Skip to content
feed: live
>_ 0dayNews
$ latest

Vulnerability & Exploit Coverage

250 articles · sorted newest first

~/articles/2026-07-21-signature-was-there-trust-wasnt-week-retrospective
The signature was there. The trust wasn't.
Analysis
threat intel

The signature was there. The trust wasn't.

DigiCert's EV certs, WebEx and Zoom installers, ViPNet's signed updater. Three subverted trust chains this week, one design assumption behind them.

read →
~/articles/2026-07-21-mythos-three-months-exposure-window-triage-playbook
Mythos at three months: measure exposure, not volume
Analysis
threat intel

Mythos at three months: measure exposure, not volume

Three months after Anthropic's Mythos disclosure, the industry is still arguing about CVE queue depth. The number that matters is time-to-patch on your exposed critical assets.

read →
~/articles/2026-07-21-ai-agent-sandboxes-only-as-tight-as-host-tools
AI-agent sandboxes are only as tight as the host tools
Analysis
threat intel

AI-agent sandboxes are only as tight as the host tools

Pillar walked the same escape out of Cursor, Codex, Gemini CLI, and Antigravity in one week. The pattern isn't new — the trusted host tool is.

read →
~/articles/2026-07-20-ostium-arbitrum-off-chain-oracle-forgery-23-75m-lp-vault-drain
Ostium's LP vault down $23.75M after oracle-feed forgery
threat intel

Ostium's LP vault down $23.75M after oracle-feed forgery

Attackers compromised off-chain price signing for Ostium's Arbitrum perpetuals DEX, submitted forged price attestations, and drained $23.75M from the LP vault.

read →
~/articles/2026-07-21-estee-lauder-cl0p-oracle-ebs-cve-2025-61882-bi-publisher-11-month-dwell
Estée Lauder confirms Cl0p Oracle EBS breach, 11mo dwell
● Breaking
oracle

Estée Lauder confirms Cl0p Oracle EBS breach, 11mo dwell

Estée Lauder's July 20 letter says Cl0p breached its Oracle E-Business Suite HR system on August 9, 2025 via CVE-2025-61882. Dwell: 11 months.

read →
~/articles/2026-07-20-jadepuffer-encforge-ai-asset-ransomware-model-weights-vector-dbs
Sysdig: JADEPUFFER now ships EncForge, targets model weights
● Breaking
ransomware

Sysdig: JADEPUFFER now ships EncForge, targets model weights

Sysdig's Threat Research Team says the agentic operator it named JADEPUFFER has upgraded from generic database encryption to a custom Go ransomware, EncForge, that specifically targets AI model checkpoints, vector databases, and training data.

read →
~/articles/2026-07-20-pillar-week-sandbox-escapes-cursor-codex-gemini-cli-antigravity
Cursor, Codex, Gemini CLI, Antigravity: sandbox escapes
threat intel

Cursor, Codex, Gemini CLI, Antigravity: sandbox escapes

Pillar Security walks the same file out of the sandbox in four AI coding agents — each time by getting a trusted host tool to run what the agent wrote.

read →
~/articles/2026-07-20-island-fakegit-7600-github-mcp-smartloader-agentbaiting
FakeGit: 7,600 GitHub repos push SmartLoader via MCP lure
● Breaking
supply chain

FakeGit: 7,600 GitHub repos push SmartLoader via MCP lure

Island's Oleg Zaytsev catalogs 7,600 malicious GitHub repos posing as AI/MCP tooling, delivering SmartLoader via LuaJIT to StealC. 14M+ downloads observed.

read →
~/articles/2026-07-20-group-ib-hollowgraph-m365-calendar-events-2050-c2-dead-drop
HollowGraph hides M365 C2 in calendar events dated 2050
threat intel

HollowGraph hides M365 C2 in calendar events dated 2050

Group-IB's HollowGraph hides M365 command-and-control in calendar events dated 2050-05-13, moving tasking and stolen files through legitimate Graph API traffic.

read →
~/articles/2026-07-20-rapid7-exposed-webdav-lab-1048-artifacts-mexico-curp-victims
Exposed WebDAV lab: 1,048 artifacts, real Mexico victims
● Breaking
threat intel

Exposed WebDAV lab: 1,048 artifacts, real Mexico victims

Rapid7 found an exposed WebDAV server with 1,048 attacker artifacts — QA'd lures, three tested CVEs, and 2,384 confirmed launch hits against Mexican targets.

read →
~/articles/2026-07-20-aivd-mivd-russian-intel-ip-cameras-nato-military-transport-ukraine
AIVD/MIVD: Russia hijacks IP cameras on NATO convoy routes
ics ot

AIVD/MIVD: Russia hijacks IP cameras on NATO convoy routes

AIVD and MIVD say Russian intel is hijacking exposed IP cameras across EU, NATO states, and Ukraine to watch military convoys and weapons shipments to Kyiv.

read →
~/articles/2026-07-20-wsus-sync-fix-new-installs-only-old-servers-metadata-cleanup
WSUS sync fix only for new installs, old servers still stuck
microsoft

WSUS sync fix only for new installs, old servers still stuck

WSUS servers on Windows Server 2012+ have failed to sync since roughly July 13. Microsoft's July 18 mitigation restores fresh installs; older ones wait on a metadata cleanup step.

read →
~/articles/2026-07-20-trend-micro-bandcampro-gemini-cli-c2-dental-clinic-eight-node-botnet
Trend Micro: 'bandcampro' ran botnet ops through Gemini CLI
● Breaking
threat intel

Trend Micro: 'bandcampro' ran botnet ops through Gemini CLI

Trend Micro forensicated 200 Google Gemini CLI sessions used by a lone Russian-speaking actor to run an eight-node dental-clinic botnet through natural-language prompts.

read →
~/articles/2026-07-20-microsoft-kb5121767-oob-dell-intel-ipf-driver-hold-fix
Microsoft ships KB5121767 OOB for Dell IPF driver hold
microsoft

Microsoft ships KB5121767 OOB for Dell IPF driver hold

Microsoft shipped KB5121767 on 2026-07-20 to patch the Intel IPF driver incompatibility stranding a subset of Dell PCs off July's Windows 11 security update.

read →
~/articles/2026-07-20-servicenow-ai-platform-cve-2026-6875-defused-exploitation
ServiceNow AI Platform RCE exploited in wild: CVE-2026-6875
● Breaking
servicenow

ServiceNow AI Platform RCE exploited in wild: CVE-2026-6875

Threat-intel firm Defused reports active exploitation of ServiceNow AI Platform CVE-2026-6875, a week after ServiceNow said it saw none.

read →
~/articles/2026-07-20-hugging-face-autonomous-ai-agent-breach-internal-datasets
Hugging Face confirms breach by autonomous AI agent
● Breaking
threat intel

Hugging Face confirms breach by autonomous AI agent

Hugging Face disclosed unauthorized access to internal datasets and service credentials by an autonomous agent framework that ran thousands of sandboxed actions across a weekend.

read →
~/articles/2026-07-20-stepsecurity-sleepergem-rubygems-dormant-accounts-forgejo-loader
SleeperGem loader hides in dormant RubyGems, skips CI/CD
supply chain

SleeperGem loader hides in dormant RubyGems, skips CI/CD

StepSecurity: three RubyGems, two dormant since 2018-2020, ship a Forgejo-hosted loader that fingerprints CI runners and skips them before dropping a daemon.

read →
~/articles/2026-07-20-wp2shell-first-exploitation-cve-2026-60137-sqli-companion-patched
wp2shell: first signs of exploitation; CVE-2026-60137 lands
● Breaking
wordpress

wp2shell: first signs of exploitation; CVE-2026-60137 lands

watchTowr reports first signs of in-the-wild exploitation of the WordPress Core wp2shell RCE. The pending companion CVE-2026-60137 SQLi has landed, and exact patched versions are 6.9.5 and 7.0.2.

read →
~/articles/2026-07-19-nginx-cve-2026-42533-map-regex-heap-overflow-worker-patch
nginx patches heap overflow in worker (CVE-2026-42533)
threat intel

nginx patches heap overflow in worker (CVE-2026-42533)

F5 shipped nginx 1.30.4/1.31.3 and NGINX Plus 37.0.3.1 for CVE-2026-42533, a worker heap overflow reachable when a map directive uses regex capture variables in a string expression.

read →
~/articles/2026-07-19-cert-ua-uac-0145-sandworm-clickfix-ukraine
CERT-UA: UAC-0145 (Sandworm) runs ClickFix on Ukraine
threat intel

CERT-UA: UAC-0145 (Sandworm) runs ClickFix on Ukraine

CERT-UA alert 6318437 attributes a June–July ClickFix campaign hitting at least 10 compromised Ukrainian sites to UAC-0145, a Sandworm sub-cluster tied to GRU.

read →
~/articles/2026-07-19-kaspersky-hellonet-vipnet-updater-dll-sideload-russian-orgs
Kaspersky details HelloNet abuse of ViPNet updater
Analysis
threat intel

Kaspersky details HelloNet abuse of ViPNet updater

Kaspersky says an unknown APT — low-confidence Chinese ties — has abused the InfoTeCS ViPNet update client to plant Russian orgs since May.

read →
~/articles/2026-07-19-volexity-uta0533-sma1000-rootrun-knuckleball-orangetail
SonicWall SMA1000: Volexity names UTA0533, IoC list out
● Breaking
sonicwall

SonicWall SMA1000: Volexity names UTA0533, IoC list out

Volexity attributes the SMA1000 pre-disclosure exploitation to a new actor, UTA0533, active since June 22 — and publishes the toolkit for defenders to hunt.

read →
~/articles/2026-07-19-legacyhive-nightmare-eclipse-windows-user-profile-usrclass-lpe-unpatched
LegacyHive: PoC drops for unpatched Windows LPE zero-day
microsoft

LegacyHive: PoC drops for unpatched Windows LPE zero-day

A researcher publishing as "Nightmare Eclipse" dropped a PoC for LegacyHive — an unpatched local privilege escalation in Windows' User Profile Service.

read →
~/articles/2026-07-19-metasploit-weekly-http-smb-relay-riscv-fetch-payloads
Metasploit adds HTTP-to-SMB NTLM relay, RISC-V payloads
threat intel

Metasploit adds HTTP-to-SMB NTLM relay, RISC-V payloads

Rapid7's July 17 Metasploit wrap-up ships a Windows HTTP-to-SMB NTLM relay module, RISC-V shell payloads, and 421 new fetch-style variants. Check SMB signing tonight.

read →
~/articles/2026-07-18-microsoft-acr-stealer-april-june-webdav-etherhiding
Microsoft ties ACR Stealer surge to WebDAV, blockchain C2
threat intel

Microsoft ties ACR Stealer surge to WebDAV, blockchain C2

Microsoft's July 16 writeup links a late-April through mid-June ACR Stealer surge to WebDAV-hosted payloads and a blockchain dead-drop for C2 updates.

read →
~/articles/2026-07-18-7-zip-26-02-xz-heap-overflow-rce-zdi-26-444
7-Zip 26.02 patches XZ heap overflow, no auto-update
7 zip

7-Zip 26.02 patches XZ heap overflow, no auto-update

7-Zip 26.02 fixes a heap-based buffer overflow in XZ decompression (ZDI-26-444) — RCE if a user opens a crafted archive, and there is no automatic update.

read →
~/articles/2026-07-18-doj-chen-zhang-queens-brooklyn-43m-investment-fraud-laundering-140-accounts-45-shells
Two indicted over $43M laundered from investment scams
threat intel

Two indicted over $43M laundered from investment scams

DOJ charged two New York-based Chinese nationals with laundering $43M in investment-fraud proceeds through 140 bank accounts and roughly 45 shell companies.

read →
~/articles/2026-07-18-nadmesh-go-botnet-shodan-comfyui-ollama-3811-aws-keys
NadMesh botnet raids exposed AI tools for 3,811 AWS keys
cloud

NadMesh botnet raids exposed AI tools for 3,811 AWS keys

A Go botnet called NadMesh, active since early July, feeds a Shodan queue into ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio. Operator dashboard claims 3,811 AWS keys.

read →
~/articles/2026-07-18-expel-digicert-goldeneyedog-cylindricalcanine-27-ev-code-signing-certs-zhong-stealer
Expel: GoldenEyeDog stole 27 EV certs from DigiCert
supply chain

Expel: GoldenEyeDog stole 27 EV certs from DigiCert

Expel says the April DigiCert breach was CylindricalCanine, a GoldenEyeDog subgroup. Twenty-seven of 60 revoked EV certs signed Zhong Stealer artifacts.

read →
~/articles/2026-07-18-abbott-shinyhunters-vishing-exact-sciences-labcentral-disputed
Abbott confirms Exact Sciences hit; LabCentral disputed
ransomware

Abbott confirms Exact Sciences hit; LabCentral disputed

ShinyHunters used vishing to hit legacy Exact Sciences systems in Abbott's Cancer Diagnostics business; a separate LabCentral extortion claim by ShadowByt3$ is disputed.

