Skip to content
feed: live
>_ 0dayNews
$ latest

Vulnerability & Exploit Coverage

143 articles · sorted newest first

~/articles/2026-07-13-nihon-kotsu-japan-taxi-cyberattack-dispatch-offline
Nihon Kotsu cyberattack takes Japan taxi dispatch offline
● Breaking
threat intel

Nihon Kotsu cyberattack takes Japan taxi dispatch offline

Japan's largest taxi operator says a July 12 malware intrusion knocked dispatch, web booking, and labor-taxi services offline. No group has claimed.

read →
~/articles/2026-07-13-jamf-crashstealer-werkbit-notarized-macos-stealer
Notarized Werkbit.app carries CrashStealer past Gatekeeper
apple

Notarized Werkbit.app carries CrashStealer past Gatekeeper

Jamf flagged CrashStealer, a native-C++ macOS infostealer arriving inside Werkbit.app — Apple-notarized and gated behind a meeting PIN.

read →
~/articles/2026-07-13-modheader-stripe-olt-stanfordstudies-dormant-collector
ModHeader carried a dormant collector to 1.6M installs
● Breaking
browser

ModHeader carried a dormant collector to 1.6M installs

Stripe OLT found a browsing-history collector inside the store-signed ModHeader extension. Edge pulled it July 3; Chrome pulled it July 10. The allow-list shipped empty.

read →
~/articles/2026-07-13-cisa-kev-cve-2008-4128-cisco-ios-12-4-csrf
Cisco IOS 12.4 CSRF From 2008 Lands in CISA KEV
● Breaking
cisco

Cisco IOS 12.4 CSRF From 2008 Lands in CISA KEV

CISA added CVE-2008-4128 — a Cisco IOS 12.4 mainline HTTP admin CSRF from 2008 — to the KEV catalog on 2026-07-13. IOS 12.4 mainline is obsolete. Upgrade.

read →
~/articles/2026-07-13-memghost-arxiv-persistent-memory-poison-openclaw
MemGhost: an email that rewrites an AI agent's memory
Analysis
threat intel

MemGhost: an email that rewrites an AI agent's memory

arXiv paper: one crafted email talks a memory-enabled AI agent into writing attacker-supplied 'facts' into its memory files. Future sessions load them.

read →
~/articles/2026-07-13-cisa-github-leak-postmortem-nine-alerts-six-months
CISA postmortem: nine alerts ignored, six months exposed
Analysis
cloud

CISA postmortem: nine alerts ignored, six months exposed

CISA's postmortem on its own six-month GitHub credential leak faults slow key rotation and nine ignored GitGuardian alerts — signal without intake.

read →
~/articles/2026-07-13-lidl-online-shop-breach-de-be-nl-service-provider
Lidl online shop breach hits DE, BE, NL via provider
● Breaking
threat intel

Lidl online shop breach hits DE, BE, NL via provider

Lidl says a file at an unnamed service provider was accessed; DE/BE/NL online shop customer PII taken. Passwords and payment data not yet ruled out.

read →
~/articles/2026-07-13-huntress-ai-generated-powershell-ad-enum
Huntress Flags Suspected AI-Written PowerShell in AD Case
threat intel

Huntress Flags Suspected AI-Written PowerShell in AD Case

Huntress attributes an early-June AD enumeration case to a PowerShell script with clear LLM tells — cyan-and-green banners and 'FULLY FIXED' in the title.

read →
~/articles/2026-07-13-eu-uk-first-joint-cyber-sanctions-russia-33-named
First joint EU-UK cyber sanctions name 33 Russian targets
● Breaking
threat intel

First joint EU-UK cyber sanctions name 33 Russian targets

The EU Council named 9 individuals and 4 entities; the UK named 24 more. FSB Center 16, Sandworm, Turla, Lumma Stealer, and Rybar LLC are on the list.

read →
~/articles/2026-07-13-fsb-centre-16-cve-2018-0171-router-hygiene-csa
Seven years on, CVE-2018-0171 draws a 13-state advisory
ics ot

Seven years on, CVE-2018-0171 draws a 13-state advisory

US, UK, and eleven allied governments co-signed a July 13 advisory naming FSB Centre 16 as the actor still pulling configs off end-of-life Cisco routers via CVE-2018-0171.

read →
~/articles/2026-07-13-lexfo-evilginx-three-crews-open-directory
Three Evilginx Crews, One Forgotten Bash History
Analysis
threat intel

Three Evilginx Crews, One Forgotten Bash History

Lexfo pulled the full toolkit from an open Python server in Budapest and pivoted to two more Evilginx operations targeting Microsoft 365 tenants.

read →
~/articles/2026-07-12-redhook-group-ib-wireless-adb-loopback-shizuku-uid-2000
RedHook Android RAT pairs Wireless ADB on-device
mobile

RedHook Android RAT pairs Wireless ADB on-device

Group-IB details RedHook using Accessibility to enable Wireless Debugging, pair over loopback, and run shell as uid 2000. No CVE. Southeast Asia targeted.

read →
~/articles/2026-07-12-coinspect-ill-bloom-weak-prng-wallet-seed-5-1m-drained
Ill Bloom: Weak PRNG Drained $5.1M From Crypto Wallets
● Breaking
threat intel

Ill Bloom: Weak PRNG Drained $5.1M From Crypto Wallets

Coinspect's Ill Bloom disclosure: five unnamed wallets shipped seed-phrase code with weak randomness. Two sweeps in May and June drained $5.1M.

read →
~/articles/2026-07-11-sentinellabs-balochistan-police-china-india-converge
China, India APTs Converge on Balochistan Police
threat intel

China, India APTs Converge on Balochistan Police

SentinelLABS ties 22 months of intrusions at Balochistan Police to two separate crews: China-nexus operators using PlugX and India-linked Mysterious Elephant.

read →
~/articles/2026-07-11-jscrambler-npm-8-14-0-preinstall-rust-infostealer
jscrambler 8.14.0 npm hijack: Rust stealer on install
supply chain

jscrambler 8.14.0 npm hijack: Rust stealer on install

Malicious jscrambler 8.14.0 on npm shipped a preinstall hook that dropped a Rust infostealer targeting cloud creds, wallets, and AI-coder configs.

read →
~/articles/2026-07-11-mvpnalyzer-281-android-vpn-study-leaks-tracking
281 free Android VPN apps: 29 leak, 246 track
Analysis
mobile

281 free Android VPN apps: 29 leak, 246 track

MVPNalyzer, a University of Michigan / UNM / IIT Delhi tool presented at NDSS 2026, ran 281 top free Android VPN apps and found leaks, plaintext, and trackers.

read →
~/articles/2026-07-11-ptc-windchill-flexplm-cve-2026-12569-kev-jsp-webshell
PTC Windchill PLM RCE is on KEV — shells still landing
ptc

PTC Windchill PLM RCE is on KEV — shells still landing

PTC Windchill PDMLink and FlexPLM ship an unauth deserialization RCE. CISA added it to KEV on 2026-06-25. Unpatched instances are still catching JSP webshells.

read →
~/articles/2026-07-11-acsc-cms-plugin-exploitation-advisory-18-cves
Australia's ACSC names 18 CMS bugs under exploitation
Analysis
threat intel

Australia's ACSC names 18 CMS bugs under exploitation

Australia's ACSC named 18 CVEs across WordPress plugins, Craft CMS, Joomla JCE, and more as active exploitation targets, with attackers dropping webshells.

