HOT NEWS 2026 JULY  January(174) February(168) March(221) April(222) May(261) June(255) July(464) August(10) September(0) October(0) November(0) December(0) | STATISTICS (7049)

DATE

NAME

INFO

CATEGORY

SUBCATE

31.7.26

VPS.org one-click deployment templates contain multiple vulnerabilities VPS.org's one-click deployment templates provision services with default passwords and predefined network bindings instead of generating randomized secrets or applying per-deployment hardening measures. ALERT ALERT

31.7.26

Understanding Implicit Trust Errors in Core Carrier Networks through
Multi-Agent Flaw Discovery and Analysis
Cellular core networks (CNs) are critical infrastructure, yet their internal security model has historically relied on physical isolation: interfaces between core components often operate within an assumed trust zone. As CNs transition to cloud-native deployments, this assumption weakens, expanding the attack surface and enabling external adversaries to reach previously internal interfaces. PAPERS PAPERS

31.7.26

CVE-2026-4368 Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mixup VULNEREBILITY VULNEREBILITY

31.7.26

CVE-2026-3055 Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread VULNEREBILITY VULNEREBILITY

31.7.26

CVE-2026-8233 A vulnerability was determined in Dotouch XproUPF 2.0.0-release-088aa7c4. Affected is an unknown function of the component UPF. This manipulation causes improper access controls. A high degree of complexity is needed for the attack. The exploitability is told to be difficult. The vendor was contacted early about this disclosure. VULNEREBILITY VULNEREBILITY

S31.7.26

CVE-2026-3545 Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) VULNEREBILITY VULNEREBILITY

31.7.26

ClickFix, EtherHiding & a DPRK Wallet Trail A fake macOS "update" screen convinced a victim to paste one command into Terminal, installing a Node.js backdoor that takes its orders from an Ethereum smart contract. We reverse-engineered every stage, then followed the money on-chain. HACKING HACKING

31.7.26

Malicious Cyber Actors Targeting Water and Wastewater Sector Internet Facing Programmable Logic Controllers, Causing Operational Disruptions The Federal Bureau of Investigation (FBI) and Environmental Protection Agency (EPA) are issuing this Public Service Announcement (PSA) to warn critical infrastructure asset owners and operators that malicious cyber actors (MCAs) are conducting cyber attacks  targeting Operational Technology (OT) devices, including Rockwell Automation/AllenBradley Programmable Logic Controllers (PLCs), specifically MicroLogix 1100 and 1400 series. IC3 IC3

31.7.26

SGLang contains six different vulnerabilities including RCE, data exfiltration, and credential disclosure Six vulnerabilities have been discovered within the SGLang project, including remote code execution (RCE), server-side request forgery (SSRF), local file read, credential leakage, and model weight exfiltration on a target server. ALERT ALERT

31.7.26

foreUP golf management platform's web API contains multiple vulnerabilities Two vulnerabilities in the REST API were found in Golf Compete foreUP. The first exposes the merchant, Finix, API credentials directly in customer record responses, allowing any user to obtain and use the payment processor account. ALERT ALERT

30.7.26

SilkLurk OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia MALWARE BACKDOOR

30.7.26

OctLurk OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia MALWARE BACKDOOR

30.7.26

Toy Ghouls Toy Ghouls’ new toy: the GenieLocker ransomware RANSOM RANSOM

30.7.26

Toy Ghouls Toy Ghouls’ new toy: the GenieLocker ransomware GROUP GROUP

30.7.26

CosmosEscape CosmosEscape: Taking Over Every Database in Azure Cosmos DB VULNEREBILITY VULNEREBILITY

30.7.26

Certighost Certighost is an Active Directory Certificate Services (AD CS) vulnerability that allowed a low-privileged domain user to impersonate a Domain Controller and achieve domain compromise in the tested AD CS configuration. The issue was addressed in the July 2026 security updates. VULNEREBILITY VULNEREBILITY

30.7.26

Operation Double Barrel This technical analysis report was prepared as part of the joint cybersecurity advisory titled “Advisory on Cyberattacks Targeting Korean Citizens and Businesses by State-Sponsored Hacking Groups,” issued by the Republic of Korea’s National Intelligence Service (NIS), National Police Agency (NPA), Korea Internet & Security Agency (KISA), and Financial Security Institute (FSI). OPERATION OPERATION

30.7.26

SIGNBT Detailed Analysis of SIGNBT Malware Cluster MALWARE CLUSTER

30.7.26

AtlasRAT Not Every Fox is Silver: Inside an AtlasRAT loader chain MALWARE RAT

30.7.26

SilverFox Evolves Cato CTRL™ Threat Research: SilverFox Evolves: Abuse of New Drivers and Trusted Software Hijacking Enable Remote Access with ValleyRAT in Japan GROUP GROUP

30.7.26

TA488 Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit GROUP GROUP

30.7.26

Arbitrary File Overwrite in Develar app-builder (zipx.Unzip) via Symlink Following on macOS (APFS) A vulnerability in the zipx.Unzip extraction routine of Develar’s app-builder allows an attacker to overwrite arbitrary files on macOS using Apple File System (APFS). The issue arises from a combination of Unicode normalization collisions and unsafe symlink-following behavior. APFS treats certain Unicode equivalent filenames as identical (e.g., ß ↔ ss), while app builder performs no canonical normalization before validating or writing paths. ALERT ALERT

30.7.26

OPeNDAP Hyrax is vulnerable to SSRF and Credential Disclosure A vulnerability has been discovered in the OPeNDAP Hyrax software solution. A remote attacker with the ability to submit crafted requests to an affected Hyrax instance could cause the application to communicate with unauthorized remote systems. Under certain conditions, the vulnerability may also result in the unintended disclosure of user authentication tokens to unauthorized destinations. ALERT ALERT

30.7.26

CVE-2026-20316 Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability VULNEREBILITY VULNEREBILITY

30.7.26

CVE-2026-20316 Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability KEV KEV

30.7.26

CVE-2026-47876 Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Application Testing Suite. VULNEREBILITY VULNEREBILITY

30.7.26

CVE-2026-41703 An unauthenticated remote attacker can cause a Denial of Service by turning off the output of the UPS via Modbus command. VULNEREBILITY VULNEREBILITY

30.7.26

CVE-2026-41709 An unauthenticated remote attacker can perform a command injection via Modbus-TCP or Modbus-RTU to gain read and write access on the affected device. VULNEREBILITY VULNEREBILITY