read →
~/articles/2026-07-18-checkmarx-vitevenom-chainveil-seven-npm-tron-blockchain-c2
Seven Vite-adjacent npm packages route a RAT through Tron
supply chain

Seven Vite-adjacent npm packages route a RAT through Tron

Checkmarx flagged a fresh cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem. Codenamed ViteVenom, they route through a four-tier blockchain C2 including Tron to drop a RAT.

read →
~/articles/2026-07-18-okta-hollowbyte-openssl-dos-june-silent-fix
HollowByte: 11-byte OpenSSL DoS, no CVE, silent June fix
threat intel

HollowByte: 11-byte OpenSSL DoS, no CVE, silent June fix

Okta's Red Team named 'HollowByte' — an OpenSSL DoS where 11 bytes of TLS pull 131 KB of process memory per shot. OpenSSL patched it in June with no CVE.

read →
~/articles/2026-07-18-wordpress-core-cve-2026-63030-wp2shell-rce-poc-public
WordPress Core RCE (wp2shell): CVE-2026-63030, PoC public
wordpress

WordPress Core RCE (wp2shell): CVE-2026-63030, PoC public

A critical unauthenticated remote code execution flaw in WordPress Core got a CVE, a GitHub advisory, and a working public PoC on July 17, 2026.

read →
~/articles/2026-07-18-choi-lee-seoul-uiuc-adi-agent-data-injection-web-coding-agents
Agent Data Injection: The Bug Under Every AI Agent
Analysis
threat intel

Agent Data Injection: The Bug Under Every AI Agent

Seoul National / UIUC / Largosoft research shows web and coding agents get steered by planted content in the pages, comments, and reviews they consume. Fix the trust boundary, not the model.

read →
~/articles/2026-07-17-ec-google-android-qaap-mic-cam-screen-hotword-rival-ai
EU order opens Android mic, cam, screen to rival AI agents
google

EU order opens Android mic, cam, screen to rival AI agents

EC ordered Google to open Android's mic, camera, screen, and always-on hotword to rival AI assistants — mandatory in Android 18 by 1 August 2027.

read →
~/articles/2026-07-17-flare-2889-underground-posts-clean-residential-proxies-post-netnut
Flare finds carders still hunting clean IPs post-NetNut
Analysis
threat intel

Flare finds carders still hunting clean IPs post-NetNut

Flare's read of 2,889 underground posts finds carders scrambling for 'clean' residential IPs two weeks after the FBI's NetNut seizure disrupted supply.

read →
~/articles/2026-07-17-ernst-young-third-party-support-ticket-breach-mar-apr-window
EY discloses breach via third-party IT ticket system
threat intel

EY discloses breach via third-party IT ticket system

Ernst & Young says an unauthorized party accessed a third-party support ticket platform used by its IT staff between March 28 and April 12. Detection followed on April 23; disclosure landed July 17.

read →
~/articles/2026-07-17-armenia-detains-ermakov-yerevan-revil-warrant-identity-dispute
Armenia detains Aleksandr Ermakov on US REvil warrant
threat intel

Armenia detains Aleksandr Ermakov on US REvil warrant

Russian tourist Aleksandr Ermakov has been held in Yerevan since 2026-06-28 on a US extradition request for a REvil suspect of the same name. His lawyer says the paperwork carries no patronymic.

read →
~/articles/2026-07-17-elastic-ottercookie-svg-flag-steganography-ai-tool-configs
OtterCookie's fake interview now steals AI-tool configs
Analysis
threat intel

OtterCookie's fake interview now steals AI-tool configs

Elastic Security Labs catches the DPRK's Contagious Interview crew hiding a four-stage payload in SVG country flag files — and the new file stealer specifically hunts .claude, .cursor, .gemini, and .windsurf configs.

read →
~/articles/2026-07-17-kaspersky-goserpent-go-rat-tetrisphantom-overlap-apac-diplomatic
GoSerpent: Go RAT hits APAC gov, TetrisPhantom overlap
threat intel

GoSerpent: Go RAT hits APAC gov, TetrisPhantom overlap

Kaspersky documents GoSerpent, a Go-based RAT hitting Southeast Asian government and diplomatic entities since late 2025. Operational overlap with TetrisPhantom.

read →
~/articles/2026-07-17-nightmare-eclipse-legacyhive-windows-user-profile-service-lpe-zero-day
LegacyHive: unpatched Windows LPE zero-day, PoC public
microsoft

LegacyHive: unpatched Windows LPE zero-day, PoC public

Researcher Nightmare Eclipse dropped LegacyHive — an unpatched Windows User Profile Service LPE — hours after July Patch Tuesday. No CVE, PoC on GitHub.

read →
~/articles/2026-07-17-microsoft-defender-experts-acr-stealer-clickfix-run-box-paste-and-run
ACR Stealer, ClickFix, and why the Run box still works
Analysis
threat intel

ACR Stealer, ClickFix, and why the Run box still works

Microsoft's Defender Experts detailed two ACR Stealer chains Thursday. Both start with a Run-dialog paste — and walk out with browser tokens and M365 files.

read →
~/articles/2026-07-17-microsoft-windows-server-2022-mainstream-eos-october-13-extended-2031
Windows Server 2022 mainstream support ends Oct 13
microsoft

Windows Server 2022 mainstream support ends Oct 13

Microsoft's Windows Server 2022 leaves mainstream support October 13, 2026 — but extended support runs five more years with security updates at no extra cost.

read →
~/articles/2026-07-17-doj-chen-zhang-43m-money-laundering-140-accounts-45-shells
The plumbing behind $43M in investment-fraud losses
Analysis
threat intel

The plumbing behind $43M in investment-fraud losses

DOJ charges two in a New York-based network that laundered at least $43 million from pig-butchering-style investment scams through ~140 accounts.

read →
~/articles/2026-07-16-microsoft-windows-11-24h2-home-pro-eos-october-13-25h2-enablement
Windows 11 24H2 Home and Pro: 90 days to end of updates
microsoft

Windows 11 24H2 Home and Pro: 90 days to end of updates

Microsoft has set October 13, 2026 as the last patch day for Windows 11 24H2 Home and Pro. Enterprise and Education get one more year — the usual split.

read →
~/articles/2026-07-17-n8n-cve-2026-59208-cross-issuer-token-exchange-sub-iss
n8n cross-issuer JWT bypass logs attackers in as anyone
n8n

n8n cross-issuer JWT bypass logs attackers in as anyone

CVE-2026-59208: n8n Enterprise instances trusting two or more JWT issuers matched incoming tokens on `sub` alone, letting a token from issuer A log in as B's user.

read →
~/articles/2026-07-16-talos-uat-11795-starland-rat-wldr-c2-trojanized-installers
UAT-11795 hides Starland RAT in trojanized installers
threat intel

UAT-11795 hides Starland RAT in trojanized installers

Cisco Talos names UAT-11795 — a financially motivated Russian actor pushing Starland RAT and bespoke WLDR C2 via trojanized WebEx, Zoom, MobaXterm installers.

read →
~/articles/2026-07-16-sans-stephen-sims-bugcrowd-ai-triage-proof-standard
AI can find the bug. Proving it is still the job.
Analysis
threat intel

AI can find the bug. Proving it is still the job.

SANS Fellow Stephen Sims argues the noise-to-signal ratio in bug bounty has shifted, but the proof-of-exploit standard hasn't — Bugcrowd's own policy shift agrees.

read →
~/articles/2026-07-16-elastic-telepuz-clickfix-maas-vidar-stage-two
Elastic: TELEPUZ ClickFix stealer confirmed since April
threat intel

Elastic: TELEPUZ ClickFix stealer confirmed since April

Elastic Security Labs pins TELEPUZ, a modular C stealer spreading via ClickFix since late April, likely MaaS, with a Go Vidar variant as stage two.

read →
~/articles/2026-07-16-coca-cola-fairlife-ransomware-sec-8k-us-production-halt
Coca-Cola halts Fairlife US production after ransomware
ransomware

Coca-Cola halts Fairlife US production after ransomware

Coca-Cola disclosed a Fairlife ransomware attack via SEC 8-K on July 16. US dairy production suspended, Canada unaffected. No group has claimed it.

read →
~/articles/2026-07-16-cisa-kev-sharepoint-cve-2026-58644-deserialization-fourth-in-week
CISA adds a fourth SharePoint bug to KEV in 48 hours
microsoft

CISA adds a fourth SharePoint bug to KEV in 48 hours

CVE-2026-58644 — an unauthenticated deserialization RCE, CVSS 9.8 — landed on CISA KEV this morning, two days after Microsoft shipped the SharePoint fix.

read →
~/articles/2026-07-16-agent-data-injection-choi-snu-uiuc-probabilistic-delimiter
Agent Data Injection: SQL injection, different decade
Analysis
threat intel

Agent Data Injection: SQL injection, different decade

Seoul National, UIUC, and Largosoft show AI agents misread punctuation in trusted data as structural delimiters. No CVE, no vendor fix planned.

read →
~/articles/2026-07-16-fortinet-fortisandbox-cve-2026-39808-25089-kev-unauth-rce
FortiSandbox: two 9.8 unauth RCEs hit KEV, Sunday deadline
fortinet

FortiSandbox: two 9.8 unauth RCEs hit KEV, Sunday deadline

CISA added CVE-2026-39808 and CVE-2026-25089 to KEV today — unauthenticated OS command injection in Fortinet FortiSandbox, CVSS 9.8 each, federal BOD 26-04 deadline this Sunday.

read →
~/articles/2026-07-16-group-ib-clicklock-macos-clickfix-launchagent-210ms-loop
ClickLock macOS stealer kills apps until user types password
threat intel

ClickLock macOS stealer kills apps until user types password

Group-IB documents ClickLock, a macOS stealer delivered via ClickFix that kills Finder, Dock, and browsers on a 210ms loop until the victim types their login password.

read →
~/articles/2026-07-16-anyrun-phantomenigma-brazil-gov-br-hijack-dmarc-inno-node
PhantomEnigma rides Brazilian .gov.br sites and mailboxes
threat intel

PhantomEnigma rides Brazilian .gov.br sites and mailboxes

ANY.RUN links a Brazilian banking crimeware operation to 20+ hijacked .gov.br sites and mailboxes, using signature-valid mail and trusted redirects.

read →
~/articles/2026-07-16-rapid7-attackerkb-public-sunset-august-18-curation
AttackerKB's public tier closes August 18
Analysis
threat intel

AttackerKB's public tier closes August 18

Rapid7 retires the public AttackerKB site and its open submissions on August 18. Analysis, writeups, and API access move behind curation and a customer login.

read →
~/articles/2026-07-16-23andme-chrome-holding-18m-43-state-ag-settlement-2023-breach
23andMe settles genetics breach: $18M, 43 states
threat intel

23andMe settles genetics breach: $18M, 43 states

Multistate AG coalition led by New York's Letitia James. Settlement resolves claims over the 2023 credential-stuffing breach that exposed 6.9M customers' genetic profiles.

read →
~/articles/2026-07-16-daxin-srt64-stupig-winlogon-taiwan-digiwin-jdk
Daxin resurfaces in Taiwan alongside new Stupig backdoor
threat intel

Daxin resurfaces in Taiwan alongside new Stupig backdoor

Symantec finds the Daxin kernel rootkit resurfacing at a Taiwan manufacturer, alongside a previously unreported pre-login SYSTEM backdoor called Stupig.

read →
~/articles/2026-07-16-scattered-spider-tfl-jubair-flowers-nca-cma-sentence
Two Scattered Spider affiliates get 5.5 years for TfL hack
threat intel

Two Scattered Spider affiliates get 5.5 years for TfL hack

Thalha Jubair, 20, and Owen Flowers, 18, pleaded guilty under the UK Computer Misuse Act. The 2024 intrusion knocked out 148 TfL systems and cost £29 million.

read →
~/articles/2026-07-16-sharkninja-tokay0-aws-iot-cert-region-root-no-patch
Unpatched Shark vacuums: regional root, no CVE, no patch
threat intel

Unpatched Shark vacuums: regional root, no CVE, no patch

tokay0 published a Shark robot vacuum flaw July 13: over-permissive AWS IoT device cert grants root on any other Shark in the same region. No patch.

read →
~/articles/2026-07-16-symantec-spirals-ransomware-iis-webshell-24h-south-asia
Spirals ransomware: full network encrypted in under 24h
ransomware

Spirals ransomware: full network encrypted in under 24h

Symantec documents Spirals, a new ransomware family: IIS web-shell entry to a fully encrypted network in under 24 hours — one confirmed victim so far, an IT services firm in South Asia.

read →
~/articles/2026-07-16-openai-gpt-red-internal-red-teamer-prompt-injection
OpenAI discloses GPT-Red, its internal automated red-teamer
threat intel

OpenAI discloses GPT-Red, its internal automated red-teamer

OpenAI describes GPT-Red, an internal automated red-teamer that scales prompt injection discovery and adversarially trains later models against those attacks.

read →
~/articles/2026-07-16-mindgard-cursor-workspace-git-hijack-windows-no-patch
Cursor: opening a repo runs its git.exe. No patch, 7 months.
supply chain

Cursor: opening a repo runs its git.exe. No patch, 7 months.