read →
~/articles/2026-07-11-gitea-docker-cve-2026-20896-sysdig-csa-1264-regression
Gitea Docker Auth Bypass: Patch 1.26.4, CSA Confirms
gitea

Gitea Docker Auth Bypass: Patch 1.26.4, CSA Confirms

Sysdig confirms the first in-the-wild hit on Gitea Docker CVE-2026-20896; Singapore CSA now warns customers; 1.26.3 shipped with a regression, so run 1.26.4.

read →
~/articles/2026-07-11-u-boot-libfdt-fit-parsing-six-brly-flaws
Six U-Boot flaws trace to one libfdt helper
ics ot

Six U-Boot flaws trace to one libfdt helper

Binarly disclosed six bugs in U-Boot's FIT-image parsing on July 9 — two potential RCE, four DoS — all tracing to unchecked libfdt calls present since 2013.07.

read →
~/articles/2026-07-11-ghostcommit-png-prompt-injection-coderabbit-bugbot
Ghostcommit and the reviewers that don't open the PNG
Analysis
threat intel

Ghostcommit and the reviewers that don't open the PNG

A PNG carrying prompt injection slips past AI code reviewers that never open image files, then talks a coding agent into exfiltrating a repo's .env secrets as a list of numbers.

read →
~/articles/2026-07-11-modbeacon-silver-fox-rust-rat-grpc-c2-qianxin
Silver Fox ships MODBEACON, a Rust RAT with gRPC C2
threat intel

Silver Fox ships MODBEACON, a Rust RAT with gRPC C2

QiAnXin attributes a new Rust-based RAT called MODBEACON to Silver Fox, using gRPC streaming for encrypted C2 and SEO-poisoned installers for delivery.

read →
~/articles/2026-07-11-metasploit-weekly-flowise-csv-packagekit-modules
Metasploit Weekly Adds Flowise CSV, macOS PackageKit
threat intel

Metasploit Weekly Adds Flowise CSV, macOS PackageKit

Rapid7's Metasploit weekly drops two modules — a Flowise CSV Agent prompt-injection RCE and a macOS PackageKit LPE. New tooling, not new bugs.

read →
~/articles/2026-07-11-cisa-kev-balbooa-icagenda-joomla-file-upload
Balbooa, iCagenda Join KEV: Four Joomla RCEs in Four Days
threat intel

Balbooa, iCagenda Join KEV: Four Joomla RCEs in Four Days

CISA added Balbooa Forms and iCagenda to KEV on July 10 — two unauthenticated file-upload RCEs in Joomla extensions. Federal due date is July 13.

read →
~/articles/2026-07-10-openmandriva-beatrici-cooker-cosmic-gnome-admin-boundary
OpenMandriva contributor deleted GNOME and Cosmic repos
Analysis
supply chain

OpenMandriva contributor deleted GNOME and Cosmic repos

Davide Beatrici, a three-year OpenMandriva admin, deleted the Cosmic and GNOME repositories and pushed an obsoleting empty package into Cooker on July 8.

read →
~/articles/2026-07-11-zimbra-10-1-19-classic-web-client-xss-google-tag
Zimbra ships 10.1.19; Google TAG reported the XSS
zimbra

Zimbra ships 10.1.19; Google TAG reported the XSS

Zimbra 10.1.19 patches a stored XSS in the Classic Web Client. No CVE yet, no confirmed exploitation — Google TAG reported it, which is the reason to patch now.

read →
~/articles/2026-07-11-npm-12-allowscripts-off-default-gats-oidc-branch
npm 12 turns install scripts off by default
Analysis
supply chain

npm 12 turns install scripts off by default

npm 12 defaults allowScripts to off and deprecates 2FA-bypass tokens. Closes the install-hook branch; does not touch the maintainer-account one.

read →
~/articles/2026-07-10-iossifov-seized-crypto-wallet-still-had-key
A seized crypto account that moved from a cell
Analysis
threat intel

A seized crypto account that moved from a cell

Rossen Iossifov, ten years into a laundering sentence, is charged with moving $290K from a seized crypto account. The interesting part is it still moved.

read →
~/articles/2026-07-10-microsoft-mdash-msrc-humans-downstream
Microsoft's MDASH and the humans downstream of it
Analysis
microsoft

Microsoft's MDASH and the humans downstream of it

Microsoft says AI-found Windows bugs will make Patch Tuesdays bigger. The interesting part isn't the AI — it's the human queue that signs off on what ships.

read →
~/articles/2026-07-10-openclaw-2026-6-6-nayak-whatsapp-host-rce-chain
OpenClaw patched a chain that started in a chat message
Analysis
threat intel

OpenClaw patched a chain that started in a chat message

OpenClaw 2026.6.6 closes three flaws that let a WhatsApp message reach the host as command execution. No public PoC, no observed exploitation.

read →
~/articles/2026-07-10-injective-sdk-ts-npm-oidc-thomasralee
Injective SDK's npm compromise, and the OIDC that let it
Analysis
supply chain

Injective SDK's npm compromise, and the OIDC that let it

@injectivelabs/sdk-ts@1.20.21 shipped a wallet-key exfiltration routine for two days. A maintainer account walked it through the OIDC publisher pipeline.

read →
~/articles/2026-07-10-binarly-uboot-six-flaws-fit-signature-verification
Six U-Boot bugs sit in front of the signature check
Analysis
supply chain

Six U-Boot bugs sit in front of the signature check

Binarly disclosed six flaws in U-Boot's FIT image parser. Two allow code execution, four are DoS, all reached before the signature check runs.

read →
~/articles/2026-07-10-vardanyan-ryuk-guilty-plea-portland-six-year-pipeline
A Ryuk operator pleads guilty, six years after wind-down
Analysis
ransomware

A Ryuk operator pleads guilty, six years after wind-down

Karen Vardanyan pleaded guilty in Portland to Ryuk-era conspiracy charges from 2019-2020. Sentencing is set for September. A note on how long the pipeline actually takes.

read →
~/articles/2026-07-10-politie-odido-dutch-speaker-vishing-shinyhunters-62m
Politie Points at Dutch Hackers in the 88GB Odido Leak
threat intel

Politie Points at Dutch Hackers in the 88GB Odido Leak

Dutch National Police say strong indications point at Dutch attackers behind February's Odido breach: a Dutch-speaking vishing call to customer service, then 6.2M records leaked.

read →
~/articles/2026-07-10-progress-sharefile-shutdown-storage-zone-moveit-echo
Progress tells ShareFile on-prem users to shut down servers
progress

Progress tells ShareFile on-prem users to shut down servers

Progress emailed on-prem ShareFile Storage Zone customers to shut down servers over a 'credible external threat.' No CVE, no patch — just an offline advisory.

read →
~/articles/2026-07-10-donjon-tangem-laser-fault-injection-eal6-samsung
A laser resets Tangem wallets, and there's no patch
Analysis
threat intel

A laser resets Tangem wallets, and there's no patch

Ledger Donjon's laser fault-injection attack resets a Tangem card's password without the old one. There is no patch — Tangem ships no firmware updates.

read →
~/articles/2026-07-10-foxio-xring-xquic-qpack-integer-underflow-alibaba-silence
XRING: 260 bytes, no patch, three months of Alibaba silence
Analysis
threat intel

