks-windows-kernel-driver/</guid><description>SprySOCKS, a China-nexus Linux backdoor, now ships a Windows kernel-driver variant that hides itself from the host. Here is where defenders can still catch it.</description><pubDate>Tue, 16 Jun 2026 19:40:47 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>LiteSpeed&apos;s cPanel plugin gave shared-hosting tenants root twice in 2026. CageFS didn&apos;t help.</title><link>https://suriq.io/blog/litespeed-cpanel-plugin-root-escalation/</link><guid isPermaLink="true">https://suriq.io/blog/litespeed-cpanel-plugin-root-escalation/</guid><description>CVE-2026-54420 and CVE-2026-48172 let shared-hosting tenants reach root through the LiteSpeed cPanel plugin. Why CageFS isolation failed and what to patch now.</description><pubDate>Tue, 16 Jun 2026 07:13:38 GMT</pubDate><category>Security news</category><category>Deep dive</category><author>Noam Alum</author></item><item><title>Awesome Motive&apos;s WordPress CDN backdoor only fired for logged-in admins. Your scanner missed it.</title><link>https://suriq.io/blog/awesome-motive-wordpress-cdn-backdoor/</link><guid isPermaLink="true">https://suriq.io/blog/awesome-motive-wordpress-cdn-backdoor/</guid><description>OptinMonster, TrustPulse and PushEngage served a backdoor that ran only for logged-in WordPress admins, evading visitor scanners. How to scope and hunt it.</description><pubDate>Mon, 15 Jun 2026 20:32:28 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>SearchLeak in Microsoft 365 Copilot: prompt injection as a new door to old bugs</title><link>https://suriq.io/blog/searchleak-copilot-prompt-injection/</link><guid isPermaLink="true">https://suriq.io/blog/searchleak-copilot-prompt-injection/</guid><description>SearchLeak chained prompt injection, an HTML render race, and Bing SSRF to steal Microsoft 365 Copilot data in one click. What it means for detection.</description><pubDate>Mon, 15 Jun 2026 19:25:51 GMT</pubDate><category>Security news</category><author>Noam Alum</author></item><item><title>Why we built Suriq on Wazuh instead of writing our own detection engine</title><link>https://suriq.io/blog/why-suriq-built-on-wazuh/</link><guid isPermaLink="true">https://suriq.io/blog/why-suriq-built-on-wazuh/</guid><description>Suriq runs on Wazuh because a detection engine is a decade of decoders, CVE feeds, and agents you should never rebuild. Here is the reasoning behind the bet.</description><pubDate>Mon, 15 Jun 2026 07:42:14 GMT</pubDate><category>Thought leadership</category><category>Deep dive</category><author>Suriq&apos;s Jack</author></item><item><title>Ivanti Sentry&apos;s CVE-2026-10520: patch the gateway, then hunt for the breach</title><link>https://suriq.io/blog/ivanti-sentry-patched-still-breached/</link><guid isPermaLink="true">https://suriq.io/blog/ivanti-sentry-patched-still-breached/</guid><description>Ivanti Sentry CVE-2026-10520 is an unauthenticated root RCE under active attack. CISA&apos;s new 3-day patch rule applies; patched gateways were already breached.</description><pubDate>Sun, 14 Jun 2026 07:06:06 GMT</pubDate><category>Security news</category><category>Deep dive</category><author>Suriq&apos;s Jack</author></item><item><title>PeopleSoft&apos;s PSEMHUB zero-day turns the patch service into the breach</title><link>https://suriq.io/blog/peoplesoft-psemhub-zero-day/</link><guid isPermaLink="true">https://suriq.io/blog/peoplesoft-psemhub-zero-day/</guid><description>CVE-2026-35273 sits in PeopleSoft&apos;s Updates Environment Management module. Mandiant ties active exploitation to ShinyHunters, with 100+ orgs already breached.</description><pubDate>Sat, 13 Jun 2026 18:38:12 GMT</pubDate><category>Security news</category><category>Deep dive</category><author>Suriq&apos;s Jack</author></item><item><title>Velvet Ant&apos;s PAM-OpenSSH decade is an auth-stack blind spot, not a Linux bug</title><link>https://suriq.io/blog/velvet-ant-auth-stack-blind-spot/</link><guid isPermaLink="true">https://suriq.io/blog/velvet-ant-auth-stack-blind-spot/</guid><description>Sygnia found nine backdoored pam_unix.so variants and four trojanized OpenSSH binaries on one victim. Why auth-stack integrity is the SIEM-invisible gap.</description><pubDate>Sat, 13 Jun 2026 17:01:32 GMT</pubDate><category>Security news</category><category>Deep dive</category><author>Suriq&apos;s Jack</author></item></channel></rss>