Mindgard disclosed a Cursor zero-day July 14 after seven months without a fix. Opening a repo with a git.exe file runs it as you. Windows only. No patch.

read →
~/articles/2026-07-16-microsoft-mdash-july-622-cves-ai-attribution-krebs-rapid7
The July patch count Microsoft warned would come
Analysis
microsoft

The July patch count Microsoft warned would come

Microsoft credited AI discovery for July's record 622-CVE Patch Tuesday. That's the second half of the story the MDASH post previewed a week earlier.

read →
~/articles/2026-07-16-microsoft-kb5099539-windows-10-esu-july-22h2-ltsc-2021
KB5099539 lands: Windows 10 ESU carries the July zero-days
microsoft

KB5099539 lands: Windows 10 ESU carries the July zero-days

Microsoft's KB5099539 delivers July's Patch Tuesday to Windows 10 22H2 and LTSC 2021 fleets, including two exploited zero-days. Enrollment required.

read →
~/articles/2026-07-16-intruder-vending-machine-llm-code-slicing-wordpress-zero-day
Intruder ships an LLM vuln-discovery product, plus a 0-day
Analysis
threat intel

Intruder ships an LLM vuln-discovery product, plus a 0-day

Intruder shipped an LLM code-slicing pipeline that turned up a WordPress plugin zero-day, plus more bugs still under responsible disclosure.

read →
~/articles/2026-07-15-cisa-kev-oracle-ebs-cve-2026-46817-payments-file-transmission
CISA KEV: Oracle EBS Payments 9.8 unauth RCE lands
oracle

CISA KEV: Oracle EBS Payments 9.8 unauth RCE lands

CISA added CVE-2026-46817 to KEV on Wednesday: unauthenticated CVSS 9.8 takeover of Oracle E-Business Suite Payments. Oracle's May 2026 CPU already has the fix.

read →
~/articles/2026-07-15-zoom-psirt-zsb-26014-workplace-windows-cvss-98-unauth-takeover
Zoom PSIRT: patch Workplace 7.0.0, unauth takeover 9.8
zoom

Zoom PSIRT: patch Workplace 7.0.0, unauth takeover 9.8

Zoom pushed a critical unauth account-takeover advisory (ZSB-26014, CVSS 9.8) for the Windows Workplace client and VDI Client — patch to 7.0.0 or the branch build.

read →
~/articles/2026-07-15-dutch-politie-100m-investment-fraud-20-call-centers-700-shills
Dutch bust €100M fraud ring, 20 call centers, 700 shills
threat intel

Dutch bust €100M fraud ring, 20 call centers, 700 shills

Dutch Politie takedown of a 2021-active investment-fraud ring — 20 call centers, ~700 fake advisers, five-country arrests, €100M+ estimated peak monthly.

read →
~/articles/2026-07-15-rapid7-sma1000-mdr-writeup-mfa-seeds-dc-pivots
SonicWall SMA1000: what Rapid7 saw before disclosure
sonicwall

SonicWall SMA1000: what Rapid7 saw before disclosure

Rapid7 caught the SMA1000 zero-day exploitation before SonicWall's advisory. Attackers took credentials, MFA seeds, and pivoted to internal domain controllers.

read →
~/articles/2026-07-15-unit-42-tuxbot-v3-llm-chain-of-thought-iot-botnet
Unit 42: TuxBot v3 shipped LLM chain-of-thought in comments
threat intel

Unit 42: TuxBot v3 shipped LLM chain-of-thought in comments

Palo Alto Unit 42 documents TuxBot v3, an IoT botnet whose developer left an AI safety disclaimer and raw reasoning traces in the shipped binary.

read →
~/articles/2026-07-15-trend-micro-bandcampro-gemini-cli-c2-botnet-operator
Trend Micro: bandcampro ran a C2 botnet on Gemini CLI
threat intel

Trend Micro: bandcampro ran a C2 botnet on Gemini CLI

Trend Micro logs 200+ Gemini CLI sessions from a Russian-speaking actor tracked as bandcampro: C2 migration, credential work, and daily botnet ops.

read →
~/articles/2026-07-15-knx-cve-2023-4346-cisa-kev-account-lockout-bod-26-04
KNX account-lockout flaw added to CISA KEV, three years on
ics ot

KNX account-lockout flaw added to CISA KEV, three years on

CVE-2023-4346 turns the KNX Association's account-lockout mechanism into a device-purge weapon on a building-automation bus. CISA added it to KEV under BOD 26-04.

read →
~/articles/2026-07-15-rapid7-blazek-aws-persistence-iam-lambda-federated-hunt-runbook
AWS persistence: four patterns to hunt after an incident
Analysis
cloud

AWS persistence: four patterns to hunt after an incident

Rapid7's Jan Blažek maps four AWS persistence classes — new IAM users, assume-role edits, Lambda backdoors, federated tokens — with the CloudTrail signals to hunt for each.

read →
~/articles/2026-07-15-kaspersky-okobot-seedhunter-ledger-trezor-electron-hook
Kaspersky: OkoBot phishes seeds inside Ledger, Trezor apps
threat intel

Kaspersky: OkoBot phishes seeds inside Ledger, Trezor apps

Kaspersky's GReAT team says OkoBot has hooked Electron in Ledger and Trezor apps since April 2025 to draw a fake seed-phrase prompt inside the real wallet UI.

read →
~/articles/2026-07-15-zyxel-cve-2023-28771-epss-099-three-years-post-patch
Zyxel CVE-2023-28771: EPSS 0.99 three years after the patch
Analysis
zyxel

Zyxel CVE-2023-28771: EPSS 0.99 three years after the patch

Zyxel's 2023 firewall command-injection bug still ranks EPSS 0.99 three years post-patch. Scans stay constant; unpatched SMB perimeter boxes remain plentiful.

read →
~/articles/2026-07-15-chaotic-eclipse-legacyhive-profsvc-lpe-poc-drop
LegacyHive: Chaotic Eclipse's fourth Windows zero-day
microsoft

LegacyHive: Chaotic Eclipse's fourth Windows zero-day

Researcher 'Chaotic Eclipse' released LegacyHive, a Windows User Profile Service arbitrary-hive-load LPE PoC, hours after July Patch Tuesday. Unpatched.

read →
~/articles/2026-07-15-mozilla-firefox-exploit-public-chrome-adobe-coldfusion-patch-day
Firefox exploit code public; Chrome, Adobe patch same day
mozilla

Firefox exploit code public; Chrome, Adobe patch same day

Mozilla says exploit code is public for two Firefox flaws fixed in 152.0.6. Chrome shipped Ozone use-after-free fixes; Adobe pushed 8 ColdFusion criticals.

read →
~/articles/2026-07-15-cisa-sharepoint-three-cves-bod-26-04-july-17-deadline
CISA: three SharePoint bugs exploited, patch by July 17
microsoft

CISA: three SharePoint bugs exploited, patch by July 17

CISA named three actively exploited on-prem SharePoint CVEs and put a July 17 remediation clock on federal agencies. Shadowserver counts 800+ unpatched servers. Patch on one maintenance touch.

read →
~/articles/2026-07-15-asyncapi-npm-miasma-multi-c2-loader-cicd-compromise
Miasma loader shipped in 5 @asyncapi npm package versions
supply chain

Miasma loader shipped in 5 @asyncapi npm package versions

5 @asyncapi npm versions unpublished. Miasma loader ships 744 modules over six C2 channels. Attackers compromised the CI/CD pipeline, not npm tokens — treat as post-install compromise.

read →
~/articles/2026-07-15-mindgard-cursor-git-exe-workspace-root-no-patch
Mindgard: Cursor still runs git.exe from repo root
threat intel

Mindgard: Cursor still runs git.exe from repo root

Aaron Portnoy's Mindgard team went public today: Cursor 3.11 on Windows executes any git.exe sitting in a cloned repo's root — seven months, no patch.

read →
~/articles/2026-07-15-doj-media-land-yalishanda-lockbit-blacksuit-play-bulletproof-hosting-indictment
DOJ indicts Media Land trio: LockBit, BlackSuit, Play host
ransomware

DOJ indicts Media Land trio: LockBit, BlackSuit, Play host

USAO-NDOH unsealed a Dec 2024 indictment against Volosovik ('Yalishanda'), Pankova, and Zatolokin — Media Land and ML.Cloud hosted LockBit, BlackSuit, Play. $62M losses, 21 states.

read →
~/articles/2026-07-15-microsoft-safeguard-hold-dell-kb5101650-intel-ipf-shutdowns
Microsoft blocks Dell PCs from July KB5101650 rollout
microsoft

Microsoft blocks Dell PCs from July KB5101650 rollout

Microsoft applied a safeguard hold on July's KB5101650 for a limited set of Dell devices running Windows 11 25H2 and 24H2 after a June preview update triggered Intel IPF driver crashes, heat, and battery drain.

read →
~/articles/2026-07-15-microsoft-entra-id-passkeys-default-september-sms-voice-retirement-feb-2027
Entra ID passkeys go default in Sept; SMS/voice out Feb 1
microsoft

Entra ID passkeys go default in Sept; SMS/voice out Feb 1

Microsoft is auto-enrolling Entra ID SMS/voice MFA users into passkeys starting September 2026 and retiring native SMS/voice delivery on Feb 1, 2027. What to do.

read →
~/articles/2026-07-15-reliaquest-jalisco-omegalord-m365-device-code-mfa-bypass
Jalisco kit auto-refreshes M365 device codes on demand
threat intel

Jalisco kit auto-refreshes M365 device codes on demand

ReliaQuest maps two new M365 phishing kits: Jalisco auto-refreshes OAuth device codes to defeat the 15-min window, OmegaLord harvests phones for MFA bypass.

read →
~/articles/2026-07-15-spain-140m-bec-fraud-ring-800-accounts-67-mules
Spain Dismantles €140M BEC Ring; 800 Accounts, 67 Mules
threat intel

Spain Dismantles €140M BEC Ring; 800 Accounts, 67 Mules

Spanish National Police dismantle a €140M BEC and investment fraud network using 800 bank accounts, 120 companies, and 67 mules; four arrested across three countries.

read →
~/articles/2026-07-15-lastpass-bitwarden-compliance-lookalike-domain-phishing
LastPass, Bitwarden users hit by lookalike-domain phishing
threat intel

LastPass, Bitwarden users hit by lookalike-domain phishing

LastPass and Bitwarden users are getting phishing from lookalike "compliance" domains pushing a DocuSign-styled downloader. Delete the email; don't click.

read →
~/articles/2026-07-15-blackpoint-labubarat-rust-nvidia-sysruntime-maas
Blackpoint flags LabubaRAT: Rust MaaS RAT poses as NVIDIA
threat intel

Blackpoint flags LabubaRAT: Rust MaaS RAT poses as NVIDIA

Blackpoint Cyber's Sam Decker and Nevan Beal document LabubaRAT — a Rust MaaS trojan on Windows that ships as nvidia-sysruntime.exe with runtime config.

read →
~/articles/2026-07-14-arctic-wolf-292-fake-github-repos-boryptgrab-infostealer
Arctic Wolf: 292 fake GitHub repos push BoryptGrab stealer
supply chain

Arctic Wolf: 292 fake GitHub repos push BoryptGrab stealer

Arctic Wolf tracked 292 fake GitHub repos seeding a BoryptGrab infostealer since June 26 — impersonating security tools, crypto wallets, and dev utilities.

read →
~/articles/2026-07-14-sonicwall-sma1000-cve-2026-15409-15410-kev-active-exploitation
SonicWall SMA1000 zero-days on CISA KEV: patch by July 17
sonicwall

SonicWall SMA1000 zero-days on CISA KEV: patch by July 17

Two SMA1000 flaws — a CVSS-10.0 unauthenticated SSRF and a post-auth code injection — hit CISA KEV today. Patch to 12.4.3-03453 or 12.5.0-02835 before July 17.

read →
~/articles/2026-07-14-manifold-claude-for-chrome-trust-boundary-still-open
Claude for Chrome flaw lets other extensions read Gmail
Analysis
browser

Claude for Chrome flaw lets other extensions read Gmail

Manifold says the trust-boundary flaw behind ClaudeBleed is still open in Claude for Chrome v1.0.80 — eight releases after Anthropic's May fix.

read →
~/articles/2026-07-14-rapid7-sharepoint-cve-2026-55040-jwt-auth-bypass-rce-chain-half
SharePoint JWT bypass fixed; RCE half of chain still open
microsoft