XRING: 260 bytes, no patch, three months of Alibaba silence

FoxIO's Sébastien Féry disclosed a QPACK integer underflow in Alibaba XQUIC that crashes HTTP/3 servers with 260 bytes. Reported April 7. No reply. No patch.

read →
~/articles/2026-07-10-wp-shellstorm-socradar-exposed-server-funnel
WP-SHELLSTORM ran 22 days with its door left open
Analysis
threat intel

WP-SHELLSTORM ran 22 days with its door left open

SOCRadar and Ctrl-Alt-Intel pulled 22 days of files off an exposed WP-SHELLSTORM server: 1.4M targets, 25K compromises, 5,700 live shells.

read →
~/articles/2026-07-10-android-free-vpn-study-familiar-audit-outcome
281 free Android VPNs, and a familiar audit outcome
Analysis
mobile

281 free Android VPNs, and a familiar audit outcome

A new study of 281 popular free Android VPN apps found traffic leaks, missing encryption, and tracking. The category has kept failing this test for years.

read →
~/articles/2026-07-10-illbloom-coinspect-weak-prng-mobile-wallet-drain
Ill Bloom is a $3.1M lesson in weak randomness, again
Analysis
threat intel

Ill Bloom is a $3.1M lesson in weak randomness, again

Coinspect disclosed weak PRNG in wallet recovery-phrase generation; attackers drained $3.1M in a May sweep. The pattern — bad randomness, stolen keys — is old.

read →
~/articles/2026-07-10-digitalmint-martino-70-months-blackcat-insider-negotiation
Ex-DigitalMint negotiator gets 70 months for BlackCat scheme
Analysis
ransomware

Ex-DigitalMint negotiator gets 70 months for BlackCat scheme

Angelo Martino, ex-DigitalMint IR employee, sentenced to 70 months for feeding BlackCat victims' insurance limits and negotiation floors. An old failure mode.

read →
~/articles/2026-07-10-meta-muse-image-instagram-public-default-impersonation-surface
Meta's Muse Image defaults on for public Instagram
Analysis
threat intel

Meta's Muse Image defaults on for public Instagram

Meta's new Muse Image model reuses public Instagram photos and reels by default — no notification, no watermark discussion, opt-out three levels deep in Sharing settings.

read →
~/articles/2026-07-10-clearinghouse-summer-athena-lightwell-old-pattern
The clearinghouse boom is not new, and neither is the fatigue
Analysis
threat intel

The clearinghouse boom is not new, and neither is the fatigue

Chainguard announced Athena. Red Hat and the White House announced Lightwell. Vulnerability clearinghouses have been getting reannounced since the 1980s.

read →
~/articles/2026-07-10-hackernews-ato-verification-step-passkey-aftermath
The ATO fight moved past credential stuffing
Analysis
threat intel

The ATO fight moved past credential stuffing

The Hacker News argues account takeover shifted from credential stuffing to attacking verification — passkeys pushed the front door shut, so attackers moved.

read →
~/articles/2026-07-10-talos-hazel-winning-54-percent-defender-cliche
Talos on 'attackers only need to be right once'
Analysis
threat intel

Talos on 'attackers only need to be right once'

Cisco Talos's Hazel argues 'attackers only need to be right once' is a cliché the defensive community should retire. It's overdue.

read →
~/articles/2026-07-10-datadog-dormant-github-ghost-accounts-org-enumeration
Datadog: 50+ dormant GitHub accounts mapping org charts
Analysis
threat intel

Datadog: 50+ dormant GitHub accounts mapping org charts

Datadog Security Labs documents 50+ dormant GitHub accounts running months-long enumeration of corporate orgs, repos, and — in some cases — private code.

read →
~/articles/2026-07-09-openmandriva-beatrici-mumble-contributor-repo-sabotage
OpenMandriva ex-contributor wipes GNOME, Cosmic packages
supply chain

OpenMandriva ex-contributor wipes GNOME, Cosmic packages

Mumble developer Davide Beatrici used leftover admin from a repo migration to delete OpenMandriva GitHub content and obsolete GNOME, Cosmic packages.

read →
~/articles/2026-07-09-talos-vdr-wolfssl-geovision-vtk-dicom-disclosure
Talos discloses 18 vulns in WolfSSL, GeoVision, VTK-DICOM
ics ot

Talos discloses 18 vulns in WolfSSL, GeoVision, VTK-DICOM

Cisco Talos published a bulk third-party disclosure covering 3 WolfSSL, 14 GeoVision, and 1 VTK-DICOM vulnerabilities — all patched before publication.

read →
~/articles/2026-07-09-helix-reliaquest-sharepoint-vishing-blackfile-overlap
Helix: new data-extortion crew hits SharePoint via vishing
threat intel

Helix: new data-extortion crew hits SharePoint via vishing

ReliaQuest attributes new data-extortion crew Helix to vishing and device-code phishing against SharePoint. Infrastructure overlaps BlackFile.

read →
~/articles/2026-07-09-microsoft-mdash-ai-scanner-fatter-patch-tuesdays
Microsoft: MDASH will grow Patch Tuesday numbers
Analysis
microsoft

Microsoft: MDASH will grow Patch Tuesday numbers

Microsoft EVP Pavan Davuluri says a multi-model AI scanner called MDASH will surface more Windows bugs — expect higher-volume monthly releases.

read →
~/articles/2026-07-09-injectivelabs-sdk-ts-npm-1-20-21-wallet-stealer
Injective SDK 1.20.21 on npm shipped a wallet stealer
supply chain

Injective SDK 1.20.21 on npm shipped a wallet stealer

Attacker pushed @injectivelabs/sdk-ts 1.20.21 with mnemonic and private-key exfil after compromising a contributor's GitHub. 310 installs before the pull.

read →
~/articles/2026-07-09-microsoft-gigawiper-bluerabbit-cyberav3ngers-israel-wiper
GigaWiper/BLUERABBIT: Go-based wiper, CyberAv3ngers-linked
threat intel

GigaWiper/BLUERABBIT: Go-based wiper, CyberAv3ngers-linked

Microsoft and Binary Defense concurrently disclose a Go-based Windows destructive backdoor — wipe, fake ransomware, spyware in one binary — attributed to Iran-nexus CyberAv3ngers.

read →
~/articles/2026-07-09-npm-12-install-scripts-off-default-github-gat-deprecation
npm 12 flips install scripts off by default
Analysis
supply chain

npm 12 flips install scripts off by default

npm 12 lands with allowScripts, --allow-git, and --allow-remote all defaulting to none. GitHub is also winding down GATs that skip 2FA. The default just moved.

read →
~/articles/2026-07-09-forg365-phaas-m365-aitm-device-code-zerobec
Forg365 PhaaS Chains AiTM + Device-Code + AI Lures at M365
microsoft

Forg365 PhaaS Chains AiTM + Device-Code + AI Lures at M365

ZeroBEC flagged a new phishing-as-a-service, Forg365, bundling AiTM proxying with OAuth device-code prompts and AI lures against Microsoft 365 accounts.

read →
~/articles/2026-07-09-goddamn-ransomware-poisonx-driver-beast-rebrand
GodDamn ransomware: Beast rebrand, signed EDR-killer driver
ransomware

GodDamn ransomware: Beast rebrand, signed EDR-killer driver

Symantec attributes a new family, GodDamn, as a Beast rebrand shipping the PoisonX driver (g11.sys) — a Microsoft-signed kernel BYOVD used to neutralize endpoint defenses.