30.7.26

CVE-2026-66066 [CVE-2026-66066] Possible arbitrary file read and remote code execution in Active Storage variant processing VULNEREBILITY VULNEREBILITY

30.7.26

CVE-2026-59726 Unauthenticated RCE in ruflo MCP bridge default docker-compose deployment VULNEREBILITY VULNEREBILITY

29.7.26

2026 Minimum Elements for a Software Bill of Materials (SBOM) The U.S. Cybersecurity and Infrastructure Security Agency (CISA), in partnership with the co-authoring organizations, updated the Minimum Elements for a Software Bill of Materials (SBOM) to reflect current SBOM needs, while preserving the core principles of the document published in 2021 by the National Telecommunications and
Information Administration (NTIA).
IC3 IC3 INDUSTRY

29.7.26

CI Fortify - Advice for isolating vital systems State-sponsored cyber actors routinely target critical infrastructure (CI) to conduct espionage or to pre-position for disruptive and destructive effects in the event of crisis or conflict.4 Cybercriminals continue to opportunistically target CI operators. The sensitivity of the data stored by these entities, and the importance of their services, makes them attractive for cybercriminals seeking to extort victims via data exfiltration or by conducting ransomware attacks for disruptive or destructive purposes IC3 IC3 INDUSTRY

29.7.26

AT&T's Arris BGW210-700 gateway contains authentication bypass vulnerability in LAN-side management interface Firmware versions 2.7.7 and earlier of the Arris BGW210-700 residential gateway contain an authentication bypass vulnerability, tracked as CVE-2026-16771, that allows any unauthenticated LAN-side user to read sensitive configuration data and modify device settings through web management endpoints ALERT ALERT

29.7.26

CVE-2026-10702 JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3. VULNEREBILITY VULNEREBILITY

29.7.26

Flying Eagle Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon MALWARE ANDROID RAT

29.7.26

CVE-2025-60004 An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-Of-Service (DoS). When an affected system receives a specific BGP EVPN update message over an established BGP session, this causes an rpd crash and restart. A BGP EVPN configuration is not necessary to be vulnerable. VULNEREBILITY VULNEREBILITY

29.7.26

CryptanalysisBench: Can LLMs do Cryptanalysis? Cryptanalysis—the task of finding attacks against cryptographic schemes—sits at the intersection of mathematical reasoning and cybersecurity, two areas where LLMs have advanced fastest. PAPERS PAPERS

29.7.26

Cryptanalysis of 7-Round AES via the Algebraic Structure of its S-box The AES S-Box is not a random permutation; we show that its algebraic structure allows for improved attacks on 7 rounds in the single-key setting. We focusour efforts on extending a 2 105 chosen plaintext and 2 99-time algorithm designed by PAPERS PAPERS

29.7.26

HAWK-n Key Recovery Reduces to SVP in Dimension n/2 + 1 HAWK is a lattice signature scheme that is currently a thirdround candidate in NIST’s post-quantum signature competition. We give
an unconditional, deterministic polynomial-time reduction from HAWKn key recovery over Kn = Q(ζ2ℓ ) to poly(n) calls to an exact Shortest Vector Problem (SVP) oracle in dimension n/2 + 1, where n = 2ℓ−1 is the ring degree.
PAPERS PAPERS

29.7.26

HAWK: Having Automorphisms Weakens Key The search rank-2 module Lattice Isomorphism Problem (smLIP), over a cyclotomic ring of degree a power of two, can be reduced to an instance of the Lattice Isomorphism Problem (LIP) of at most half the rank if an adversary knows a nontrivial automorphism of the underlying integer lattice. PAPERS PAPERS

29.7.26

HAWK HAWK is a signature scheme inspired by the introduction of the lattice isomorphism problem (LIP) to signatures [DvW22], and this specification document is based on the article that first described a practical variant [DPPvW22a]. PAPERS PAPERS

29.7.26

Status Report on the Second Round of the Additional Digital Signature Schemes for the NIST Post-Quantum Cryptography Standardization Process The National Institute of Standards and Technology (NIST) initiated the public PostQuantum Cryptography (PQC) Standardization  Process in December 2016 to select  quantum-resistant public-key cryptographic algorithms for standardization in response to the substantial development and advancement of quantum computing. DIRECTION DIRECTION

29.7.26

Status Report on the First Round of the
Additional Digital Signature Schemes for
the NIST Post-Quantum Cryptography
Standardization Process
The National Institute of Standards and Technology (NIST) initiated the public Post-Quantum Cryptography (PQC) Standardization Process in December 2016 to select quantum-resistant public-key cryptographic algorithms for standardization in response to the substantial development and advancement of quantum computing. After three rounds of evaluation and analysis, NIST announced the selection of the first algorithms to be standardized. DIRECTION DIRECTION

29.7.26

Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident A companion technical writeup to our incident disclosure. This post walks through how the intrusion actually worked: the two initial-access vectors, how the agent pivoted and moved laterally, representative examples of the commands that were run and how we investigated with GLM 5.2 (an open-source model). Live credentials, internal hostnames, and specific indicators have been redacted or genericized, while the techniques are described exactly as observed by Hugging Face. INCIDENT AI

29.7.26

DEV#POPPER Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan MALWARE RAT

29.7.26

Tengu Tengu: A Modernized Mirai That Doesn’t Want to Leave BOTNET BOTNET

28.7.26

MedusaHVNC A Hidden Desktop That Steals Live Windows Sessions MALWARE RAT

28.7.26

CVE-2013-4786 The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC. VULNEREBILITY VULNEREBILITY

28.7.26

AutoIT For a long time, AutoIT has been pretty common in the malware ecosystem. Threat actors still use it because it’s easy to write and powerful. Indeed, it can perform all the required actions to inject a payload into a remote process as you’ll see below. MALWARE INJECTOR

28.7.26

CVE-2026-62947 ACL bypass and arbitrary root file read via cgi-io cgi-download VULNEREBILITY VULNEREBILITY

28.7.26

CVE-2026-63921 In the Linux kernel, the following vulnerability has been resolved: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). After patch 1/2 in this series, vti6_update() unlinks and relinks the tunnel through t->net. vti6_siocdevprivate() still uses dev_net(dev) for the collision lookup. VULNEREBILITY VULNEREBILITY

28.7.26

NightLedger backdoor NightLedger is a recently identified Windows backdoor that we attribute to Mirage Kitten based on code and behavioral similarities to the historical implants developed and used by the group. The implant masquerades as SspiCli.dll and appears to be designed for DLL search-order hijacking, targeting a legitimate AppVShNotify.exe binary. MALWARE BACKDOOR