SharePoint JWT bypass fixed; RCE half of chain still open

Rapid7 disclosed CVE-2026-55040 today — a SharePoint JWT auth bypass patched in July Patch Tuesday. Second half of a pre-auth RCE chain lands next month. Patch now.

read →
~/articles/2026-07-14-microsoft-july-patch-tuesday-570-cves-adfs-sharepoint-bitlocker-zero-days
Microsoft July Patch Tuesday: 570 CVEs, 3 zero-days out
microsoft

Microsoft July Patch Tuesday: 570 CVEs, 3 zero-days out

Microsoft's July 2026 Patch Tuesday ships 570 CVEs, including two exploited zero-days in AD FS and SharePoint plus a publicly disclosed BitLocker bypass. Patch AD FS first.

read →
~/articles/2026-07-14-ku-leuven-distrinet-85-crypto-wallet-extensions-address-linking
KU Leuven: 85 wallet extensions leak addresses cross-site
browser

KU Leuven: 85 wallet extensions leak addresses cross-site

KU Leuven's DistriNet tested 85 Chrome crypto wallet extensions with ~35M installs. 17 link separate addresses in a single request. 22 of 36 ignore site disconnects.

read →
~/articles/2026-07-14-progress-sharefile-storage-zone-5-12-5-6-0-2-path-traversal-patch
Progress patches ShareFile zero-day: 5.12.5 and 6.0.2 out
progress

Progress patches ShareFile zero-day: 5.12.5 and 6.0.2 out

Progress shipped ShareFile Storage Zone Controller 5.12.5 and 6.0.2 to fix a high-severity authenticated path traversal. CVE pending. Patch first, then bring the boxes back up.

read →
~/articles/2026-07-14-rabbitmq-miggo-oauth-secret-cross-tenant-cve-2026-57219
Miggo: RabbitMQ leaked OAuth secret via obsolete endpoint
cloud

Miggo: RabbitMQ leaked OAuth secret via obsolete endpoint

Miggo disclosed two RabbitMQ flaws today: an obsolete /api/auth endpoint exposed the broker's OAuth client secret, and a bug bypassed vhost boundaries.

read →
~/articles/2026-07-14-proofpoint-oauth-client-id-spoofing-entra-signin-logs-blind
OAuth client ID spoofing sneaks past Entra sign-in logs
microsoft

OAuth client ID spoofing sneaks past Entra sign-in logs

Proofpoint tracked two credential-stuffing crews that submit fake OAuth application IDs to Entra ID's token endpoint. The sign-in logs don't record what defenders are looking for.

read →
~/articles/2026-07-14-eset-uefi-shim-cve-2026-8863-secure-boot-bypass
ESET: 11 old signed UEFI shims still bypass Secure Boot
microsoft

ESET: 11 old signed UEFI shims still bypass Secure Boot

ESET's Martin Smolár found 11 old Microsoft-signed UEFI shims that still bypass Secure Boot — CVE-2026-8863, revoked via the June DBX update.

read →
~/articles/2026-07-14-sap-july-patch-day-three-criticals-netweaver-approuter-commerce
SAP's July Patch Day: three criticals, worst is 9.9
sap

SAP's July Patch Day: three criticals, worst is 9.9

SAP's July 2026 Security Patch Day fixes 16 flaws — three rated critical, worst a CVSS 9.9 memory-corruption bug in NetWeaver ABAP. No known exploitation yet.

read →
~/articles/2026-07-14-ofac-1vpns-rashevskyi-silayev-sb0559-cryptor-designation
OFAC sanctions 1VPNS admin plus Belarusian cryptor seller
ransomware

OFAC sanctions 1VPNS admin plus Belarusian cryptor seller

OFAC designated 1VPNS, its Ukrainian admin Rashevskyi, and Belarusian cryptor seller Silayev on July 14 — the follow-on to May's Operation Saffron seizure.

read →
~/articles/2026-07-14-cereblab-grok-build-0-2-93-git-repo-upload-gcs
Grok Build v0.2.93 uploaded whole repos to xAI's bucket
threat intel

Grok Build v0.2.93 uploaded whole repos to xAI's bucket

xAI's Grok Build CLI v0.2.93 uploaded whole git repos, history and all, to a GCS bucket. The "Improve the model" toggle didn't stop it. Fix is server-side.

read →
~/articles/2026-07-14-jfrog-148-npm-packages-browser-ddos-botnet-may
148 npm packages ran a browser-based DDoS botnet in May
supply chain

148 npm packages ran a browser-based DDoS botnet in May

JFrog: 148 npm packages hosted a fake student web proxy that turned visiting browsers into a DDoS botnet for about two weeks in May. Not a supply-chain attack.

read →
~/articles/2026-07-14-microsoft-shinyhunters-salesforce-oauth-three-paths
A year of ShinyHunters OAuth abuse, mapped by Microsoft
Analysis
threat intel

A year of ShinyHunters OAuth abuse, mapped by Microsoft

Microsoft's July 13 report maps three OAuth paths ShinyHunters-linked actors used against Salesforce customers for a year — none of them a Salesforce bug.

read →
~/articles/2026-07-14-forg365-phaas-m365-device-code-aitm-market
Forg365 shows PhaaS became a $400/mo rental market
Analysis
threat intel

Forg365 shows PhaaS became a $400/mo rental market

Analysis: Forg365's $400/mo Microsoft 365 phishing kit adds device code, AitM, and AI-drafted replies. What changed here is finish, not the underlying kind.

read →
~/articles/2026-07-14-jscrambler-npm-post-mortem-four-versions-8-22-clean
Jscrambler: four npm versions hit, publish creds revoked
supply chain

Jscrambler: four npm versions hit, publish creds revoked

Jscrambler's post-incident report widens its July 11 npm compromise from one release to four (8.14, 8.16, 8.17, 8.20). 8.22 clean; publish creds revoked.

read →
~/articles/2026-07-13-nca-russian-coms-five-charged-1-8m-spoofed-calls
NCA charges five over Russian Coms spoofing platform
threat intel

NCA charges five over Russian Coms spoofing platform

The NCA charged five London residents over Russian Coms — a caller-ID spoofing platform behind 1.8M scam calls and 170,000 victims. Westminster court date Aug 14.

read →
~/articles/2026-07-13-meta-2026-0182881-lachlan-dunn-emotion-listening-patent
Meta patent describes an always-on emotion-reading AI
Analysis
threat intel

Meta patent describes an always-on emotion-reading AI

Meta patent 2026/0182881, published July 2, describes an always-on AI that tags voice, biometrics, and app use to score a user's emotional patterns.

read →
~/articles/2026-07-13-nihon-kotsu-japan-taxi-cyberattack-dispatch-offline
Nihon Kotsu cyberattack takes Japan taxi dispatch offline
threat intel

Nihon Kotsu cyberattack takes Japan taxi dispatch offline

Japan's largest taxi operator says a July 12 malware intrusion knocked dispatch, web booking, and labor-taxi services offline. No group has claimed.

read →
~/articles/2026-07-13-jamf-crashstealer-werkbit-notarized-macos-stealer
Notarized Werkbit.app carries CrashStealer past Gatekeeper
apple

Notarized Werkbit.app carries CrashStealer past Gatekeeper

Jamf flagged CrashStealer, a native-C++ macOS infostealer arriving inside Werkbit.app — Apple-notarized and gated behind a meeting PIN.

read →
~/articles/2026-07-13-modheader-stripe-olt-stanfordstudies-dormant-collector
ModHeader carried a dormant collector to 1.6M installs
browser

ModHeader carried a dormant collector to 1.6M installs

Stripe OLT found a browsing-history collector inside the store-signed ModHeader extension. Edge pulled it July 3; Chrome pulled it July 10. The allow-list shipped empty.

read →
~/articles/2026-07-13-cisa-kev-cve-2008-4128-cisco-ios-12-4-csrf
Cisco IOS 12.4 CSRF From 2008 Lands in CISA KEV
cisco

Cisco IOS 12.4 CSRF From 2008 Lands in CISA KEV

CISA added CVE-2008-4128 — a Cisco IOS 12.4 mainline HTTP admin CSRF from 2008 — to the KEV catalog on 2026-07-13. IOS 12.4 mainline is obsolete. Upgrade.

read →
~/articles/2026-07-13-memghost-arxiv-persistent-memory-poison-openclaw
MemGhost: an email that rewrites an AI agent's memory
Analysis
threat intel

MemGhost: an email that rewrites an AI agent's memory

arXiv paper: one crafted email talks a memory-enabled AI agent into writing attacker-supplied 'facts' into its memory files. Future sessions load them.

read →
~/articles/2026-07-13-cisa-github-leak-postmortem-nine-alerts-six-months
CISA postmortem: nine alerts ignored, six months exposed
Analysis
cloud

CISA postmortem: nine alerts ignored, six months exposed

CISA's postmortem on its own six-month GitHub credential leak faults slow key rotation and nine ignored GitGuardian alerts — signal without intake.

read →
~/articles/2026-07-13-lidl-online-shop-breach-de-be-nl-service-provider
Lidl online shop breach hits DE, BE, NL via provider
threat intel

Lidl online shop breach hits DE, BE, NL via provider

Lidl says a file at an unnamed service provider was accessed; DE/BE/NL online shop customer PII taken. Passwords and payment data not yet ruled out.

read →
~/articles/2026-07-13-huntress-ai-generated-powershell-ad-enum
Huntress Flags Suspected AI-Written PowerShell in AD Case
threat intel

Huntress Flags Suspected AI-Written PowerShell in AD Case

Huntress attributes an early-June AD enumeration case to a PowerShell script with clear LLM tells — cyan-and-green banners and 'FULLY FIXED' in the title.

read →
~/articles/2026-07-13-eu-uk-first-joint-cyber-sanctions-russia-33-named
First joint EU-UK cyber sanctions name 33 Russian targets
threat intel

First joint EU-UK cyber sanctions name 33 Russian targets

The EU Council named 9 individuals and 4 entities; the UK named 24 more. FSB Center 16, Sandworm, Turla, Lumma Stealer, and Rybar LLC are on the list.

read →
~/articles/2026-07-13-fsb-centre-16-cve-2018-0171-router-hygiene-csa
Seven years on, CVE-2018-0171 draws a 13-state advisory
ics ot

Seven years on, CVE-2018-0171 draws a 13-state advisory

US, UK, and eleven allied governments co-signed a July 13 advisory naming FSB Centre 16 as the actor still pulling configs off end-of-life Cisco routers via CVE-2018-0171.

read →
~/articles/2026-07-13-lexfo-evilginx-three-crews-open-directory
Three Evilginx Crews, One Forgotten Bash History
Analysis
threat intel

Three Evilginx Crews, One Forgotten Bash History

Lexfo pulled the full toolkit from an open Python server in Budapest and pivoted to two more Evilginx operations targeting Microsoft 365 tenants.

read →
~/articles/2026-07-12-redhook-group-ib-wireless-adb-loopback-shizuku-uid-2000
RedHook Android RAT pairs Wireless ADB on-device
mobile

RedHook Android RAT pairs Wireless ADB on-device

Group-IB details RedHook using Accessibility to enable Wireless Debugging, pair over loopback, and run shell as uid 2000. No CVE. Southeast Asia targeted.

read →
~/articles/2026-07-12-coinspect-ill-bloom-weak-prng-wallet-seed-5-1m-drained
Ill Bloom: Weak PRNG Drained $5.1M From Crypto Wallets
threat intel

Ill Bloom: Weak PRNG Drained $5.1M From Crypto Wallets

Coinspect's Ill Bloom disclosure: five unnamed wallets shipped seed-phrase code with weak randomness. Two sweeps in May and June drained $5.1M.

read →
~/articles/2026-07-11-sentinellabs-balochistan-police-china-india-converge
China, India APTs Converge on Balochistan Police
threat intel

China, India APTs Converge on Balochistan Police

SentinelLABS ties 22 months of intrusions at Balochistan Police to two separate crews: China-nexus operators using PlugX and India-linked Mysterious Elephant.

read →
~/articles/2026-07-11-jscrambler-npm-8-14-0-preinstall-rust-infostealer
jscrambler 8.14.0 npm hijack: Rust stealer on install
supply chain

jscrambler 8.14.0 npm hijack: Rust stealer on install

Malicious jscrambler 8.14.0 on npm shipped a preinstall hook that dropped a Rust infostealer targeting cloud creds, wallets, and AI-coder configs.

read →
~/articles/2026-07-11-mvpnalyzer-281-android-vpn-study-leaks-tracking
281 free Android VPN apps: 29 leak, 246 track
Analysis
mobile

281 free Android VPN apps: 29 leak, 246 track

MVPNalyzer, a University of Michigan / UNM / IIT Delhi tool presented at NDSS 2026, ran 281 top free Android VPN apps and found leaks, plaintext, and trackers.

read →
~/articles/2026-07-11-ptc-windchill-flexplm-cve-2026-12569-kev-jsp-webshell
PTC Windchill PLM RCE is on KEV — shells still landing
ptc