read →
~/articles/2026-07-09-microsoft-owa-light-retirement-exchange-server
Microsoft to retire OWA Light in Exchange Server
Analysis
microsoft

Microsoft to retire OWA Light in Exchange Server

Microsoft is disabling OWA Light in an August 2026 Exchange Server update, ending a legacy client shipped when IE6 was current. Admins can disable it today.

read →
~/articles/2026-07-09-interpol-first-light-5811-arrests-293m-seized
INTERPOL First Light 2026: 5,811 arrests, $293M seized
threat intel

INTERPOL First Light 2026: 5,811 arrests, $293M seized

INTERPOL's Operation First Light 2026 arrested 5,811 fraud suspects across 97 countries, seized $293M and blocked 31,014 accounts over 3.5 months.

read →
~/articles/2026-07-09-ai-now-friendly-fire-claude-code-codex-review-exploit
Friendly Fire: agents review the trap, then execute it
Analysis
threat intel

Friendly Fire: agents review the trap, then execute it

AI Now Institute researchers show autonomous Claude Code and Codex can be tricked into running a hidden binary during their own security-review pass.

read →
~/articles/2026-07-09-assuranceamerica-breach-6-9m-drivers-march-intrusion
AssuranceAmerica breach: 6.9M drivers, 4-month notice gap
threat intel

AssuranceAmerica breach: 6.9M drivers, 4-month notice gap

AssuranceAmerica confirms a March 16 intrusion exposed data on 6,998,886 drivers. Notification letters went out in July — a nearly four-month gap between detection and public notice.

read →
~/articles/2026-07-09-infoblox-lurking-lizard-230-domain-fake-7zip-residential-proxy
Infoblox: Lurking Lizard runs 230-domain fake 7-Zip proxy
threat intel

Infoblox: Lurking Lizard runs 230-domain fake 7-Zip proxy

Infoblox ties a China-based residential-proxy operator to 230+ lookalike domains active since 2022, seeding fake 7-Zip and WireVPN installers.

read →
~/articles/2026-07-09-microsoft-defender-rogueplanet-cve-2026-50656-lpe-patch
Microsoft patches Defender 'RoguePlanet' LPE; PoC public
microsoft

Microsoft patches Defender 'RoguePlanet' LPE; PoC public

Microsoft shipped an out-of-band Defender engine update for RoguePlanet (CVE-2026-50656), a race-condition LPE to SYSTEM. Public PoC. Verify auto-update landed.

read →
~/articles/2026-07-09-wiz-ghostapproval-symlink-six-ai-coding-assistants
GhostApproval symlink bug hits six AI coding assistants
threat intel

GhostApproval symlink bug hits six AI coding assistants

Wiz research: Amazon Q, Cursor, Claude Code, Augment, Antigravity, Windsurf all approved one file path in the dialog while writing to another via symlinks.

read →
~/articles/2026-07-09-simplehelp-cve-2026-48558-oidc-bypass-past-kev-deadline
SimpleHelp OIDC Auth Bypass Past CISA Deadline: Patch Now
simplehelp

SimpleHelp OIDC Auth Bypass Past CISA Deadline: Patch Now

SimpleHelp Server 5.5.15 and earlier accept forged OIDC tokens as valid technician sessions. CVSS 10.0, KEV, patch is 5.5.16 — CISA deadline was July 2.

read →
~/articles/2026-07-08-redwing-android-maas-oblivion-telegram-zimperium
RedWing turns Android bank fraud into a Telegram rental
Analysis
mobile

RedWing turns Android bank fraud into a Telegram rental

Zimperium's zLabs details RedWing, an Android bank-fraud MaaS sold on Telegram — Oblivion variant, subscription tiers, prebuilt droppers, 82 target banks.

read →
~/articles/2026-07-08-spain-palencia-carr-noname-logistics-arrest
Spain arrests suspected CARR logistics operator
Analysis
threat intel

Spain arrests suspected CARR logistics operator

Spanish police detained a Palencia man tied to CyberArmy of Russia Reborn, Z-Pentest, and NoName057(16). The announcement lands nearly four months after the raid.

read →
~/articles/2026-07-08-writeout-writer-ai-cross-tenant-session-sand-security
WriteOut: One Preview Link Took Over Writer AI Accounts
cloud

WriteOut: One Preview Link Took Over Writer AI Accounts

SAND Security's WriteOut let a Writer AI agent preview link steal a signed-in user's session cookie across tenants. Writer has patched — the pattern hasn't.

read →
~/articles/2026-07-08-mount-royal-university-cmd-organization-30-btc-breach
Mount Royal University confirms June breach, 30 BTC demand
ransomware

Mount Royal University confirms June breach, 30 BTC demand

Mount Royal University confirms a June 17 intrusion exfiltrated H drive data. A group calling itself CMD demands 30 BTC before the stated leak deadline.

read →
~/articles/2026-07-08-socket-paysafe-skrill-npm-pypi-fake-sdks
Socket: 17 fake Paysafe, Skrill, Neteller SDKs on npm and PyPI
supply chain

Socket: 17 fake Paysafe, Skrill, Neteller SDKs on npm and PyPI

Socket disclosed 17 malicious packages posing as Paysafe, Skrill, and Neteller SDKs across npm and PyPI. Payload steals payment API keys, AWS keys, and GitHub/npm tokens.

read →
~/articles/2026-07-08-iris-c2-krebs-wohl-burkman-zero-day-broker
Krebs traces zero-day broker IRIS C2 to Wohl and Burkman
Analysis
threat intel

Krebs traces zero-day broker IRIS C2 to Wohl and Burkman

Krebs ties IRIS C2, an offensive-security startup pitching zero-day acquisition, to Jacob Wohl and Jack Burkman — both convicted of felony fraud.

read →
~/articles/2026-07-08-sophos-coding-agents-tripping-edr-attacker-detections
Sophos: Coding Agents Are Tripping the Attacker Detections
Analysis
threat intel

Sophos: Coding Agents Are Tripping the Attacker Detections

Seven days of Sophos endpoint telemetry: Claude Code, Cursor, and Codex trip the same rules built to catch attackers — because behaviorally, they should.

read →
~/articles/2026-07-08-pink-o-unc-066-entra-passkey-vishing-okta-unit42
Pink Vishing Enrolls Rogue Entra Passkeys on M365 Tenants
microsoft

Pink Vishing Enrolls Rogue Entra Passkeys on M365 Tenants

Okta and Unit 42 attribute an ongoing vishing campaign — active since April — that walks Microsoft 365 users through enrolling a passkey the attacker controls.

read →
~/articles/2026-07-08-hallusquatting-npm-ai-hallucinated-packages-tel-aviv
HalluSquatting weaponizes AI-hallucinated npm packages
supply chain

HalluSquatting weaponizes AI-hallucinated npm packages

Tel Aviv researchers register the fake package names AI coding assistants keep inventing. Up to 100% hit rate on skill installs, no confirmed exploitation yet.

read →
~/articles/2026-07-08-copilot-workflow-jailbreak-arxiv-kumar-maple
Refused in Chat, Written in Code: Copilot's Workflow Gap
Analysis
threat intel

Refused in Chat, Written in Code: Copilot's Workflow Gap

Kumar and Maple's new arXiv preprint says Copilot's Claude and Gemini backends refused harmful prompts in chat but produced them 816-for-816 in a workflow.