28.7.26

CVE-2026-64739 Apple Libnotify/notifyd Stack Overflow (CVE-2026-64739) — Discovered by ThreatBook XGPT VULNEREBILITY VULNEREBILITY

28.7.26

CyberGym-E2E: Scalable Real-World Benchmark for AI Agents’ End-to-End
Cybersecurity Capabilities
AI has the potential to transform cybersecurity by enabling systems that can autonomously detect, analyze, and remediate software vulnerabilities. However, existing cybersecurity evaluations of AI systems are limited in scale or scope, and fail to capture the end-to-end lifecycle of real-world software vulnerability discovery and remediation PAPERS PAPERS

28.7.26

CYBERGYM: EVALUATING AI AGENTS’ REAL-WORLD CYBERSECURITY CAPABILITIES AT SCALE AI agents have significant potential to reshape cybersecurity, making a thorough assessment of their capabilities critical. However, existing evaluations fall short,
because they are based on small-scale benchmarks and only measure static outcomes, failing to capture the full, dynamic range of  real-world security challenges.
To address these limitations, we introduce CyberGym, a large-scale benchmark
PAPERS PAPERS

28.7.26

CVE-2026-53264 In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: use RCU with deferred freeing for action lifecycle When NEWTFILTER and DELFILTER are run concurrently it is possible to create a race with an associated action. VULNEREBILITY VULNEREBILITY

28.7.26

CVE-2026-63077 In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol VULNEREBILITY VULNEREBILITY

28.7.26

CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability VULNEREBILITY VULNEREBILITY

28.7.26

CVE-2026-16812 Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability VULNEREBILITY VULNEREBILITY

28.7.26

CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability KEV KEV

28.7.26

CVE-2026-16812 Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability KEV KEV

28.7.26

CVE-2025-9528 A vulnerability was determined in Linksys E1700 1.0.0.4.003. This vulnerability affects the function systemCommand of the file /goform/systemCommand. Executing manipulation of the argument command can lead to os command injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. VULNEREBILITY VULNEREBILITY

28.7.26

Dysphoria Dysphoria: A Rising Star in Botnets – Evolution and In-Depth Technical Analysis BOTNET BOTNET

28.7.26

CVE-2026-61511 vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. VULNEREBILITY VULNEREBILITY

27.7.26

DNS Poisoning Tactics DNS Poisoning Tactics Expand to Hospitality Wi-Fi HACKING HACKING

27.7.26

JIVS PhishKit Inside JIVS PhishKit: A Domain-Adaptive Credential Harvester PHISHING KIT

27.7.26

Bypassing n8n's CVE-2026-27577 Breaking the Sandbox Again: Bypassing n8n's CVE-2026-27577 Patch VULNEREBILITY VULNEREBILITY

27.7.26

Operation BlueDash Operation BlueDash: Multi-RMM Workplace Phishing OPERATION OPERATION

27.7.26

[Op Report] From SSA Phish to AdaptixC2: A Multi-RAT Intrusion Over five days in mid-May 2026, an operator engaged a deception workstation in the Deception.Pro environment and executed a near-complete commodity intrusion chain from initial access through domain reconnaissance. OPERATION OPERATION

27.7.26

Cruciferra

Unpacking “Cruciferra”: An Analysis of a Sophisticated Crypter Service

CRYPTOCURRENCY

CRYPTOCURRENCY

27.7.26

TELESHIM

Targeted Attack on Government Entities in the Middle East | Part 1

CAMPAIGN

CAMPAIGN

26.7.26

20th USENIX Symposium
on Operating Systems Design
and Implementation (OSDI ’26)

The full Proceedings published by USENIX for the symposium are available for download below. Individual papers can also be downloaded from their respective presentation pages. Copyright to the individual works is retained by the author[s].

CONGRESS PRESENTATION

CONGRESS PRESENTATION

26.7.26

Slopsquatting Slopsquatting is a type of cybersquatting. It is the practice of registering a non-existent software package name that a large language model (LLM) may hallucinate in its output, whereby someone unknowingly may copy-paste and install the software package without realizing it is fake. Attempting to install a non-existent package should result in an error, but some have exploited this for their gain in the form of typosquatting HACKING Cybersquatting

26.7.26

CVE-2026-12569 A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030 VULNEREBILITY VULNEREBILITY

26.726

CVE-2025-56383 Notepad++ v8.8.3 has a DLL hijacking vulnerability, which can replace the original DLL file to execute malicious code. NOTE: this is disputed by multiple parties because the behavior only occurs when a user installs the product into a directory tree that allows write access by arbitrary unprivileged users. VULNEREBILITY VULNEREBILITY

26.7.26

SourTrade Ad Campaigns SourTrade: Browser-Assembled Malware Delivered Through Malvertising CAMPAIGN CAMPAIGN

25.7.26

The NIST Cybersecurity Framework (CSF) 2.0 The Cybersecurity Framework (CSF) 2.0 is designed to help organizations of all sizes and sectors— including industry, government, academia, and nonprofit — to manage and reduce their cybersecurity risks. It is useful regardless of the maturity level and technical sophistication of an organization’s cybersecurity programs. Nevertheless, the CSF does not embrace a one-size-fitsall approach. DIRECTION DIRECTION

25.7.26

The Gentlemen RaaS The Gentlemen RaaS: Origins, OPSEC & OSINT RANSOM RaaS

25.7.26

Cl0p Exploitation of PTC Windchill & FlexPLM (CVE-2026-12569) A coordinated Unified Threat Advisory covering active Cl0p ransomware affiliate exploitation of internet-exposed PTC Windchill and FlexPLM deployments — chaining a pre-auth FlexPLM WSDL information disclosure with a Windchill login servlet flaw for unauthenticated RCE, JSP webshell deployment, and double-extortion data theft. EXPLOIT EXPLOIT

25.7.26

Fastjson RCE (≤1.2.83): Active Exploitation Detected — Detection & Mitigation A remote code execution vulnerability in Fastjson affects every version up to and including 1.2.83. A remote attacker can run arbitrary code on a vulnerable server by sending it specially crafted JSON — no user privileges, no victim interaction, and no third-party libraries required. ThreatBook TDP® (Threat Detection Platform) has already captured this vulnerability being exploited in the wild, so if you run an affected version without SafeMode enabled, treat remediation as urgent. EXPLOIT EXPLOIT

25.7.26

FastJson 1.2.83 Remote Code Execution Everyone used to treat fastjson 1.2.83 as the safe one. It's the last release of the 1.x line, it ships with AutoType turned off by default, and for years the advice has been "just move to 1.2.83 and you are good." Not anymore! VULNEREBILITY VULNEREBILITY