PTC Windchill PLM RCE is on KEV — shells still landing

PTC Windchill PDMLink and FlexPLM ship an unauth deserialization RCE. CISA added it to KEV on 2026-06-25. Unpatched instances are still catching JSP webshells.

read →
~/articles/2026-07-11-acsc-cms-plugin-exploitation-advisory-18-cves
Australia's ACSC names 18 CMS bugs under exploitation
Analysis
threat intel

Australia's ACSC names 18 CMS bugs under exploitation

Australia's ACSC named 18 CVEs across WordPress plugins, Craft CMS, Joomla JCE, and more as active exploitation targets, with attackers dropping webshells.

read →
~/articles/2026-07-11-gitea-docker-cve-2026-20896-sysdig-csa-1264-regression
Gitea Docker Auth Bypass: Patch 1.26.4, CSA Confirms
gitea

Gitea Docker Auth Bypass: Patch 1.26.4, CSA Confirms

Sysdig confirms the first in-the-wild hit on Gitea Docker CVE-2026-20896; Singapore CSA now warns customers; 1.26.3 shipped with a regression, so run 1.26.4.

read →
~/articles/2026-07-11-u-boot-libfdt-fit-parsing-six-brly-flaws
Six U-Boot flaws trace to one libfdt helper
ics ot

Six U-Boot flaws trace to one libfdt helper

Binarly disclosed six bugs in U-Boot's FIT-image parsing on July 9 — two potential RCE, four DoS — all tracing to unchecked libfdt calls present since 2013.07.

read →
~/articles/2026-07-11-ghostcommit-png-prompt-injection-coderabbit-bugbot
Ghostcommit and the reviewers that don't open the PNG
Analysis
threat intel

Ghostcommit and the reviewers that don't open the PNG

A PNG carrying prompt injection slips past AI code reviewers that never open image files, then talks a coding agent into exfiltrating a repo's .env secrets as a list of numbers.

read →
~/articles/2026-07-11-modbeacon-silver-fox-rust-rat-grpc-c2-qianxin
Silver Fox ships MODBEACON, a Rust RAT with gRPC C2
threat intel

Silver Fox ships MODBEACON, a Rust RAT with gRPC C2

QiAnXin attributes a new Rust-based RAT called MODBEACON to Silver Fox, using gRPC streaming for encrypted C2 and SEO-poisoned installers for delivery.

read →
~/articles/2026-07-11-metasploit-weekly-flowise-csv-packagekit-modules
Metasploit Weekly Adds Flowise CSV, macOS PackageKit
threat intel

Metasploit Weekly Adds Flowise CSV, macOS PackageKit

Rapid7's Metasploit weekly drops two modules — a Flowise CSV Agent prompt-injection RCE and a macOS PackageKit LPE. New tooling, not new bugs.

read →
~/articles/2026-07-11-cisa-kev-balbooa-icagenda-joomla-file-upload
Balbooa, iCagenda Join KEV: Four Joomla RCEs in Four Days
threat intel

Balbooa, iCagenda Join KEV: Four Joomla RCEs in Four Days

CISA added Balbooa Forms and iCagenda to KEV on July 10 — two unauthenticated file-upload RCEs in Joomla extensions. Federal due date is July 13.

read →
~/articles/2026-07-10-openmandriva-beatrici-cooker-cosmic-gnome-admin-boundary
OpenMandriva contributor deleted GNOME and Cosmic repos
Analysis
supply chain

OpenMandriva contributor deleted GNOME and Cosmic repos

Davide Beatrici, a three-year OpenMandriva admin, deleted the Cosmic and GNOME repositories and pushed an obsoleting empty package into Cooker on July 8.

read →
~/articles/2026-07-11-zimbra-10-1-19-classic-web-client-xss-google-tag
Zimbra ships 10.1.19; Google TAG reported the XSS
zimbra

Zimbra ships 10.1.19; Google TAG reported the XSS

Zimbra 10.1.19 patches a stored XSS in the Classic Web Client. No CVE yet, no confirmed exploitation — Google TAG reported it, which is the reason to patch now.

read →
~/articles/2026-07-11-npm-12-allowscripts-off-default-gats-oidc-branch
npm 12 turns install scripts off by default
Analysis
supply chain

npm 12 turns install scripts off by default

npm 12 defaults allowScripts to off and deprecates 2FA-bypass tokens. Closes the install-hook branch; does not touch the maintainer-account one.

read →
~/articles/2026-07-10-iossifov-seized-crypto-wallet-still-had-key
A seized crypto account that moved from a cell
Analysis
threat intel

A seized crypto account that moved from a cell

Rossen Iossifov, ten years into a laundering sentence, is charged with moving $290K from a seized crypto account. The interesting part is it still moved.

read →
~/articles/2026-07-10-microsoft-mdash-msrc-humans-downstream
Microsoft's MDASH and the humans downstream of it
Analysis
microsoft

Microsoft's MDASH and the humans downstream of it

Microsoft says AI-found Windows bugs will make Patch Tuesdays bigger. The interesting part isn't the AI — it's the human queue that signs off on what ships.

read →
~/articles/2026-07-10-openclaw-2026-6-6-nayak-whatsapp-host-rce-chain
OpenClaw patched a chain that started in a chat message
Analysis
threat intel

OpenClaw patched a chain that started in a chat message

OpenClaw 2026.6.6 closes three flaws that let a WhatsApp message reach the host as command execution. No public PoC, no observed exploitation.

read →
~/articles/2026-07-10-injective-sdk-ts-npm-oidc-thomasralee
Injective SDK's npm compromise, and the OIDC that let it
Analysis
supply chain

Injective SDK's npm compromise, and the OIDC that let it

@injectivelabs/sdk-ts@1.20.21 shipped a wallet-key exfiltration routine for two days. A maintainer account walked it through the OIDC publisher pipeline.

read →
~/articles/2026-07-10-binarly-uboot-six-flaws-fit-signature-verification
Six U-Boot bugs sit in front of the signature check
Analysis
supply chain

Six U-Boot bugs sit in front of the signature check

Binarly disclosed six flaws in U-Boot's FIT image parser. Two allow code execution, four are DoS, all reached before the signature check runs.

read →
~/articles/2026-07-10-vardanyan-ryuk-guilty-plea-portland-six-year-pipeline
A Ryuk operator pleads guilty, six years after wind-down
Analysis
ransomware

A Ryuk operator pleads guilty, six years after wind-down

Karen Vardanyan pleaded guilty in Portland to Ryuk-era conspiracy charges from 2019-2020. Sentencing is set for September. A note on how long the pipeline actually takes.

read →
~/articles/2026-07-10-politie-odido-dutch-speaker-vishing-shinyhunters-62m
Politie Points at Dutch Hackers in the 88GB Odido Leak
threat intel

Politie Points at Dutch Hackers in the 88GB Odido Leak

Dutch National Police say strong indications point at Dutch attackers behind February's Odido breach: a Dutch-speaking vishing call to customer service, then 6.2M records leaked.

read →
~/articles/2026-07-10-progress-sharefile-shutdown-storage-zone-moveit-echo
Progress tells ShareFile on-prem users to shut down servers
progress

Progress tells ShareFile on-prem users to shut down servers

Progress emailed on-prem ShareFile Storage Zone customers to shut down servers over a 'credible external threat.' No CVE, no patch — just an offline advisory.

read →
~/articles/2026-07-10-donjon-tangem-laser-fault-injection-eal6-samsung
A laser resets Tangem wallets, and there's no patch
Analysis
threat intel

A laser resets Tangem wallets, and there's no patch

Ledger Donjon's laser fault-injection attack resets a Tangem card's password without the old one. There is no patch — Tangem ships no firmware updates.

read →
~/articles/2026-07-10-foxio-xring-xquic-qpack-integer-underflow-alibaba-silence
XRING: 260 bytes, no patch, three months of Alibaba silence
Analysis
threat intel

XRING: 260 bytes, no patch, three months of Alibaba silence

FoxIO's Sébastien Féry disclosed a QPACK integer underflow in Alibaba XQUIC that crashes HTTP/3 servers with 260 bytes. Reported April 7. No reply. No patch.

read →
~/articles/2026-07-10-wp-shellstorm-socradar-exposed-server-funnel
WP-SHELLSTORM ran 22 days with its door left open
Analysis
threat intel

WP-SHELLSTORM ran 22 days with its door left open

SOCRadar and Ctrl-Alt-Intel pulled 22 days of files off an exposed WP-SHELLSTORM server: 1.4M targets, 25K compromises, 5,700 live shells.

read →
~/articles/2026-07-10-android-free-vpn-study-familiar-audit-outcome
281 free Android VPNs, and a familiar audit outcome
Analysis
mobile

281 free Android VPNs, and a familiar audit outcome

A new study of 281 popular free Android VPN apps found traffic leaks, missing encryption, and tracking. The category has kept failing this test for years.

read →
~/articles/2026-07-10-illbloom-coinspect-weak-prng-mobile-wallet-drain
Ill Bloom is a $3.1M lesson in weak randomness, again
Analysis
threat intel

Ill Bloom is a $3.1M lesson in weak randomness, again

Coinspect disclosed weak PRNG in wallet recovery-phrase generation; attackers drained $3.1M in a May sweep. The pattern — bad randomness, stolen keys — is old.

read →
~/articles/2026-07-10-digitalmint-martino-70-months-blackcat-insider-negotiation
Ex-DigitalMint negotiator gets 70 months for BlackCat scheme
Analysis
ransomware

Ex-DigitalMint negotiator gets 70 months for BlackCat scheme

Angelo Martino, ex-DigitalMint IR employee, sentenced to 70 months for feeding BlackCat victims' insurance limits and negotiation floors. An old failure mode.

read →
~/articles/2026-07-10-meta-muse-image-instagram-public-default-impersonation-surface
Meta's Muse Image defaults on for public Instagram
Analysis
threat intel

Meta's Muse Image defaults on for public Instagram

Meta's new Muse Image model reuses public Instagram photos and reels by default — no notification, no watermark discussion, opt-out three levels deep in Sharing settings.

read →
~/articles/2026-07-10-clearinghouse-summer-athena-lightwell-old-pattern
The clearinghouse boom is not new, and neither is the fatigue
Analysis
threat intel

The clearinghouse boom is not new, and neither is the fatigue

Chainguard announced Athena. Red Hat and the White House announced Lightwell. Vulnerability clearinghouses have been getting reannounced since the 1980s.

read →
~/articles/2026-07-10-hackernews-ato-verification-step-passkey-aftermath
The ATO fight moved past credential stuffing
Analysis
threat intel

The ATO fight moved past credential stuffing

The Hacker News argues account takeover shifted from credential stuffing to attacking verification — passkeys pushed the front door shut, so attackers moved.

read →
~/articles/2026-07-10-talos-hazel-winning-54-percent-defender-cliche
Talos on 'attackers only need to be right once'
Analysis
threat intel

Talos on 'attackers only need to be right once'

Cisco Talos's Hazel argues 'attackers only need to be right once' is a cliché the defensive community should retire. It's overdue.

read →
~/articles/2026-07-10-datadog-dormant-github-ghost-accounts-org-enumeration
Datadog: 50+ dormant GitHub accounts mapping org charts
Analysis
threat intel

Datadog: 50+ dormant GitHub accounts mapping org charts

Datadog Security Labs documents 50+ dormant GitHub accounts running months-long enumeration of corporate orgs, repos, and — in some cases — private code.

read →
~/articles/2026-07-09-openmandriva-beatrici-mumble-contributor-repo-sabotage
OpenMandriva ex-contributor wipes GNOME, Cosmic packages
supply chain

OpenMandriva ex-contributor wipes GNOME, Cosmic packages

Mumble developer Davide Beatrici used leftover admin from a repo migration to delete OpenMandriva GitHub content and obsolete GNOME, Cosmic packages.

read →
~/articles/2026-07-09-talos-vdr-wolfssl-geovision-vtk-dicom-disclosure
Talos discloses 18 vulns in WolfSSL, GeoVision, VTK-DICOM
ics ot

Talos discloses 18 vulns in WolfSSL, GeoVision, VTK-DICOM

Cisco Talos published a bulk third-party disclosure covering 3 WolfSSL, 14 GeoVision, and 1 VTK-DICOM vulnerabilities — all patched before publication.

read →
~/articles/2026-07-09-helix-reliaquest-sharepoint-vishing-blackfile-overlap
Helix: new data-extortion crew hits SharePoint via vishing
threat intel

Helix: new data-extortion crew hits SharePoint via vishing

ReliaQuest attributes new data-extortion crew Helix to vishing and device-code phishing against SharePoint. Infrastructure overlaps BlackFile.

read →
~/articles/2026-07-09-microsoft-mdash-ai-scanner-fatter-patch-tuesdays
Microsoft: MDASH will grow Patch Tuesday numbers
Analysis
microsoft