read →
~/articles/2026-07-08-scmbanker-elastic-ref6045-mexican-banking-fraud
SCMBANKER active against Mexican banks — Elastic REF6045
threat intel

SCMBANKER active against Mexican banks — Elastic REF6045

Elastic Security Labs is tracking SCMBANKER (REF6045), a PowerShell fraud toolkit hitting Mexican banks, fintechs, and crypto exchanges via ClickFix lures.

read →
~/articles/2026-07-08-github-verified-commit-hash-malleability-ginesin
A signed Git commit's hash is not a unique fingerprint
Analysis
supply chain

A signed Git commit's hash is not a unique fingerprint

Carnegie Mellon research shows a signed Git commit can be re-minted with a different hash but the same 'Verified' badge — no signing key required, no code changed.

read →
~/articles/2026-07-08-kddi-japan-isp-breach-12m-third-party-zero-day
KDDI Breach: 12M Emails, 7.6M Passwords via 3rd-Party 0day
threat intel

KDDI Breach: 12M Emails, 7.6M Passwords via 3rd-Party 0day

KDDI says a May 16 zero-day in unnamed third-party software exposed 12,233,087 email addresses and 7,616,173 passwords across five Japanese ISPs.

read →
~/articles/2026-07-08-gitlost-github-agentic-workflows-noma-security-private-repos
GitLost: Public Issue Leaks Private GitHub Repo Data
cloud

GitLost: Public Issue Leaks Private GitHub Repo Data

Noma Security's GitLost shows how a public GitHub issue can trick Agentic Workflows into leaking private repos. Not patchable — scope your agent tokens today.

read →
~/articles/2026-07-08-cisa-coldfusion-cve-2026-48282-kev-friday-deadline
CISA: Patch ColdFusion CVE-2026-48282 by Friday
adobe

CISA: Patch ColdFusion CVE-2026-48282 by Friday

CISA added Adobe ColdFusion CVE-2026-48282 to KEV on July 7 and set a July 10 federal patch deadline under BOD 26-04. CVSS 10.0. Actively exploited.

read →
~/articles/2026-07-08-ubiquiti-unifi-connect-command-injection-cve-2026-50746
Ubiquiti Patches Max-Severity UniFi Connect Command Injection
ubiquiti

Ubiquiti Patches Max-Severity UniFi Connect Command Injection

Ubiquiti Bulletin 066 patches seven critical UniFi flaws, headlined by a CVSS 10.0 command injection in UniFi Connect 3.4.16 and earlier. Fix: 3.4.20 or later.

read →
~/articles/2026-07-08-dialogflow-cx-rogue-agent-shared-exec-varonis
Dialogflow's Rogue Agent Flaw Is a Very Old Bug Class
Analysis
cloud

Dialogflow's Rogue Agent Flaw Is a Very Old Bug Class

Varonis' Rogue Agent finding in Google Dialogflow CX is a shared-runtime exec() escape — a bug class old enough to have graduated shared hosting.

read →
~/articles/2026-07-08-ghostlock-linux-kernel-cve-2026-43499-container-escape
GhostLock: 15-Year Linux Kernel Root/Container Escape
linux kernel

GhostLock: 15-Year Linux Kernel Root/Container Escape

Nebula Security's GhostLock (CVE-2026-43499) — a 15-year-old futex use-after-free — hits every mainstream Linux distro. Escapes containers. Patch again.

read →
~/articles/2026-07-08-debull-m365-device-code-phishing-storm-2372-overlap
DEBULL Kit Runs M365 Device-Code Phishing, Storm-2372
microsoft

DEBULL Kit Runs M365 Device-Code Phishing, Storm-2372

ZeroBEC reports DEBULL — a device-code phishing kit repackaging Storm-2372 tradecraft — active against M365 tenants late June to early July. Block it.

read →
~/articles/2026-07-08-cisa-kev-langflow-joomla-page-builder-adds
CISA Adds Langflow and Two Joomla Builders to KEV
threat intel

CISA Adds Langflow and Two Joomla Builders to KEV

CISA added three vulnerabilities to KEV on July 7 — a Langflow IDOR and two Joomla page-builder RCEs. Federal due date is July 10. Priority order below.

read →
~/articles/2026-07-08-unk-masstraction-china-cluster-roundcube-universities
Proofpoint: China cluster raids university physics mail
Analysis
threat intel

Proofpoint: China cluster raids university physics mail

Proofpoint attributes a Roundcube-exploitation campaign against U.S. and Canadian university physics departments to a China-aligned cluster, UNK_MassTraction.

read →
~/articles/2026-07-07-uat-7810-longleash-orb-network-ruckus-asus
China-Linked UAT-7810 Expands ORB Net With LONGLEASH
threat intel

China-Linked UAT-7810 Expands ORB Net With LONGLEASH

Cisco Talos ties China-aligned UAT-7810 to LONGLEASH backdoor and an expanding ORB relay network built on unpatched Ruckus and ASUS routers.

read →
~/articles/2026-07-08-scattered-spider-windows-device-id-court-filing-stokes
Windows Device ID trail led FBI to Scattered Spider suspect
Analysis
threat intel

Windows Device ID trail led FBI to Scattered Spider suspect

A newly unsealed federal complaint says a Microsoft-recorded device ID tied the account behind a Scattered Spider intrusion to 19-year-old Peter Stokes.

read →
~/articles/2026-07-07-tenda-router-backdoor-cve-2026-11405-unpatched
Tenda Router Backdoor Has No Patch. Here's What to Do.
ics ot

Tenda Router Backdoor Has No Patch. Here's What to Do.

CERT/CC flagged an authentication backdoor in multiple Tenda router firmware builds. Tenda didn't respond. No fix is coming — here's the mitigation.

read →
~/articles/2026-07-07-accenture-confirms-breach-source-code-claim
Accenture Confirms Breach; Attacker Claims 35 GB Stolen
threat intel

Accenture Confirms Breach; Attacker Claims 35 GB Stolen

Accenture confirmed a security incident. A threat actor is advertising 35 GB of alleged source code for sale. The volume claim is unverified — treat accordingly.

read →
~/articles/2026-07-07-januscape-cve-2026-53359-kvm-guest-host-escape
Januscape (CVE-2026-53359): 16-year KVM guest-to-host escape
linux kernel

Januscape (CVE-2026-53359): 16-year KVM guest-to-host escape

A 16-year-old use-after-free in KVM's shadow MMU lets a guest VM panic — or, with an unreleased exploit, root — the host on Intel and AMD. Patched June 19.

read →
~/articles/2026-07-07-beyondtrust-remote-support-pra-auth-bypass
BeyondTrust Patches Four RS/PRA Flaws — Patch Now
beyondtrust

BeyondTrust Patches Four RS/PRA Flaws — Patch Now

BeyondTrust shipped fixes on July 6 for four vulnerabilities in Remote Support and Privileged Remote Access, including a CVSS 9.8 pre-auth bypass. No in-wild exploitation reported. Here's the priority order.

read →
~/articles/2026-07-06-gitea-docker-cve-2026-20896-header-auth-bypass
Gitea Docker's Auth Bypass: Probing Already Underway
gitea

Gitea Docker's Auth Bypass: Probing Already Underway

The Gitea Docker image up through 1.26.2 shipped a wildcard reverse-proxy trusted list, collapsing auth to a header. Fixed in 1.26.3. The Hacker News reports opportunistic scanning 13 days after disclosure; ~6,200 exposed instances.