25.7.26

DevMan Ransomware
Threat Actor Report
In early April 2025, an actor presenting itself as “DevMan” has claimed on X1 to gain access and perform a ransomware attack against the French transport company “doumen”. Since then, the threat actor has proved itself as being highly prolific and was named as one of the top active ransomware attackers in the following months.2 As of July 2025, DevMan has claimed at least 54 victims. REPORT REPORT

25.7.26

DEVMAN Ransomware DEVMAN Ransomware: Analysis of New DragonForce Variant RANSOM RANSOM

25.7.26

Funky Mantis Funky Mantis operates as a centralized ransomware-as-a-service model. Administrators manage affiliates, distribute access, and support extortion through private communications and a dedicated web platform. The platform combines payload building, finance, negotiation, support, and victim management, giving the service control over affiliate access and operational progress. GROUP GROUP

25.7.26

CVE-2026-16723 A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required. VULNEREBILITY VULNEREBILITY

25.7.26

Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite A group of Russian state-supported cyber actors has been targeting and compromisingvarious Western government and commercial organizations using the Zimbra
Collaboration Suite (ZCS) software since at least July 2025. The Russian statesupported advanced persistent threat (APT) group’s activity is tracked in thecybersecurity community under several names (see Cybersecurity industry tracking), primarily as “LAUNDRY BEAR,” a name initially coined by the Netherlands General  Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD).
IC3 IC3 INDUSTRY

25.7.26

Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure This advisory was originally published on April 7, 2026, to provide tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) related to ongoing cyber exploitation of internetconnected operational technology (OT) devices by  Iranian-affiliated advanced persistent threat (APT) actors. The authoring agencies updated this advisory on July 22, 2026, to add new guidance on detecting malicious changes in reusable code modules leveraged within Rockwell Automation PLC programs. IC3 IC3 INDUSTRY

25.7.26

Cybercrime in the age of AI AI is rewiring the cybercrime ecosystem. You have six months to prepare. REPORT REPORT

24.7.26

Logto Identity Platform has authentication and authorization failures in core protocol handling The Logto platform contains multiple vulnerabilities affecting the identity‑processing pipeline. These flaws reduce the reliability of authentication and authorization decisions and may allow attackers to bypass account‑ownership checks, skip MFA, replay externally issued SSO responses, or submit identity assertions without proper cryptographic or validity checks. Collectively, the issues create several paths for unauthorized access across both local and federated sign‑in flows. ALERT ALERT

24.7.26

Duplicati backup software v2.3.0.1 is vulnerable to an incorrect permission assignment vulnerability Duplicati v2.3.0.1 is vulnerable to arbitrary code execution when installed outside the default C:\Program Files\Duplicati 2\ directory. An attacker with local user privileges who can write files to the Duplicati installation directory can execute arbitrary code by placing malicious files, such as DLLs, in that directory. To mitigate this vulnerability, install Duplicati in the default C:\Program Files\ directory or update to the latest fixed version. ALERT ALERT

24.7.26

Analog Way Picturall Quad Compact Mark II contains a local privilege escalation vulnerability Version 3.5.8 of Analog Way's Picturall Quad Compact Mark II server contains a local privilege escalation vulnerability, tracked as CVE-2026-14985, due to improper privilege delegation and insufficient input validation in a maintenance script. ALERT ALERT

24.7.26

Plane contains multi-tenant authorization bypass vulnerability The project management tool Plane, versions 1.3.0 and earlier, contains a multi-tenant authorization bypass vulnerability in its asset-management API that allows unauthorized users to access, delete, or duplicate assets that belong to other workspaces. ALERT ALERT

24.7.26

BlueNoroff ClickFix Kit JUMPSEC has obtained and analysed the source code behind an active BlueNoroff phishing kit used to impersonate Zoom and Microsoft Teams meetings. Unlike previous reporting, this research provides source-level visibility into how the operation works after operators mistakenly exposed JavaScript source maps on live infrastructure. PHISHING KIT

24.7.26

CVE-2026-54121 Active Directory Certificate Services Elevation of Privilege Vulnerability VULNEREBILITY VULNEREBILITY

24.7.26

Disrupting the first reported AI-orchestrated cyber espionage campaign We have developed sophisticated safety and security measures to prevent the misuse of our AI models. While these measures are generally effective, cybercriminals and other  malicious actors continually attempt to find ways around them. REPORT REPORT

24.7.26

ClickFix Campaigns Targeting Windows and macOS Insikt Group identified five distinct ClickFix clusters sharing the same core human-verification lure despite notable differences in themes, delivery patterns,
and infrastructure.
REPORT REPORT

24.7.26

TAG-195 Upgrades MaaS Ecosystem with Modular Tools Insikt Group identified four new TAG-195 malware families that indicate sustained  active development and a deliberate architectural transition toward modular,  operator-driven tooling. REPORT REPORT

24.7.26

CVE-2026-21536 Microsoft Devices Pricing Program Remote Code Execution Vulnerability VULNEREBILITY VULNEREBILITY

24.7.26

TAG-195 TAG-195 Upgrades MaaS Ecosystem with Modular Tools GROUP GROUP

24.7.26

CVE-2026-32194 filed as command injection under CWE-77, is the public "Search by Image" upload, with the SVG going in base64 as the imageBin field to /images/kblob. VULNEREBILITY VULNEREBILITY

24.7.26

CVE-2026-32191 filed as OS command injection under CWE-78, is the crawler route: host the SVG anywhere, hand its URL to the search through the imgurl parameter, and bingbot/2.0 fetches it into the same pipeline. Neither needs authentication, cookies, session state or a click. VULNEREBILITY VULNEREBILITY

24.7.26

Russian State-Supported Cyber Actors  Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian statesupported advanced persistent threat (APT) group’s activity is tracked in the cybersecurity community under several names (see Cybersecurity industry tracking), primarily as “LAUNDRY BEAR,” a name initially coined by the Netherlands General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD). REPORT REPORT

24.7.26

CVE-2025-27915 An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. VULNEREBILITY VULNEREBILITY

24.7.26

0day .ICS attack in the wild Earlier in 2025, an apparent sender from 193.29.58.37 spoofed the Libyan Navy’s Office of Protocol to send a then-zero-day exploit in Zimbra’s Collaboration Suite, CVE-2025-27915, targeting Brazil’s military. VULNEREBILITY ICS