Microsoft: MDASH will grow Patch Tuesday numbers

Microsoft EVP Pavan Davuluri says a multi-model AI scanner called MDASH will surface more Windows bugs — expect higher-volume monthly releases.

read →
~/articles/2026-07-09-injectivelabs-sdk-ts-npm-1-20-21-wallet-stealer
Injective SDK 1.20.21 on npm shipped a wallet stealer
supply chain

Injective SDK 1.20.21 on npm shipped a wallet stealer

Attacker pushed @injectivelabs/sdk-ts 1.20.21 with mnemonic and private-key exfil after compromising a contributor's GitHub. 310 installs before the pull.

read →
~/articles/2026-07-09-microsoft-gigawiper-bluerabbit-cyberav3ngers-israel-wiper
GigaWiper/BLUERABBIT: Go-based wiper, CyberAv3ngers-linked
threat intel

GigaWiper/BLUERABBIT: Go-based wiper, CyberAv3ngers-linked

Microsoft and Binary Defense concurrently disclose a Go-based Windows destructive backdoor — wipe, fake ransomware, spyware in one binary — attributed to Iran-nexus CyberAv3ngers.

read →
~/articles/2026-07-09-npm-12-install-scripts-off-default-github-gat-deprecation
npm 12 flips install scripts off by default
Analysis
supply chain

npm 12 flips install scripts off by default

npm 12 lands with allowScripts, --allow-git, and --allow-remote all defaulting to none. GitHub is also winding down GATs that skip 2FA. The default just moved.

read →
~/articles/2026-07-09-forg365-phaas-m365-aitm-device-code-zerobec
Forg365 PhaaS Chains AiTM + Device-Code + AI Lures at M365
microsoft

Forg365 PhaaS Chains AiTM + Device-Code + AI Lures at M365

ZeroBEC flagged a new phishing-as-a-service, Forg365, bundling AiTM proxying with OAuth device-code prompts and AI lures against Microsoft 365 accounts.

read →
~/articles/2026-07-09-goddamn-ransomware-poisonx-driver-beast-rebrand
GodDamn ransomware: Beast rebrand, signed EDR-killer driver
ransomware

GodDamn ransomware: Beast rebrand, signed EDR-killer driver

Symantec attributes a new family, GodDamn, as a Beast rebrand shipping the PoisonX driver (g11.sys) — a Microsoft-signed kernel BYOVD used to neutralize endpoint defenses.

read →
~/articles/2026-07-09-microsoft-owa-light-retirement-exchange-server
Microsoft to retire OWA Light in Exchange Server
Analysis
microsoft

Microsoft to retire OWA Light in Exchange Server

Microsoft is disabling OWA Light in an August 2026 Exchange Server update, ending a legacy client shipped when IE6 was current. Admins can disable it today.

read →
~/articles/2026-07-09-interpol-first-light-5811-arrests-293m-seized
INTERPOL First Light 2026: 5,811 arrests, $293M seized
threat intel

INTERPOL First Light 2026: 5,811 arrests, $293M seized

INTERPOL's Operation First Light 2026 arrested 5,811 fraud suspects across 97 countries, seized $293M and blocked 31,014 accounts over 3.5 months.

read →
~/articles/2026-07-09-ai-now-friendly-fire-claude-code-codex-review-exploit
Friendly Fire: agents review the trap, then execute it
Analysis
threat intel

Friendly Fire: agents review the trap, then execute it

AI Now Institute researchers show autonomous Claude Code and Codex can be tricked into running a hidden binary during their own security-review pass.

read →
~/articles/2026-07-09-assuranceamerica-breach-6-9m-drivers-march-intrusion
AssuranceAmerica breach: 6.9M drivers, 4-month notice gap
threat intel

AssuranceAmerica breach: 6.9M drivers, 4-month notice gap

AssuranceAmerica confirms a March 16 intrusion exposed data on 6,998,886 drivers. Notification letters went out in July — a nearly four-month gap between detection and public notice.

read →
~/articles/2026-07-09-infoblox-lurking-lizard-230-domain-fake-7zip-residential-proxy
Infoblox: Lurking Lizard runs 230-domain fake 7-Zip proxy
threat intel

Infoblox: Lurking Lizard runs 230-domain fake 7-Zip proxy

Infoblox ties a China-based residential-proxy operator to 230+ lookalike domains active since 2022, seeding fake 7-Zip and WireVPN installers.

read →
~/articles/2026-07-09-microsoft-defender-rogueplanet-cve-2026-50656-lpe-patch
Microsoft patches Defender 'RoguePlanet' LPE; PoC public
microsoft

Microsoft patches Defender 'RoguePlanet' LPE; PoC public

Microsoft shipped an out-of-band Defender engine update for RoguePlanet (CVE-2026-50656), a race-condition LPE to SYSTEM. Public PoC. Verify auto-update landed.

read →
~/articles/2026-07-09-wiz-ghostapproval-symlink-six-ai-coding-assistants
GhostApproval symlink bug hits six AI coding assistants
threat intel

GhostApproval symlink bug hits six AI coding assistants

Wiz research: Amazon Q, Cursor, Claude Code, Augment, Antigravity, Windsurf all approved one file path in the dialog while writing to another via symlinks.

read →
~/articles/2026-07-09-simplehelp-cve-2026-48558-oidc-bypass-past-kev-deadline
SimpleHelp OIDC Auth Bypass Past CISA Deadline: Patch Now
simplehelp

SimpleHelp OIDC Auth Bypass Past CISA Deadline: Patch Now

SimpleHelp Server 5.5.15 and earlier accept forged OIDC tokens as valid technician sessions. CVSS 10.0, KEV, patch is 5.5.16 — CISA deadline was July 2.

read →
~/articles/2026-07-08-redwing-android-maas-oblivion-telegram-zimperium
RedWing turns Android bank fraud into a Telegram rental
Analysis
mobile

RedWing turns Android bank fraud into a Telegram rental

Zimperium's zLabs details RedWing, an Android bank-fraud MaaS sold on Telegram — Oblivion variant, subscription tiers, prebuilt droppers, 82 target banks.

read →
~/articles/2026-07-08-spain-palencia-carr-noname-logistics-arrest
Spain arrests suspected CARR logistics operator
Analysis
threat intel

Spain arrests suspected CARR logistics operator

Spanish police detained a Palencia man tied to CyberArmy of Russia Reborn, Z-Pentest, and NoName057(16). The announcement lands nearly four months after the raid.

read →
~/articles/2026-07-08-writeout-writer-ai-cross-tenant-session-sand-security
WriteOut: One Preview Link Took Over Writer AI Accounts
cloud

WriteOut: One Preview Link Took Over Writer AI Accounts

SAND Security's WriteOut let a Writer AI agent preview link steal a signed-in user's session cookie across tenants. Writer has patched — the pattern hasn't.

read →
~/articles/2026-07-08-mount-royal-university-cmd-organization-30-btc-breach
Mount Royal University confirms June breach, 30 BTC demand
ransomware

Mount Royal University confirms June breach, 30 BTC demand

Mount Royal University confirms a June 17 intrusion exfiltrated H drive data. A group calling itself CMD demands 30 BTC before the stated leak deadline.

read →
~/articles/2026-07-08-socket-paysafe-skrill-npm-pypi-fake-sdks
Socket: 17 fake Paysafe, Skrill, Neteller SDKs on npm and PyPI
supply chain

Socket: 17 fake Paysafe, Skrill, Neteller SDKs on npm and PyPI

Socket disclosed 17 malicious packages posing as Paysafe, Skrill, and Neteller SDKs across npm and PyPI. Payload steals payment API keys, AWS keys, and GitHub/npm tokens.

read →
~/articles/2026-07-08-iris-c2-krebs-wohl-burkman-zero-day-broker
Krebs traces zero-day broker IRIS C2 to Wohl and Burkman
Analysis
threat intel

Krebs traces zero-day broker IRIS C2 to Wohl and Burkman

Krebs ties IRIS C2, an offensive-security startup pitching zero-day acquisition, to Jacob Wohl and Jack Burkman — both convicted of felony fraud.

read →
~/articles/2026-07-08-sophos-coding-agents-tripping-edr-attacker-detections
Sophos: Coding Agents Are Tripping the Attacker Detections
Analysis
threat intel

Sophos: Coding Agents Are Tripping the Attacker Detections

Seven days of Sophos endpoint telemetry: Claude Code, Cursor, and Codex trip the same rules built to catch attackers — because behaviorally, they should.

read →
~/articles/2026-07-08-pink-o-unc-066-entra-passkey-vishing-okta-unit42
Pink Vishing Enrolls Rogue Entra Passkeys on M365 Tenants
microsoft

Pink Vishing Enrolls Rogue Entra Passkeys on M365 Tenants

Okta and Unit 42 attribute an ongoing vishing campaign — active since April — that walks Microsoft 365 users through enrolling a passkey the attacker controls.

read →
~/articles/2026-07-08-hallusquatting-npm-ai-hallucinated-packages-tel-aviv
HalluSquatting weaponizes AI-hallucinated npm packages
supply chain

HalluSquatting weaponizes AI-hallucinated npm packages

Tel Aviv researchers register the fake package names AI coding assistants keep inventing. Up to 100% hit rate on skill installs, no confirmed exploitation yet.

read →
~/articles/2026-07-08-copilot-workflow-jailbreak-arxiv-kumar-maple
Refused in Chat, Written in Code: Copilot's Workflow Gap
Analysis
threat intel

Refused in Chat, Written in Code: Copilot's Workflow Gap

Kumar and Maple's new arXiv preprint says Copilot's Claude and Gemini backends refused harmful prompts in chat but produced them 816-for-816 in a workflow.

read →
~/articles/2026-07-08-scmbanker-elastic-ref6045-mexican-banking-fraud
SCMBANKER active against Mexican banks — Elastic REF6045
threat intel

SCMBANKER active against Mexican banks — Elastic REF6045

Elastic Security Labs is tracking SCMBANKER (REF6045), a PowerShell fraud toolkit hitting Mexican banks, fintechs, and crypto exchanges via ClickFix lures.

read →
~/articles/2026-07-08-github-verified-commit-hash-malleability-ginesin
A signed Git commit's hash is not a unique fingerprint
Analysis
supply chain

A signed Git commit's hash is not a unique fingerprint

Carnegie Mellon research shows a signed Git commit can be re-minted with a different hash but the same 'Verified' badge — no signing key required, no code changed.

read →
~/articles/2026-07-08-kddi-japan-isp-breach-12m-third-party-zero-day
KDDI Breach: 12M Emails, 7.6M Passwords via 3rd-Party 0day
threat intel

KDDI Breach: 12M Emails, 7.6M Passwords via 3rd-Party 0day

KDDI says a May 16 zero-day in unnamed third-party software exposed 12,233,087 email addresses and 7,616,173 passwords across five Japanese ISPs.

read →
~/articles/2026-07-08-gitlost-github-agentic-workflows-noma-security-private-repos
GitLost: Public Issue Leaks Private GitHub Repo Data
cloud

GitLost: Public Issue Leaks Private GitHub Repo Data

Noma Security's GitLost shows how a public GitHub issue can trick Agentic Workflows into leaking private repos. Not patchable — scope your agent tokens today.

read →
~/articles/2026-07-08-cisa-coldfusion-cve-2026-48282-kev-friday-deadline
CISA: Patch ColdFusion CVE-2026-48282 by Friday
adobe

CISA: Patch ColdFusion CVE-2026-48282 by Friday

CISA added Adobe ColdFusion CVE-2026-48282 to KEV on July 7 and set a July 10 federal patch deadline under BOD 26-04. CVSS 10.0. Actively exploited.

read →
~/articles/2026-07-08-ubiquiti-unifi-connect-command-injection-cve-2026-50746
Ubiquiti Patches Max-Severity UniFi Connect Command Injection
ubiquiti

Ubiquiti Patches Max-Severity UniFi Connect Command Injection

Ubiquiti Bulletin 066 patches seven critical UniFi flaws, headlined by a CVSS 10.0 command injection in UniFi Connect 3.4.16 and earlier. Fix: 3.4.20 or later.

read →
~/articles/2026-07-08-dialogflow-cx-rogue-agent-shared-exec-varonis
Dialogflow's Rogue Agent Flaw Is a Very Old Bug Class
Analysis
cloud

Dialogflow's Rogue Agent Flaw Is a Very Old Bug Class

Varonis' Rogue Agent finding in Google Dialogflow CX is a shared-runtime exec() escape — a bug class old enough to have graduated shared hosting.

read →
~/articles/2026-07-08-ghostlock-linux-kernel-cve-2026-43499-container-escape
GhostLock: 15-Year Linux Kernel Root/Container Escape
linux kernel

GhostLock: 15-Year Linux Kernel Root/Container Escape

Nebula Security's GhostLock (CVE-2026-43499) — a 15-year-old futex use-after-free — hits every mainstream Linux distro. Escapes containers. Patch again.