read →
~/articles/2026-07-06-trojpix-air-gap-video-cable-emanation-shandong
TrojPix: air-gap exfil via video-cable RF emanation
Analysis
ics ot

TrojPix: air-gap exfil via video-cable RF emanation

Shandong University researchers show a covert-channel technique that turns invisible pixel changes into a radio signal a nearby receiver can decode from the display cable itself.

read →
~/articles/2026-07-06-adobe-coldfusion-cve-2026-48282-active-exploitation
Adobe ColdFusion CVE-2026-48282: CVSS 10, Exploited
adobe

Adobe ColdFusion CVE-2026-48282: CVSS 10, Exploited

A max-severity unauthenticated path-traversal-to-RCE in ColdFusion 2023 and 2025 is under active attack. Adobe's 72-hour patch window has already passed. Shadowserver counts ~800 exposed instances.

read →
~/articles/2026-07-06-operation-dragonreturn-china-nexus-dcrat-india-tax
DragonReturn Drops DcRAT on Indian Taxpayers
threat intel

DragonReturn Drops DcRAT on Indian Taxpayers

Seqrite Labs attributes an ongoing spear-phishing campaign against Indian tax filers to a suspected China-nexus actor with infrastructure and tactical overlap to Silver Fox. First observed May 18.

read →
~/articles/2026-07-06-gitlab-exiftool-rce-cve-2021-22205
GitLab's ExifTool RCE Sat Unrecognized for Months
Explainer
gitlab

GitLab's ExifTool RCE Sat Unrecognized for Months

CVE-2021-22205 was quietly fixed in April 2021 — but its full unauthenticated remote-code-execution severity wasn't widely understood until late 2021, by which point mass exploitation had already begun.

read →
~/articles/2026-07-06-quimarat-java-cross-platform-maas-levelblue
QuimaRAT: A $150 Cross-Platform Java RAT MaaS
threat intel

QuimaRAT: A $150 Cross-Platform Java RAT MaaS

LevelBlue profiled a new cross-platform Java RAT sold as MaaS. No confirmed campaigns yet — but the price is low, the payload runs everywhere, and the loader is built to walk past SmartScreen. Assume it lands somewhere soon.

read →
~/articles/2026-07-06-opera-gx-mods-auto-install-flaw-patched
Opera GX Patches Auto-Install Mods Flaw
browser

Opera GX Patches Auto-Install Mods Flaw

Opera fixed a flaw that let a malicious website force-install a GX Mod and use CSS injection to lift data from pages you visited. Patched; no CVE; no in-wild exploitation reported.

read →
~/articles/2026-07-06-skillcloak-scanners-miss-agent-skill-malware-hkust
SkillCloak: Scanners Miss 90%+ of Skill Malware
supply chain

SkillCloak: Scanners Miss 90%+ of Skill Malware

HKUST researchers show static scanners for AI agent skill marketplaces miss over 90% of malware repackaged with simple tricks. If you rely on them, that gate is broken.

read →
~/articles/2026-07-05-flipper-zero-firmware-maintenance-only-community-driven
Flipper Zero Firmware Goes Maintenance-Only
threat intel

Flipper Zero Firmware Goes Maintenance-Only

Flipper Devices says the Flipper Zero firmware is stable at 1.0 and full-time feature work is over. Community PRs run the future, filtered through GitHub Discussions voting and stricter review. Here's what changes.

read →
~/articles/2026-07-05-barracuda-esg-zero-day-cve-2023-2868
Barracuda Told Customers to Replace ESG Appliances
Analysis
barracuda

Barracuda Told Customers to Replace ESG Appliances

CVE-2023-2868 was exploited as a zero-day for roughly seven months before discovery — and left some compromised appliances backdoored even after the software patch was applied.

read →
~/articles/2026-07-05-jfrog-rollup-polyfill-npm-six-packages-follow-up
Four More Rollup Polyfill Typosquats Surface
supply chain

Four More Rollup Polyfill Typosquats Surface

JFrog's disclosure names six npm packages in the Rollup polyfill typosquat cluster, not two. The extra four sit inside the same infrastructure the earlier reporting described, and the audit surface hasn't moved.

read →
~/articles/2026-07-05-winrar-path-traversal-cve-2023-38831
WinRAR Bug Hid a Malicious Script in a Fake Photo
Explainer
rarlab

WinRAR Bug Hid a Malicious Script in a Fake Photo

CVE-2023-38831 let a booby-trapped archive execute code when a user clicked what looked like a harmless image file — exploited against trading forums before the technical details were widely known.

read →
~/articles/2026-07-04-metasploit-weekly-smb-meterpreter-peyara-detection
Metasploit's July 3 Drop: SMB-to-Meterpreter, Peyara
threat intel

Metasploit's July 3 Drop: SMB-to-Meterpreter, Peyara

Rapid7 shipped an SMB-to-Meterpreter session upgrade and a Peyara Remote Mouse RCE module this week. Neither is novel research. Both change what your alerts will look like. Here's the tune.

read →
~/articles/2026-07-04-kairos-1m-extortion-payment-us-government-ransom-isac
Kairos Took $1M — and Never Encrypted a File
ransomware

Kairos Took $1M — and Never Encrypted a File

Ransom-ISAC's new case study confirms a ~$1M payment (9.44 BTC) to the Kairos crew on June 13, 2025. Krishnan's review found no encryption at any point — data-theft extortion only, tracked in ransomware feeds anyway.

read →
~/articles/2026-07-04-vmware-vcenter-vsphere-client-rce-cve-2021-21972
vCenter's Upload Bug: Don't Expose Management Planes
Explainer
vmware

vCenter's Upload Bug: Don't Expose Management Planes

CVE-2021-21972 let unauthenticated attackers execute code with root privileges on VMware vCenter Server — and internet scans found tens of thousands of instances exposed anyway, against VMware's own guidance.

read →
~/articles/2026-07-04-bluehammer-defender-lpe-kev-ransomware-confirmed
BlueHammer Defender LPE Now Used in Ransomware
microsoft

BlueHammer Defender LPE Now Used in Ransomware

CVE-2026-33825, the Microsoft Defender local privilege escalation disclosed as a zero-day by 'Chaotic Eclipse' in April, is confirmed weaponized in ransomware. Patched. Ransomware family unnamed.

read →
~/articles/2026-07-04-polinrider-108-dprk-packages-contagious-interview
PolinRider: DPRK Seeds 108 Malicious Packages
supply chain

PolinRider: DPRK Seeds 108 Malicious Packages

The Hacker News reports 108 malicious npm, Packagist, Go, and Chrome extension listings tied to the DPRK Contagious Interview cluster. Here's what a dev shop actually does about it this week.

read →
~/articles/2026-07-04-spring4shell-vmware-spring-framework-rce
Spring4Shell: Why This One Needed Careful Triage, Not Panic
Explainer
vmware

Spring4Shell: Why This One Needed Careful Triage, Not Panic

CVE-2022-22965 leaked publicly before VMware's patch was ready — but unlike Log4Shell, exploitation required a specific combination of conditions that made blanket panic the wrong response.

read →
~/articles/2026-07-04-orchid-iga-ai-agents-lifecycle-gaps
IGA Was Built Around Employment Records, Not Agents
Analysis
threat intel