24.7.26

CVE-2026-58593 NodeBB does not bind the claimed author of an inbound ActivityPub object to the authenticated remote actor. The inbound middleware verifies the HTTP-signature actor and checks the origin of object.id, but never validates that attributedTo corresponds to the sender. VULNEREBILITY VULNEREBILITY

24.7.26

CVE-2026-25589 RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does not properly validate serialized values processed through the Redis RESTORE command. VULNEREBILITY VULNEREBILITY

24.7.26

CVE-2026-25243 Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to execute RESTORE can supply a crafted serialized payload that triggers invalid memory access and may lead to remote code execution. VULNEREBILITY VULNEREBILITY

24.7.26

CVE-2026-8496 A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version 5.12.7. A maliciously crafted ICS calendar invitation files allows arbitrary JavaScript execution within the authenticated SOGo webmail session. VULNEREBILITY VULNEREBILITY

24.7.26

CVE-2025-66376 Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message. VULNEREBILITY VULNEREBILITY

23.7.26

Lampion malware returns in campaign targeting Portuguese users The Acronis Threat Research Unit has uncovered an active Lampion malware campaign targeting users in Portugal through localized administrative and financial phishing lures. The infection vector commences with compressed archives attached to emails containing heavily obfuscated HTML documents. ALERTS CAMPAIGN

23.7.26

New TrickBot vartiant adopts DNS Tunneling to evade detection Cybersecurity researchers at FortiGuard Labs recently investigated a novel iteration of the well-known TrickBot malware family that exhibits an evolution in command-and-control (C2) communication tactics. Unlike historical variants that primarily depended on standard HTTP traffic to interact with attacker infrastructure, this variant utilizes DNS tunneling. ALERTS VIRUS

23.7.26

Multi-Stage Phishing Campaign Uses Fileless Execution to Deploy Phantom Stealer v3.5.0 Researchers from Seqrite reported on a recently observed phishing operation that leverages realistic corporate lures to compromise enterprise networks. Attackers distribute malicious JavaScript payloads within compressed email attachments, pretending to represent reliable institutions such as the Malaysian Inland Revenue Board or UPS Forwarding Hub. ALERTS PHISHING

23.7.26

PylangGhost and GolangGhost RATs delivered by Purseweb in the latest ClickFake Interview campaign SOCRadar’s Threat Research Unit recently detailed the "ClickFake Interview" campaign, a sophisticated social engineering scheme conducted by the North Korea-aligned threat actor Purseweb (aka Famous Chollima, Wagemole). Posing as recruiters on social media platforms, the attackers entice prospects with high-paying opportunities before directing them to fake skill-assessment websites. ALERTS VIRUS

23.7.26

HollowGraph malware leverages Microsoft 365 Calendar events for C2 communication Group-IB researchers have uncovered HollowGraph, a novel malware variant attributed with to the Cavern backdoor framework, which is associated with Iranian threat actors targeting organizations in Israel. The malware covertly manages command-and-control (C2) operations by abusing the Microsoft Graph API through a compromised Microsoft 365 accounts, seamlessly blending malicious activity into legitimate network traffic. ALERTS VIRUS

23.7.26

CVE-2026-62144 (CVSS score of 9.3): A critical authentication bypass flaw in Security Management and Multi-Domain Security Management that enables unauthenticated remote attackers to execute administrative actions on the Management Server, including run-script and exec-command operations on Security Gateways. VULNEREBILITY VULNEREBILITY

23.7.26

CVE-2026-62145 (CVSS score of 7.5): An improper privilege management issue in the Gaia Portal that allows authenticated users with read-only access to escalate privileges and execute commands as root. VULNEREBILITY VULNEREBILITY

23.7.26

Cookie Crumbles Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware VULNEREBILITY VULNEREBILITY

23.7.26

CVE-2026-0257 Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues. VULNEREBILITY VULNEREBILITY

23.7.26

FakeGit campaign AI-Assisted Fake GitHub Repositories Fuel SmartLoader and LummaStealer Distribution CAMPAIGN CAMPAIGN

23.7.26

SharedRoot SharedRoot; Escaping the Claude Cowork sandbox VULNEREBILITY VULNEREBILITY

23.7.26

Chaos RaaS Unmasking the new Chaos RaaS group attacks GROUP GROUP

23.7.26

msaRAT Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel MALWARE RAT

23.7.26

JadeProx JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake OPERATION OPERATION

23.7.26

Large-Scale campaigne Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign CAMPAIGN CAMPAIGN

23.7.26

Operation Muck and Load Malicious Go Module Exposes GitHub Malware Lure Network Spanning 222 Repositories OPERATION OPERATION

23.7.26

RefluXFS RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600) VULNEREBILITY VULNEREBILITY

23.7.26

CVE-2026-64600 In the Linux kernel, the following vulnerability has been resolved: net: hsr: fix potential OOB access in supervision frame handling Ensure the entire TLV header is linearized before access by adding sizeof(struct hsr_sup_tlv) to the pskb_may_pull() calls. Without this, a truncated frame could cause an out-of-bounds access. VULNEREBILITY VULNEREBILITY

23.7.26

CVE-2026-16232 Authentication bypass with SmartConsole login process using application token VULNEREBILITY VULNEREBILITY

23.7.26

Hermeticreader The Vulnerability That Turned Adobe's 300M-Install Extension Into a Full WhatsApp Takeover VULNEREBILITY VULNEREBILITY

23.7.26

CVE-2026-8933 CVE-2026-8933: Local Privilege Escalation in Set-Capabilities snap-confine VULNEREBILITY VULNEREBILITY

23.7.26

CVE-2026-48294 Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origin data disclosure vulnerability. An attacker could exploit this vulnerability to gain access to data regarding the victim's session. VULNEREBILITY VULNEREBILITY

23.7.26

CVE-2026-29059 Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to version 1.603.3, an unauthenticated path traversal vulnerability exists in Windmill's get_log_file endpoint "(/api/w/{workspace}/jobs_u/get_log_file/{filename})". VULNEREBILITY VULNEREBILITY

22.7.26

UAC-0099: LUNCHPOKE, BURNYBEAR, оновлений  MATCHBOIL.V2 та  використання Notepad++ 8.8.3 Із середини літа 2026 року CERT-UA відзначено зміну в тактиках, техніках та процедурах кластера кіберзагроз UAC-0099. Зокрема, задокументовано факт запуску програмного засобу реалізації кіберзагроз у вигляді DLL-файлу, замаскованого під плагін з назвою "NppExport.dll", за допомогою легітимного файлу програми Notepad++ 8.8.3, доставленого на комп'ютер у вигляді архіву з іншими штатними програмними компонентами. Крім того, оновлено завантажувач MATCHBOIL та застосовано нові програмні засоби: LUNCHPOKE і BURNYBEAR. BATTLEFIELD UKRAINE BATTLEFIELD UKRAINE