read →
~/articles/2026-07-08-debull-m365-device-code-phishing-storm-2372-overlap
DEBULL Kit Runs M365 Device-Code Phishing, Storm-2372
microsoft

DEBULL Kit Runs M365 Device-Code Phishing, Storm-2372

ZeroBEC reports DEBULL — a device-code phishing kit repackaging Storm-2372 tradecraft — active against M365 tenants late June to early July. Block it.

read →
~/articles/2026-07-08-cisa-kev-langflow-joomla-page-builder-adds
CISA Adds Langflow and Two Joomla Builders to KEV
threat intel

CISA Adds Langflow and Two Joomla Builders to KEV

CISA added three vulnerabilities to KEV on July 7 — a Langflow IDOR and two Joomla page-builder RCEs. Federal due date is July 10. Priority order below.

read →
~/articles/2026-07-08-unk-masstraction-china-cluster-roundcube-universities
Proofpoint: China cluster raids university physics mail
Analysis
threat intel

Proofpoint: China cluster raids university physics mail

Proofpoint attributes a Roundcube-exploitation campaign against U.S. and Canadian university physics departments to a China-aligned cluster, UNK_MassTraction.

read →
~/articles/2026-07-07-uat-7810-longleash-orb-network-ruckus-asus
China-Linked UAT-7810 Expands ORB Net With LONGLEASH
threat intel

China-Linked UAT-7810 Expands ORB Net With LONGLEASH

Cisco Talos ties China-aligned UAT-7810 to LONGLEASH backdoor and an expanding ORB relay network built on unpatched Ruckus and ASUS routers.

read →
~/articles/2026-07-08-scattered-spider-windows-device-id-court-filing-stokes
Windows Device ID trail led FBI to Scattered Spider suspect
Analysis
threat intel

Windows Device ID trail led FBI to Scattered Spider suspect

A newly unsealed federal complaint says a Microsoft-recorded device ID tied the account behind a Scattered Spider intrusion to 19-year-old Peter Stokes.

read →
~/articles/2026-07-07-tenda-router-backdoor-cve-2026-11405-unpatched
Tenda Router Backdoor Has No Patch. Here's What to Do.
ics ot

Tenda Router Backdoor Has No Patch. Here's What to Do.

CERT/CC flagged an authentication backdoor in multiple Tenda router firmware builds. Tenda didn't respond. No fix is coming — here's the mitigation.

read →
~/articles/2026-07-07-accenture-confirms-breach-source-code-claim
Accenture Confirms Breach; Attacker Claims 35 GB Stolen
threat intel

Accenture Confirms Breach; Attacker Claims 35 GB Stolen

Accenture confirmed a security incident. A threat actor is advertising 35 GB of alleged source code for sale. The volume claim is unverified — treat accordingly.

read →
~/articles/2026-07-07-januscape-cve-2026-53359-kvm-guest-host-escape
Januscape (CVE-2026-53359): 16-year KVM guest-to-host escape
linux kernel

Januscape (CVE-2026-53359): 16-year KVM guest-to-host escape

A 16-year-old use-after-free in KVM's shadow MMU lets a guest VM panic — or, with an unreleased exploit, root — the host on Intel and AMD. Patched June 19.

read →
~/articles/2026-07-07-beyondtrust-remote-support-pra-auth-bypass
BeyondTrust Patches Four RS/PRA Flaws — Patch Now
beyondtrust

BeyondTrust Patches Four RS/PRA Flaws — Patch Now

BeyondTrust shipped fixes on July 6 for four vulnerabilities in Remote Support and Privileged Remote Access, including a CVSS 9.8 pre-auth bypass. No in-wild exploitation reported. Here's the priority order.

read →
~/articles/2026-07-06-gitea-docker-cve-2026-20896-header-auth-bypass
Gitea Docker's Auth Bypass: Probing Already Underway
gitea

Gitea Docker's Auth Bypass: Probing Already Underway

The Gitea Docker image up through 1.26.2 shipped a wildcard reverse-proxy trusted list, collapsing auth to a header. Fixed in 1.26.3. The Hacker News reports opportunistic scanning 13 days after disclosure; ~6,200 exposed instances.

read →
~/articles/2026-07-06-trojpix-air-gap-video-cable-emanation-shandong
TrojPix: air-gap exfil via video-cable RF emanation
Analysis
ics ot

TrojPix: air-gap exfil via video-cable RF emanation

Shandong University researchers show a covert-channel technique that turns invisible pixel changes into a radio signal a nearby receiver can decode from the display cable itself.

read →
~/articles/2026-07-06-adobe-coldfusion-cve-2026-48282-active-exploitation
Adobe ColdFusion CVE-2026-48282: CVSS 10, Exploited
adobe

Adobe ColdFusion CVE-2026-48282: CVSS 10, Exploited

A max-severity unauthenticated path-traversal-to-RCE in ColdFusion 2023 and 2025 is under active attack. Adobe's 72-hour patch window has already passed. Shadowserver counts ~800 exposed instances.

read →
~/articles/2026-07-06-operation-dragonreturn-china-nexus-dcrat-india-tax
DragonReturn Drops DcRAT on Indian Taxpayers
threat intel

DragonReturn Drops DcRAT on Indian Taxpayers

Seqrite Labs attributes an ongoing spear-phishing campaign against Indian tax filers to a suspected China-nexus actor with infrastructure and tactical overlap to Silver Fox. First observed May 18.

read →
~/articles/2026-07-06-gitlab-exiftool-rce-cve-2021-22205
GitLab's ExifTool RCE Sat Unrecognized for Months
Explainer
gitlab

GitLab's ExifTool RCE Sat Unrecognized for Months

CVE-2021-22205 was quietly fixed in April 2021 — but its full unauthenticated remote-code-execution severity wasn't widely understood until late 2021, by which point mass exploitation had already begun.

read →
~/articles/2026-07-06-quimarat-java-cross-platform-maas-levelblue
QuimaRAT: A $150 Cross-Platform Java RAT MaaS
threat intel

QuimaRAT: A $150 Cross-Platform Java RAT MaaS

LevelBlue profiled a new cross-platform Java RAT sold as MaaS. No confirmed campaigns yet — but the price is low, the payload runs everywhere, and the loader is built to walk past SmartScreen. Assume it lands somewhere soon.

read →
~/articles/2026-07-06-opera-gx-mods-auto-install-flaw-patched
Opera GX Patches Auto-Install Mods Flaw
browser

Opera GX Patches Auto-Install Mods Flaw

Opera fixed a flaw that let a malicious website force-install a GX Mod and use CSS injection to lift data from pages you visited. Patched; no CVE; no in-wild exploitation reported.

read →
~/articles/2026-07-06-skillcloak-scanners-miss-agent-skill-malware-hkust
SkillCloak: Scanners Miss 90%+ of Skill Malware
supply chain

SkillCloak: Scanners Miss 90%+ of Skill Malware

HKUST researchers show static scanners for AI agent skill marketplaces miss over 90% of malware repackaged with simple tricks. If you rely on them, that gate is broken.

read →
~/articles/2026-07-05-flipper-zero-firmware-maintenance-only-community-driven
Flipper Zero Firmware Goes Maintenance-Only
threat intel

Flipper Zero Firmware Goes Maintenance-Only

Flipper Devices says the Flipper Zero firmware is stable at 1.0 and full-time feature work is over. Community PRs run the future, filtered through GitHub Discussions voting and stricter review. Here's what changes.

read →
~/articles/2026-07-05-barracuda-esg-zero-day-cve-2023-2868
Barracuda Told Customers to Replace ESG Appliances
Analysis
barracuda

Barracuda Told Customers to Replace ESG Appliances

CVE-2023-2868 was exploited as a zero-day for roughly seven months before discovery — and left some compromised appliances backdoored even after the software patch was applied.

read →
~/articles/2026-07-05-jfrog-rollup-polyfill-npm-six-packages-follow-up
Four More Rollup Polyfill Typosquats Surface
supply chain

Four More Rollup Polyfill Typosquats Surface

JFrog's disclosure names six npm packages in the Rollup polyfill typosquat cluster, not two. The extra four sit inside the same infrastructure the earlier reporting described, and the audit surface hasn't moved.

read →
~/articles/2026-07-05-winrar-path-traversal-cve-2023-38831
WinRAR Bug Hid a Malicious Script in a Fake Photo
Explainer
rarlab

WinRAR Bug Hid a Malicious Script in a Fake Photo

CVE-2023-38831 let a booby-trapped archive execute code when a user clicked what looked like a harmless image file — exploited against trading forums before the technical details were widely known.

read →
~/articles/2026-07-04-metasploit-weekly-smb-meterpreter-peyara-detection
Metasploit's July 3 Drop: SMB-to-Meterpreter, Peyara
threat intel

Metasploit's July 3 Drop: SMB-to-Meterpreter, Peyara

Rapid7 shipped an SMB-to-Meterpreter session upgrade and a Peyara Remote Mouse RCE module this week. Neither is novel research. Both change what your alerts will look like. Here's the tune.

read →
~/articles/2026-07-04-kairos-1m-extortion-payment-us-government-ransom-isac
Kairos Took $1M — and Never Encrypted a File
ransomware

Kairos Took $1M — and Never Encrypted a File

Ransom-ISAC's new case study confirms a ~$1M payment (9.44 BTC) to the Kairos crew on June 13, 2025. Krishnan's review found no encryption at any point — data-theft extortion only, tracked in ransomware feeds anyway.

read →
~/articles/2026-07-04-vmware-vcenter-vsphere-client-rce-cve-2021-21972
vCenter's Upload Bug: Don't Expose Management Planes
Explainer
vmware

vCenter's Upload Bug: Don't Expose Management Planes

CVE-2021-21972 let unauthenticated attackers execute code with root privileges on VMware vCenter Server — and internet scans found tens of thousands of instances exposed anyway, against VMware's own guidance.

read →
~/articles/2026-07-04-bluehammer-defender-lpe-kev-ransomware-confirmed
BlueHammer Defender LPE Now Used in Ransomware
microsoft

BlueHammer Defender LPE Now Used in Ransomware

CVE-2026-33825, the Microsoft Defender local privilege escalation disclosed as a zero-day by 'Chaotic Eclipse' in April, is confirmed weaponized in ransomware. Patched. Ransomware family unnamed.

read →
~/articles/2026-07-04-polinrider-108-dprk-packages-contagious-interview
PolinRider: DPRK Seeds 108 Malicious Packages
supply chain

PolinRider: DPRK Seeds 108 Malicious Packages

The Hacker News reports 108 malicious npm, Packagist, Go, and Chrome extension listings tied to the DPRK Contagious Interview cluster. Here's what a dev shop actually does about it this week.

read →
~/articles/2026-07-04-spring4shell-vmware-spring-framework-rce
Spring4Shell: Why This One Needed Careful Triage, Not Panic
Explainer
vmware

Spring4Shell: Why This One Needed Careful Triage, Not Panic

CVE-2022-22965 leaked publicly before VMware's patch was ready — but unlike Log4Shell, exploitation required a specific combination of conditions that made blanket panic the wrong response.

read →
~/articles/2026-07-04-orchid-iga-ai-agents-lifecycle-gaps
IGA Was Built Around Employment Records, Not Agents
Analysis
threat intel

IGA Was Built Around Employment Records, Not Agents

A contributed piece to The Hacker News from Orchid Security lays out where the joiner-mover-leaver model quietly fails for AI agents. Vendor-adjacent, but the gap analysis holds.

read →
~/articles/2026-07-04-avalon-crownx-modular-malware-framework
Avalon Framework Bundles Theft, Wiper, CrownX
ransomware

Avalon Framework Bundles Theft, Wiper, CrownX

Blackpoint Cyber says the previously undocumented Avalon framework combines credential theft, EDR-aware defense evasion, shadow-copy destruction, and the CrownX ransomware payload in one multi-stage phishing chain.

read →
~/articles/2026-07-04-toddycat-umbrij-oauth-gmail-kaspersky
Umbrij: ToddyCat Hijacks Gmail OAuth via Browser
cloud

Umbrij: ToddyCat Hijacks Gmail OAuth via Browser

Kaspersky Securelist detailed Umbrij, a ToddyCat post-compromise tool that self-grants Google Workspace OAuth tokens by driving a logged-in Chromium session. Nothing to patch. Plenty to audit.

read →
~/articles/2026-07-04-artoken-eviltokens-m365-device-code-phishing-talos
ARToken PhaaS Targets M365 Device-Code Phishing
cloud

ARToken PhaaS Targets M365 Device-Code Phishing

Cisco Talos exposed ARToken, a React-panel phishing-as-a-service tied to EvilTokens. Device code flow is the mechanic. Conditional Access is the fix, and most tenants still haven't turned it on.

read →
~/articles/2026-07-04-talos-catan-and-mouse-curiosity-defensive-skill
Talos on Curiosity: A Skill That Doesn't Scale
Analysis
threat intel