IGA Was Built Around Employment Records, Not Agents

A contributed piece to The Hacker News from Orchid Security lays out where the joiner-mover-leaver model quietly fails for AI agents. Vendor-adjacent, but the gap analysis holds.

read →
~/articles/2026-07-04-avalon-crownx-modular-malware-framework
Avalon Framework Bundles Theft, Wiper, CrownX
ransomware

Avalon Framework Bundles Theft, Wiper, CrownX

Blackpoint Cyber says the previously undocumented Avalon framework combines credential theft, EDR-aware defense evasion, shadow-copy destruction, and the CrownX ransomware payload in one multi-stage phishing chain.

read →
~/articles/2026-07-04-toddycat-umbrij-oauth-gmail-kaspersky
Umbrij: ToddyCat Hijacks Gmail OAuth via Browser
cloud

Umbrij: ToddyCat Hijacks Gmail OAuth via Browser

Kaspersky Securelist detailed Umbrij, a ToddyCat post-compromise tool that self-grants Google Workspace OAuth tokens by driving a logged-in Chromium session. Nothing to patch. Plenty to audit.

read →
~/articles/2026-07-04-artoken-eviltokens-m365-device-code-phishing-talos
ARToken PhaaS Targets M365 Device-Code Phishing
cloud

ARToken PhaaS Targets M365 Device-Code Phishing

Cisco Talos exposed ARToken, a React-panel phishing-as-a-service tied to EvilTokens. Device code flow is the mechanic. Conditional Access is the fix, and most tenants still haven't turned it on.

read →
~/articles/2026-07-04-talos-catan-and-mouse-curiosity-defensive-skill
Talos on Curiosity: A Skill That Doesn't Scale
Analysis
threat intel

Talos on Curiosity: A Skill That Doesn't Scale

William Largent's Threat Source column this week reads as an essay on board games and pattern recognition. It's really an argument about the load-bearing skill that keeps a defender from becoming a checklist.

read →
~/articles/2026-07-04-armored-likho-busysnake-power-sector-kaspersky
Armored Likho Ties BusySnake to Power-Sector Spying
ics ot

Armored Likho Ties BusySnake to Power-Sector Spying

Kaspersky attributes a previously undocumented threat actor, Armored Likho, to a campaign hitting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan using the BusySnake stealer.

read →
~/articles/2026-07-04-consentfix-clickfix-m365-oauth-consent-phishing
ConsentFix + ClickFix: M365 Grants Outlive Resets
cloud

ConsentFix + ClickFix: M365 Grants Outlive Resets

BleepingComputer covered two M365 hijack patterns and Opera's Paste Protect defense this week. The clipboard lane can be closed. The OAuth grant substrate underneath is unchanged.

read →
~/articles/2026-07-03-fortibleed-inc-lynx-ransomware-attribution
FortiBleed Tied to INC and Lynx Ransomware Crews
ransomware

FortiBleed Tied to INC and Lynx Ransomware Crews

The Hacker News reports an operator behind FortiBleed's credential-theft infrastructure was seen running ransomware negotiation panels for both INC and Lynx. Not a resale ring — a pipeline.

read →
~/articles/2026-07-03-pegasus-mep-kouloglou-citizen-lab-analysis
Pegasus on the MEP investigating Pegasus
Analysis
mobile

Pegasus on the MEP investigating Pegasus

Citizen Lab's forensic analysis found that former European Parliament member Stelios Kouloglou was repeatedly infected with NSO Group's Pegasus spyware while serving on the committee tasked with investigating that industry.

read →
~/articles/2026-07-03-chocopoc-rat-fake-poc-github-pypi-yeswehack
ChocoPoC: Fake CVE PoC Repos Ship a Stealer
supply chain

ChocoPoC: Fake CVE PoC Repos Ship a Stealer

YesWeHack and Sekoia disclosed a stealer campaign hiding inside GitHub PoC repos and PyPI packages, targeting the researchers who clone them. Treat every fresh 'PoC for hot CVE' repo as hostile until you've read every dependency.

read →
~/articles/2026-07-03-fatfs-runzero-seven-flaws-embedded-firmware
runZero Discloses Seven FatFs Firmware Flaws
supply chain

runZero Discloses Seven FatFs Firmware Flaws

runZero disclosed seven vulnerabilities in FatFs, a small filesystem library shipped inside ESP-IDF, STM32Cube, Zephyr, MicroPython, and other embedded stacks. Only one has an upstream fix.

read →
~/articles/2026-07-03-sysdig-jadepuffer-ai-agent-langflow-ransomware
Sysdig: JADEPUFFER ran a full ransomware chain from one LLM
ransomware

Sysdig: JADEPUFFER ran a full ransomware chain from one LLM

Sysdig's Threat Research Team says JADEPUFFER is the first ransomware incident it has observed where an AI agent handled entry, credential theft, lateral movement, and destruction end-to-end. Initial access was a Langflow code-execution flaw.

read →
~/articles/2026-07-03-bad-epoll-linux-kernel-lpe-cve-2026-46242
Bad Epoll: Linux Kernel LPE Also Hits Android
linux kernel

Bad Epoll: Linux Kernel LPE Also Hits Android

A newly disclosed use-after-free in Linux 6.4+ kernels lets an unprivileged local user gain root. Android on affected kernels is in scope; the upstream fix is in.

read →
~/articles/2026-07-03-pamstealer-macos-maccy-impersonation-jamf
PamStealer: A Fake Maccy Site Steals macOS Creds
threat intel

PamStealer: A Fake Maccy Site Steals macOS Creds

Jamf Threat Labs disclosed a new macOS credential stealer today that impersonates the Maccy clipboard app, validates the victim's login password against PAM in real time, and exfiltrates keychain and browser data. Apple Silicon only. Here's what defenders should do.

read →
~/articles/2026-07-03-avalon-crownx-modular-malware-framework
Blackpoint: Avalon Bundles Theft, Wiper, CrownX
ransomware

Blackpoint: Avalon Bundles Theft, Wiper, CrownX

Blackpoint Cyber documents Avalon, a previously undocumented modular framework whose ransomware payload — CrownX — arrives at the end of a legal-lure phishing chain that stages through Proton Drive, ISO, LNK, and MSBuild.

read →
~/articles/2026-07-03-cisco-unified-cm-active-exploitation-confirmed
Cisco Confirms Active Exploitation of Unified CM Flaw
cisco

Cisco Confirms Active Exploitation of Unified CM Flaw

Cisco updated its Unified Communications Manager advisory this week to state attackers are exploiting the flaw in the wild. Patched builds have been out for a month. If yours isn't on one, that's the whole conversation.

read →
~/articles/2026-07-03-argo-cd-repo-server-unauth-rce-unpatched
Unpatched Argo CD Flaw Lets Unauth Cluster Takeover
cloud

Unpatched Argo CD Flaw Lets Unauth Cluster Takeover

Synacktiv disclosed an unpatched code-execution flaw in Argo CD's repo-server component. No fix, no CVE. Reachability of the internal port is the whole game.

read →
~/articles/2026-07-03-dprk-npm-rollup-polyfill-supply-chain
DPRK npm Packages Impersonate a Rollup Polyfill
Analysis
supply chain

DPRK npm Packages Impersonate a Rollup Polyfill

JFrog links two new malicious npm packages — impersonating a Rollup polyfill project down to its metadata — to a DPRK cluster after developer secrets and remote access.