22.7.26

ExploitGym: Can AI Agents Turn Security
Vulnerabilities into Real Attacks?
AI agents are rapidly gaining capabilities that could significantly reshape cybersecurity, making rigorous evaluation urgent. A critical capability is exploitation: turning a vulnerability, which is not yet an attack, into a concrete security impact, such as unauthorized file access or code execution. PAPERS PAPERS

21.7.26

FBI Warns of Scammers Impersonating the IC3 FBI Warns of Scammers Impersonating the IC3 IC3 IC3 PRESS

21.7.26

Backdoor.Win32.TOFSEE.VSNTGE26 This Backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites. MALWARE BACKDOOR

21.7.26

Trojan.Win64.COROXY.A This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.It does not have any propagation routine. MALWARE TROJAN

21.7.26

TrojanSpy.Win32.XTRAT.A This Trojan Spy arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.It does not have any propagation routine. MALWARE TROJAN

21.7.26

Anatomy of a Cyber World Effectively prioritize your investment in cybersecurity through understanding your adversaries and the attack methods targeting your industry and region REPORT REPORT

21.7.26

CVE-2021-27137 DD-WRT Stack-Based Buffer Overflow Vulnerability KEV KEV

21.7.26

CVE-2026-0770 Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability   KEV KEV

21.7.26

CVE-2026-63030 WordPress Core Interpretation Conflict Vulnerability   KEV KEV

21.7.26

CVE-2026-60137 WordPress Core SQL Injection Vulnerability KEV KEV

21.7.26

CVE-2026-10591 CVE-2026-10591 - Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths VULNEREBILITY VULNEREBILITY

21.7.26

CVE-2026-50522 Microsoft SharePoint Remote Code Execution Vulnerability VULNEREBILITY VULNEREBILITY

21.7.26

NadMesh Botnet targets AI services

Cybersecurity researchers at XLab identified NadMesh, a new Go-based botnet designed to target exposed artificial intelligence (AI) frameworks and Model Context Protocol (MCP) environments. Operating as an autonomous threat platform, NadMesh integrates expansive cloud network scanning with more than twenty exploitation pathways to compromise systems running Kubernetes, Docker, Redis and more. ALERTS AI

21.7.26

Disguised .ttf Files Deploy Infostealers

A new campaign documented by Fortinet highlights a loader operation targeting global organizations. Attackers initiate the intrusion by impersonating trusted business entities via phishing emails that contain malicious archives. These archives contain heavily obfuscated JScript droppers designed to bypass signature-based detection using string array mapping and control flow flattening. ALERTS VIRUS

21.7.26

ClickLock Stealer malware

Researchers from Group-IB recently uncovered a novel macOS malware dubbed ClickLock Stealer. Operating without requiring administrative privileges or system exploits, this modular shell script spreads through deceptive ClickFix prompts hosted on compromised WordPress sites, utilizing Telegram for its C2 infrastructure. ALERTS VIRUS

21.7.26

ClickFix and Vidar used to Deliver Telepuz malware

Elastic Security Labs shared details of an emerging threat named Telepuz, a lightweight and modular malware-as-a-service (MaaS) family that has been active since late April 2026. Distributed broadly through ClickFix social engineering campaigns, the attack chain begins when an unsuspecting user executes a malicious PowerShell command on a compromised web page. ALERTS VIRUS

21.7.26

UAT-11795 Leverages Trojanized Software Installers to Deliver Custom Python and PowerShell Payloads

In a recent write-up, Cisco Talos details a financially motivated campaign attributed to the Russian-speaking threat group UAT-11795, which has been active since at least June 2025 against users in the U.S. and Europe. Initial intrusion is achieved via ClickFix social engineering tricks that trigger a weaponized HTA stager, ultimately placing trojanized installers for common administration and collaboration utilities on the endpoint. ALERTS APT

21.7.26

(A)I Sees What You Don’t: Exploiting New Attack Surfaces in Third-Party Mobile Agents Third-party mobile agents powered by VisionLanguage Models (VLMs) have emerged as a promising paradigm for automating smartphone interactions. These agents act as high-privilege decision-makers, perceiving device states through screenshots and executing actions via VLM reasoning, transforming how an agent app interacts with the environment (i.e., other apps or the OS). PAPERS PAPERS

21.7.26

CVE-2026-0257 Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues. VULNEREBILITY VULNEREBILITY

21.7.26

LegacyHive Free micropatches available for "LegacyHive" 0day VULNEREBILITY VULNEREBILITY

21.7.26

SonicWall Secure Mobile Access 0-day Exploitation Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation EXPLOIT EXPLOIT

21.7.26

Considering Simultaneous Voltage-Sensitive Load Reductions Operators and planners of the Bulk Electric System (BES) should be aware of the risks and challenges associated with voltage-sensitive large loads that are rapidly being connected to the power system. Specifically, when considering data centers and cryptocurrency mining facilities, entities should be aware of the potential for large amounts of voltage-sensitive load loss during normally cleared faults on the BES REPORT REPORT

21.7.26

PowerHammer: Exfiltrating Data from Air-Gapped Computers through Power Lines In this paper we provide an implementation, evaluation, and analysis of PowerHammer, a malware (bridgeware that uses power lines to exfiltrate data from air-gapped computers. In this case, a malicious code running on a compromised computer can control the powerconsumption of the
system by intentionally regulating the CPU utilization.
PAPERS PAPERS

21.7.26

Power Stabilization for AI Training Datacenters Large Artificial Intelligence (AI) training workloads spanning several tens of thousands of GPUs present
unique power management challenges. These arise due to the high variability in power consumption during the training.
PAPERS PAPERS

21.7.26

Bit2Watt: A CyberPhysical Vulnerability Exploiting GPU Workloads Across Power and Computing Infrastructures Modern data centers increasingly rely on large-scale GPU clusters and on-site renewable energy resources, resulting in a tightly coupled cyberphysical system between computing workloads and power-electronic-dominated grids. PAPERS PAPERS

21.7.26

CVE-2026-63030 WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution VULNEREBILITY VULNEREBILITY

21.7.26

CVE-2025-3248 Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code. VULNEREBILITY VULNEREBILITY