Talos on Curiosity: A Skill That Doesn't Scale

William Largent's Threat Source column this week reads as an essay on board games and pattern recognition. It's really an argument about the load-bearing skill that keeps a defender from becoming a checklist.

read →
~/articles/2026-07-04-armored-likho-busysnake-power-sector-kaspersky
Armored Likho Ties BusySnake to Power-Sector Spying
ics ot

Armored Likho Ties BusySnake to Power-Sector Spying

Kaspersky attributes a previously undocumented threat actor, Armored Likho, to a campaign hitting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan using the BusySnake stealer.

read →
~/articles/2026-07-04-consentfix-clickfix-m365-oauth-consent-phishing
ConsentFix + ClickFix: M365 Grants Outlive Resets
cloud

ConsentFix + ClickFix: M365 Grants Outlive Resets

BleepingComputer covered two M365 hijack patterns and Opera's Paste Protect defense this week. The clipboard lane can be closed. The OAuth grant substrate underneath is unchanged.

read →
~/articles/2026-07-03-fortibleed-inc-lynx-ransomware-attribution
FortiBleed Tied to INC and Lynx Ransomware Crews
ransomware

FortiBleed Tied to INC and Lynx Ransomware Crews

The Hacker News reports an operator behind FortiBleed's credential-theft infrastructure was seen running ransomware negotiation panels for both INC and Lynx. Not a resale ring — a pipeline.

read →
~/articles/2026-07-03-pegasus-mep-kouloglou-citizen-lab-analysis
Pegasus on the MEP investigating Pegasus
Analysis
mobile

Pegasus on the MEP investigating Pegasus

Citizen Lab's forensic analysis found that former European Parliament member Stelios Kouloglou was repeatedly infected with NSO Group's Pegasus spyware while serving on the committee tasked with investigating that industry.

read →
~/articles/2026-07-03-chocopoc-rat-fake-poc-github-pypi-yeswehack
ChocoPoC: Fake CVE PoC Repos Ship a Stealer
supply chain

ChocoPoC: Fake CVE PoC Repos Ship a Stealer

YesWeHack and Sekoia disclosed a stealer campaign hiding inside GitHub PoC repos and PyPI packages, targeting the researchers who clone them. Treat every fresh 'PoC for hot CVE' repo as hostile until you've read every dependency.

read →
~/articles/2026-07-03-fatfs-runzero-seven-flaws-embedded-firmware
runZero Discloses Seven FatFs Firmware Flaws
supply chain

runZero Discloses Seven FatFs Firmware Flaws

runZero disclosed seven vulnerabilities in FatFs, a small filesystem library shipped inside ESP-IDF, STM32Cube, Zephyr, MicroPython, and other embedded stacks. Only one has an upstream fix.

read →
~/articles/2026-07-03-sysdig-jadepuffer-ai-agent-langflow-ransomware
Sysdig: JADEPUFFER ran a full ransomware chain from one LLM
ransomware

Sysdig: JADEPUFFER ran a full ransomware chain from one LLM

Sysdig's Threat Research Team says JADEPUFFER is the first ransomware incident it has observed where an AI agent handled entry, credential theft, lateral movement, and destruction end-to-end. Initial access was a Langflow code-execution flaw.

read →
~/articles/2026-07-03-bad-epoll-linux-kernel-lpe-cve-2026-46242
Bad Epoll: Linux Kernel LPE Also Hits Android
linux kernel

Bad Epoll: Linux Kernel LPE Also Hits Android

A newly disclosed use-after-free in Linux 6.4+ kernels lets an unprivileged local user gain root. Android on affected kernels is in scope; the upstream fix is in.

read →
~/articles/2026-07-03-pamstealer-macos-maccy-impersonation-jamf
PamStealer: A Fake Maccy Site Steals macOS Creds
threat intel

PamStealer: A Fake Maccy Site Steals macOS Creds

Jamf Threat Labs disclosed a new macOS credential stealer today that impersonates the Maccy clipboard app, validates the victim's login password against PAM in real time, and exfiltrates keychain and browser data. Apple Silicon only. Here's what defenders should do.

read →
~/articles/2026-07-03-avalon-crownx-modular-malware-framework
Blackpoint: Avalon Bundles Theft, Wiper, CrownX
ransomware

Blackpoint: Avalon Bundles Theft, Wiper, CrownX

Blackpoint Cyber documents Avalon, a previously undocumented modular framework whose ransomware payload — CrownX — arrives at the end of a legal-lure phishing chain that stages through Proton Drive, ISO, LNK, and MSBuild.

read →
~/articles/2026-07-03-cisco-unified-cm-active-exploitation-confirmed
Cisco Confirms Active Exploitation of Unified CM Flaw
cisco

Cisco Confirms Active Exploitation of Unified CM Flaw

Cisco updated its Unified Communications Manager advisory this week to state attackers are exploiting the flaw in the wild. Patched builds have been out for a month. If yours isn't on one, that's the whole conversation.

read →
~/articles/2026-07-03-argo-cd-repo-server-unauth-rce-unpatched
Unpatched Argo CD Flaw Lets Unauth Cluster Takeover
cloud

Unpatched Argo CD Flaw Lets Unauth Cluster Takeover

Synacktiv disclosed an unpatched code-execution flaw in Argo CD's repo-server component. No fix, no CVE. Reachability of the internal port is the whole game.

read →
~/articles/2026-07-03-dprk-npm-rollup-polyfill-supply-chain
DPRK npm Packages Impersonate a Rollup Polyfill
Analysis
supply chain

DPRK npm Packages Impersonate a Rollup Polyfill

JFrog links two new malicious npm packages — impersonating a Rollup polyfill project down to its metadata — to a DPRK cluster after developer secrets and remote access.

read →
~/articles/2026-07-03-anubis-ransomware-citrix-bleed-2-cve-2025-5777
Anubis Ransomware Exploits Citrix Bleed 2
ransomware

Anubis Ransomware Exploits Citrix Bleed 2

The Hacker News reports Anubis-ransomware affiliates using Citrix Bleed 2 (CVE-2025-5777) to breach NetScaler-fronted environments, then pivoting with legit RMM, BYOVD, and stolen supply-chain credentials.

read →
~/articles/2026-07-03-confluence-ognl-injection-cve-2022-26134
The Confluence Bug That Became a Ransomware Precursor
Explainer
atlassian

The Confluence Bug That Became a Ransomware Precursor

CVE-2022-26134 gave unauthenticated attackers remote code execution on any exposed Confluence instance — and became a go-to foothold for ransomware operators within days of disclosure.

read →
~/articles/2026-07-03-fortios-fortiproxy-auth-bypass-cve-2022-40684
FortiOS Auth Bypass: Fortinet Warned Select Customers
Explainer
fortinet

FortiOS Auth Bypass: Fortinet Warned Select Customers

CVE-2022-40684 let attackers bypass authentication on FortiOS and FortiProxy management interfaces and plant persistent SSH keys — Fortinet quietly warned targeted customers before public disclosure.

read →
~/articles/2026-07-03-kemp-loadmaster-cve-2026-8037-pre-auth-rce
Kemp LoadMaster Pre-Auth RCE: PoC Is Out, Patch Now
progress

Kemp LoadMaster Pre-Auth RCE: PoC Is Out, Patch Now

A functional proof-of-concept for a critical pre-auth RCE in Progress Kemp LoadMaster hit the internet on June 29 and eSentire started seeing exploitation attempts the same day. Progress's fix has been available since June 4.

read →
~/articles/2026-07-03-fbi-netnut-popa-botnet-takedown
FBI Seizes NetNut Proxy, Google Degrades Popa Botnet
threat intel

FBI Seizes NetNut Proxy, Google Degrades Popa Botnet

The FBI seized hundreds of NetNut proxy domains on July 2; Google's Threat Intelligence Group, working with FBI and Lumen, cut the linked Popa botnet's usable device pool by millions the same day.

read →
~/articles/2026-07-03-sharepoint-cve-2026-45659-kev-active-exploitation
SharePoint RCE now on CISA KEV: patch it this week, not next
microsoft

SharePoint RCE now on CISA KEV: patch it this week, not next

CISA added CVE-2026-45659, a high-severity SharePoint Server deserialization RCE, to the Known Exploited Vulnerabilities catalog on July 2 after confirming active exploitation. Microsoft's May patch is your remediation.

read →
~/articles/2026-07-02-f5-big-ip-icontrol-rest-auth-bypass
F5 BIG-IP's Max-Severity Auth Bypass, Explained
Explainer
f5

F5 BIG-IP's Max-Severity Auth Bypass, Explained

A critical authentication-bypass flaw in F5 BIG-IP's iControl REST API let unauthenticated attackers execute system commands on appliances that front an enormous share of enterprise application traffic.

read →
~/articles/2026-07-02-follina-msdt-zero-day-explained
Follina: The MSDT Bug That Skipped Macro Warnings
Explainer
microsoft

Follina: The MSDT Bug That Skipped Macro Warnings

CVE-2022-30190 let a Word document trigger arbitrary code execution through the Windows Support Diagnostic Tool — no macros, and in some configurations no explicit click required beyond opening the file.

read →
~/articles/2026-07-01-mshtml-office-zero-day-cve-2021-40444
The MSHTML Zero-Day That Weaponized a Word Doc
Explainer
microsoft

The MSHTML Zero-Day That Weaponized a Word Doc

CVE-2021-40444 let attackers execute arbitrary code through a malicious Office document with no macros required — exploited in the wild before Microsoft's patch existed.

read →
~/articles/2026-07-01-proxylogon-exchange-server-attack-chain
ProxyLogon: Inside the Exchange Server Attack Chain
Analysis
microsoft

ProxyLogon: Inside the Exchange Server Attack Chain

CVE-2021-26855 and three chained Exchange Server bugs gave attackers unauthenticated remote code execution — and led to a compromise event so widespread the FBI obtained a court order to remove webshells itself.

read →
~/articles/2026-06-30-printnightmare-windows-print-spooler-explained
PrintNightmare: A Leaked PoC Forced an Emergency Patch
Explainer
microsoft

PrintNightmare: A Leaked PoC Forced an Emergency Patch

CVE-2021-34527 let attackers turn the Windows Print Spooler service — running by default on nearly every Windows machine — into a path to SYSTEM privileges or full domain compromise.

read →
~/articles/2026-06-30-log4shell-log4j-anniversary-explainer
Log4Shell, Explained: The Internet's Worst Week
Explainer
apache

Log4Shell, Explained: The Internet's Worst Week

CVE-2021-44228 turned a single misused feature in Apache Log4j2 — a Java logging library embedded almost everywhere — into one of the most widely exploited vulnerabilities ever recorded.

read →
~/articles/2026-06-28-outlook-monikerlink-rce-patch-tuesday-explainer
Outlook MonikerLink Bug Bypasses Protected View
Explainer
microsoft

Outlook MonikerLink Bug Bypasses Protected View

CVE-2024-21413 let attackers bypass Outlook's Protected View sandbox with a single specially crafted hyperlink, leading to code execution and potential credential leakage. Patched in February 2024's Patch Tuesday.

read →
~/articles/2026-06-27-pan-os-globalprotect-command-injection-zero-day
PAN-OS GlobalProtect Zero-Day Gave Attackers Root
Explainer
palo alto networks

PAN-OS GlobalProtect Zero-Day Gave Attackers Root

CVE-2024-3400, a maximum-severity command-injection flaw in Palo Alto Networks' PAN-OS GlobalProtect feature, was exploited in the wild before a patch existed — handing attackers root access to the perimeter firewall.

read →
~/articles/2026-06-26-ivanti-connect-secure-chained-zero-days-explained
Inside Ivanti Connect Secure's Chained Zero-Days
Explainer
ivanti

Inside Ivanti Connect Secure's Chained Zero-Days

CVE-2023-46805 and CVE-2024-21887, chained together, gave a suspected nation-state actor unauthenticated remote code execution on Ivanti Connect Secure and Policy Secure VPN gateways for weeks before patches.

read →
~/articles/2026-06-25-citrix-bleed-netscaler-session-hijacking-explained
Citrix Bleed: A Memory Leak That Bypassed MFA
Explainer
citrix

Citrix Bleed: A Memory Leak That Bypassed MFA

CVE-2023-4966, known as Citrix Bleed, let attackers pull live session tokens straight out of NetScaler ADC and Gateway memory — hijacking already-authenticated sessions without needing a password or MFA code.

read →
~/articles/2026-06-24-cisco-ios-xe-web-ui-zero-day-mass-exploitation
Cisco IOS XE Web UI Zero-Day: Mass Exploitation
Explainer
cisco

Cisco IOS XE Web UI Zero-Day: Mass Exploitation

CVE-2023-20198, a maximum-severity privilege-escalation flaw in Cisco IOS XE's web management interface, was exploited at mass scale before a patch existed — handing attackers full admin control of network infrastructure.

read →