read →
~/articles/2026-07-03-anubis-ransomware-citrix-bleed-2-cve-2025-5777
Anubis Ransomware Exploits Citrix Bleed 2
ransomware

Anubis Ransomware Exploits Citrix Bleed 2

The Hacker News reports Anubis-ransomware affiliates using Citrix Bleed 2 (CVE-2025-5777) to breach NetScaler-fronted environments, then pivoting with legit RMM, BYOVD, and stolen supply-chain credentials.

read →
~/articles/2026-07-03-confluence-ognl-injection-cve-2022-26134
The Confluence Bug That Became a Ransomware Precursor
Explainer
atlassian

The Confluence Bug That Became a Ransomware Precursor

CVE-2022-26134 gave unauthenticated attackers remote code execution on any exposed Confluence instance — and became a go-to foothold for ransomware operators within days of disclosure.

read →
~/articles/2026-07-03-fortios-fortiproxy-auth-bypass-cve-2022-40684
FortiOS Auth Bypass: Fortinet Warned Select Customers
Explainer
fortinet

FortiOS Auth Bypass: Fortinet Warned Select Customers

CVE-2022-40684 let attackers bypass authentication on FortiOS and FortiProxy management interfaces and plant persistent SSH keys — Fortinet quietly warned targeted customers before public disclosure.

read →
~/articles/2026-07-03-kemp-loadmaster-cve-2026-8037-pre-auth-rce
Kemp LoadMaster Pre-Auth RCE: PoC Is Out, Patch Now
progress

Kemp LoadMaster Pre-Auth RCE: PoC Is Out, Patch Now

A functional proof-of-concept for a critical pre-auth RCE in Progress Kemp LoadMaster hit the internet on June 29 and eSentire started seeing exploitation attempts the same day. Progress's fix has been available since June 4.

read →
~/articles/2026-07-03-fbi-netnut-popa-botnet-takedown
FBI Seizes NetNut Proxy, Google Degrades Popa Botnet
threat intel

FBI Seizes NetNut Proxy, Google Degrades Popa Botnet

The FBI seized hundreds of NetNut proxy domains on July 2; Google's Threat Intelligence Group, working with FBI and Lumen, cut the linked Popa botnet's usable device pool by millions the same day.

read →
~/articles/2026-07-03-sharepoint-cve-2026-45659-kev-active-exploitation
SharePoint RCE now on CISA KEV: patch it this week, not next
microsoft

SharePoint RCE now on CISA KEV: patch it this week, not next

CISA added CVE-2026-45659, a high-severity SharePoint Server deserialization RCE, to the Known Exploited Vulnerabilities catalog on July 2 after confirming active exploitation. Microsoft's May patch is your remediation.

read →
~/articles/2026-07-02-f5-big-ip-icontrol-rest-auth-bypass
F5 BIG-IP's Max-Severity Auth Bypass, Explained
Explainer
f5

F5 BIG-IP's Max-Severity Auth Bypass, Explained

A critical authentication-bypass flaw in F5 BIG-IP's iControl REST API let unauthenticated attackers execute system commands on appliances that front an enormous share of enterprise application traffic.

read →
~/articles/2026-07-02-follina-msdt-zero-day-explained
Follina: The MSDT Bug That Skipped Macro Warnings
Explainer
microsoft

Follina: The MSDT Bug That Skipped Macro Warnings

CVE-2022-30190 let a Word document trigger arbitrary code execution through the Windows Support Diagnostic Tool — no macros, and in some configurations no explicit click required beyond opening the file.

read →
~/articles/2026-07-01-mshtml-office-zero-day-cve-2021-40444
The MSHTML Zero-Day That Weaponized a Word Doc
Explainer
microsoft

The MSHTML Zero-Day That Weaponized a Word Doc

CVE-2021-40444 let attackers execute arbitrary code through a malicious Office document with no macros required — exploited in the wild before Microsoft's patch existed.

read →
~/articles/2026-07-01-proxylogon-exchange-server-attack-chain
ProxyLogon: Inside the Exchange Server Attack Chain
Analysis
microsoft

ProxyLogon: Inside the Exchange Server Attack Chain

CVE-2021-26855 and three chained Exchange Server bugs gave attackers unauthenticated remote code execution — and led to a compromise event so widespread the FBI obtained a court order to remove webshells itself.

read →
~/articles/2026-06-30-printnightmare-windows-print-spooler-explained
PrintNightmare: A Leaked PoC Forced an Emergency Patch
Explainer
microsoft

PrintNightmare: A Leaked PoC Forced an Emergency Patch

CVE-2021-34527 let attackers turn the Windows Print Spooler service — running by default on nearly every Windows machine — into a path to SYSTEM privileges or full domain compromise.

read →
~/articles/2026-06-30-log4shell-log4j-anniversary-explainer
Log4Shell, Explained: The Internet's Worst Week
Explainer
apache

Log4Shell, Explained: The Internet's Worst Week

CVE-2021-44228 turned a single misused feature in Apache Log4j2 — a Java logging library embedded almost everywhere — into one of the most widely exploited vulnerabilities ever recorded.

read →
~/articles/2026-06-28-outlook-monikerlink-rce-patch-tuesday-explainer
Outlook MonikerLink Bug Bypasses Protected View
Explainer
microsoft

Outlook MonikerLink Bug Bypasses Protected View

CVE-2024-21413 let attackers bypass Outlook's Protected View sandbox with a single specially crafted hyperlink, leading to code execution and potential credential leakage. Patched in February 2024's Patch Tuesday.

read →
~/articles/2026-06-27-pan-os-globalprotect-command-injection-zero-day
PAN-OS GlobalProtect Zero-Day Gave Attackers Root
Explainer
palo alto networks

PAN-OS GlobalProtect Zero-Day Gave Attackers Root

CVE-2024-3400, a maximum-severity command-injection flaw in Palo Alto Networks' PAN-OS GlobalProtect feature, was exploited in the wild before a patch existed — handing attackers root access to the perimeter firewall.

read →
~/articles/2026-06-26-ivanti-connect-secure-chained-zero-days-explained
Inside Ivanti Connect Secure's Chained Zero-Days
Explainer
ivanti

Inside Ivanti Connect Secure's Chained Zero-Days

CVE-2023-46805 and CVE-2024-21887, chained together, gave a suspected nation-state actor unauthenticated remote code execution on Ivanti Connect Secure and Policy Secure VPN gateways for weeks before patches.

read →
~/articles/2026-06-25-citrix-bleed-netscaler-session-hijacking-explained
Citrix Bleed: A Memory Leak That Bypassed MFA
Explainer
citrix

Citrix Bleed: A Memory Leak That Bypassed MFA

CVE-2023-4966, known as Citrix Bleed, let attackers pull live session tokens straight out of NetScaler ADC and Gateway memory — hijacking already-authenticated sessions without needing a password or MFA code.

read →
~/articles/2026-06-24-cisco-ios-xe-web-ui-zero-day-mass-exploitation
Cisco IOS XE Web UI Zero-Day: Mass Exploitation
Explainer
cisco

Cisco IOS XE Web UI Zero-Day: Mass Exploitation

CVE-2023-20198, a maximum-severity privilege-escalation flaw in Cisco IOS XE's web management interface, was exploited at mass scale before a patch existed — handing attackers full admin control of network infrastructure.

read →