21.7.26

JADEPUFFER JADEPUFFER evolves: The agentic threat actor deploys ransomware built to destroy AI models RANSOM AI

21.7.26

CVE-2026-6875 ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. VULNEREBILITY VULNEREBILITY

21.7.26

AgentBaiting AgentBaiting: How 800+ Fake AI Skills and MCP Servers Delivered Malware AI AI

20.7.26

CVE-2025-33053 External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network. VULNEREBILITY VULNEREBILITY

20.7.26

HOLLOWGRAPH HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels MALWARE BACKDOOR

20.7.26

Russian state actors are compromising IP cameras in Europe for military purposes Cybersecurity advisory Russian state actors are compromising IP cameras in Europe for military purposes REPORT REPORT

20.7.26

CVE-2026-14266 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability VULNEREBILITY VULNEREBILITY

20.7.26

Patriot Bait One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign CAMPAIGN CAMPAIGN

20.7.26

CVE-2026-42533 A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable VULNEREBILITY VULNEREBILITY

19.7.26

OpenSSL HollowByte OpenSSL HollowByte: A DoS Hiding in 11 Bytes VULNEREBILITY VULNEREBILITY

18.7.26

BoryptGrab Malicious GitHub Campaign: Fake “Arctic Wolf” and 290+ Brand-Impersonation Repositories Deliver BoryptGrab-Lineage Infostealer MALWARE INFOSTEALER

18.7.26

CVE-2026-53410 high-severity TOCTOU (time-of-check to time-of-use) race condition affecting Zoom Workplace for Windows before 7.0.5, Zoom Workplace VDI Client and VDI Plugin before 6.5.17/6.6.14, Zoom Rooms for Windows before 7.0.5, and Remote Control for Zoom Contact Center before 7.0.0. VULNEREBILITY VULNEREBILITY

18.7.26

CVE-2026-53409 high-severity improper privilege management flaw affecting Zoom Rooms for Windows before version 7.1.0 that could allow an authenticated user with local access to escalate privileges. VULNEREBILITY VULNEREBILITY

18.7.26

CVE-2026-53411 high-severity improper input validation flaw affecting the Zoom Workplace VDI Plugin for Windows before version 6.6.14 that could allow an authenticated user with local access to escalate privileges. VULNEREBILITY VULNEREBILITY

18.7.26

CVE-2026-60137 WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter. VULNEREBILITY VULNEREBILITY

18.7.26

CVE-2026-63030 WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution. VULNEREBILITY VULNEREBILITY

18.7.26

GTIG AIThreat Tracker: Advances in Threat Actor Usage of AI Tools Advances in Threat Actor Usage  of AI Tools REPORT REPORT

18.7.26

m-trends-2026-en m-trends-2026 REPORT REPORT

18.7.26

AI Security
Report 2026
AI SecurityReport 2026 Check Point AI Report • 2nd Annual EditionCheck Point Research AI Security Report 202 REPORT REPORT

18.7.26

CVE-2026-46817: Vulnerability in the Oracle Payments product of Oracle E-Business Suite In a recent write-up, Oracle details a critical security flaw in the Oracle Payments module of its E-Business Suite, tracked as CVE-2026-46817. The vulnerability impacts product versions 12.2.3 through 12.2.15 and stems from missing authentication and improper privilege management within the file transmission component. ALERTS VULNEREBILITY

18.7.26

Operation ShadowRecruit Deploys RMM and SheetAgent RAT A new campaign documented by Seqrite, dubbed Operation ShadowRecruit, targets Indian job seekers with recruitment-themed lures. Specifically focused on candidates applying for government roles, the attack relies on malicious ZIP archives containing disguised Windows shortcuts. ALERTS OPERATION

18.7.26

Active Directory Federation Services Privilege Escalation Flaw (CVE-2026-56155) According to Microsoft, a high-severity vulnerability (CVE-2026-56155) in Active Directory Federation Services (AD FS) is actively being exploited in the wild. The flaw stems from insufficient granularity of access control, allowing an authenticated, local attacker to improperly elevate their privileges on compromised machines. ALERTS VULNEREBILITY

18.7.26

TuxBot v3 Targets IoT for DDoS Operations In a recent write-up, Palo Alto Networks details TuxBot v3 Evolution, an advanced internet-of-things botnet framework designed for distributed denial-of-service operations. T ALERTS BOTNET

18.7.26

Spirals: New Stealthy Ransomware Deployed Against Asian IT Company A previously unseen ransomware family, named Spirals by its operators, was deployed in a double extortion attack against an IT services company in South Asia in June 2026, the Symantec Threat Hunter Team can reveal. The Rust-based payload is either a new ransomware threat or one purpose-built for this attack. The actor behind the attack remains unknown ALERTS RANSOM

18.7.26

BoryptGrab-Lineage Infostealer via Fake GitHub Repositories Researchers at Arctic Wolf recently reported a malicious campaign leveraging hundreds of fake GitHub repositories to deliver a BoryptGrab-lineage infostealer. Actors behind this activity established over 290 deceptive project pages impersonating various legitimate software and security vendors. ALERTS VIRUS

18.7.26

Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor More than four years after Symantec first uncovered Backdoor.Daxin, the malware has resurfaced. Symantec's Threat Hunter Team uncovered Daxin in active use on a compromised host in Taiwan in May 2026, long after the tool was last found. ALERTS VIRUS

18.7.26

LabubaRAT Blackpoint's Adversary Pursuit Group (APG) has recently identified a previously undocumented Rust-based remote access tool, tracked as LabubaRAT, that masquerades as NVIDIA software. ALERTS VIRUS

18.7.26

CrashStealer Malware Targets macOS Users via Mimicked Crash Reporter In a recent write-up, Jamf Threat Labs researchers detail CrashStealer, a native C++ macOS infostealer designed to masquerade as the operating system's built-in crash-reporting framework. The malware is initially distributed via a signed and Apple-notarized dropper disguised as a meeting application, allowing it to easily bypass Gatekeeper protections. ALERTS VIRUS

18.7.26

Albiriox Android RAT Spread via Fake Bank Rewards Researchers at D3Lab recently reported an Android campaign abusing a major Italian banking brand to distribute the Albiriox banking RAT. A lookalike domain advertises a fake cash reward and redirects victims to a Telegram bot, which offers money for installing an APK and more for referrals, turning the fraud into a self-propagating distribution channel. ALERTS VIRUS

18.7.26

CrySome RAT Delivered via Logistics-Themed Phishing Campaign Researchers at LevelBlue's recently reported a multi-stage intrusion that culminates in deployment of the CrySome remote access trojan. Initial access came from a spear-phishing email impersonating a freight rate confirmation, directing the recipient to an actor-controlled portal that delivered a batch file rather than the expected PDF. ALERTS VIRUS

18.7.26

GigaWiper Implant Employs Modular Design for Espionage and Irreversible Wiping A new malware family documented by Microsoft Threat Intelligence, known as GigaWiper, combines multiple legacy destructive payloads into a single Go-based backdoor platform4. Operating in compromised Windows environments since late 2025, this threat masquerades as a OneDrive executable and utilizes legitimate messaging and storage services for command-and-control communication. ALERTS VIRUS

18.7.26

Salat Stealer deployments bundled with Xeno Executor tool Salat Stealer is a Go-based information-gathering and spying utility that targets unsuspecting gamers and cryptocurrency holders. The malware spreads primarily via social engineering campaigns, or as recently observed by the Splunk researchers, bundled with third-party game modification tools such as Xeno Executor, a Roblox scripting utility. ALERTS VIRUS

18.7.26

Everest Ransomware variant Active since late 2020, Everest is a sophisticated double-extortion ransomware operation targeting diverse global industries including government and healthcare across North America, Europe, and Asia. Initial access is typically gained via phishing, stolen credentials, or exploitation of vulnerable applications. ALERTS RANSOM

18.7.26

Operation Henhouse Operation Henhouse: Hundreds of arrests and millions in assets seized in month tackling fraud OPERATION OPERATION

18.7.26

CVE-2026-44761 SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data. Successful exploitation results in high impact on confidentiality and integrity, with no impact on availability. VULNEREBILITY VULNEREBILITY

18.7.26

CVE-2026-44747 SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability. This has high impact on confidentiality, integrity, and availability of the application. VULNEREBILITY VULNEREBILITY

18.7.26

Jalisco Toolkit The Jalisco Toolkit and AI-Powered Phishing Surge PHISHING TOOL

18.7.26

CVE-2026-25089 Fortinet FortiSandbox OS Command Injection Vulnerability KEV KEV

18.7.26

CVE-2026-39808 Fortinet FortiSandbox OS Command Injection Vulnerability KEV KEV

18.7.26

CVE-2026-58644 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability KEV KEV

18.7.26

CVE-2026-46817 Oracle E-Business Suite Improper Privilege Management Vulnerability KEV KEV

18.7.26

CVE-2023-4346 KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability KEV KEV

18.7.26

CVE-2026-56164 Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability KEV KEV

18.7.26

CVE-2026-56155 Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability KEV KEV

18.7.26

CVE-2026-15410 SonicWall SMA1000 Appliances Code Injection Vulnerability KEV KEV

18.7.26

CVE-2026-15409 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability KEV KEV

18.7.26

Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditions A denial-of-service (DoS) vulnerability exists in some HTTP/2 server implementations that fail to adequately limit resource consumption when buffering response data under stalled flow-control conditions. A remote, unauthenticated attacker can trigger memory exhaustion and service interruption by using standard flow-control parameters such as SETTINGS_INITIAL_WINDOW_SIZE = 0 to stall outbound data for multiple simultaneous request streams. ALERT ALERT

18.7.26

SGLang contains a vulnerable pickle deserialization vulnerability through the expert-parallel subsystem A Pickle deserialization vulnerability has been discovered within the SGLang project, enabling an attacker to perform remote code execution (RCE) on the target vulnerable server. In order for an attacker to exploit this vulnerability, the expert-parallel backup subsystem must be enabled, and an attacker must have network access to the SGLang service. No patch is available at this time, and no response was obtained from the project maintainers during coordination. ALERT ALERT

18.7.26

Privilege escalation vulnerability via unprotected IOCTL interface in Pegatron Tdelo64.sys A privilege escalation vulnerability exists in the tdeio64.sys driver due to an unprotected input/output control (IOCTL) dispatch routine that fails to validate the origin and permissions of user-supplied requests. An unprivileged local attacker can abuse exposed IOCTL dispatch routines [RM1.1][MB1.2]to perform arbitrary kernel memory read and write operations, ultimately obtaining NT AUTHORITY\SYSTEM privileges and compromising the security of the affected system. ALERT ALERT

18.7.26

node-forge Signature Forgery Vulnerabilities in RSA-PKCS and ED25519 Implementations Two distinct cryptographic signature verification vulnerabilities exist in Digital Bazaar node-forge, a widely used JavaScript library implementing cryptographic primitives for Node.js and browser environments. These vulnerabilities allow attackers to forge RSA (PKCS#1 v1.5) and Ed25519 signatures under specific, exploitable conditions. ALERT ALERT

18.7.26

SuccessKey ChainVeil: A Malicious npm Supply Chain Attack by SuccessKey

GROUP

GROUP

18.7.26

ChainVeil Sequel to ChainVeil npm Malware Targets Vite Ecosystem MALWARE PYTHON

18.7.26

NadMesh NadMesh Botnet Analysis: A Product-Grade Threat for the AI Service Era BOTNET BOTNET

18.7.26

HelloNet campaign We identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks). CAMPAIGN CAMPAIGN

18.7.26

Operation ShadowRecruit Contents Introduction Key Targets Industries Affected Geographical focus Infection Chain Initial Findings Looking into the Decoy Document Technical Analysis Stage 1 – Initial Infection through LNK file Stage 2 – PowerShell Downloader Analysis Stage 3 – The .NET Dropper...

OPERATION

OPERATION

18.7.26

CVE-2025-40948 An attacker leverages an insecure configuration of the xz utility, which executes with root privileges, to read any file on the switch’s file system. This vulnerability enables initial reconnaissance that could reveal critical information such as sensitive configuration files, password hashes and private cryptographic keys. VULNEREBILITY VULNEREBILITY

18.7.26

CVE-2025-40947 This critical flaw resides in the feature key validation function. The function fails to sanitize an attacker-controlled payload before inserting it directly into a command executed with root privileges. Exploiting this allows for direct command injection and full root access. VULNEREBILITY VULNEREBILITY

18.7.26

CVE-2025-40949 Following privilege escalation, the final vulnerability is exploited in the switch’s web management task scheduler. Improper input sanitization allows an authenticated attacker to inject malicious commands into the system’s root cron table. This establishes persistent code execution, surviving system reboots and maintaining full control. VULNEREBILITY VULNEREBILITY

18.7.26

PhantomGate Campaign The PhantomGate Campaign — Obfuscation, Persistence, and Covert Surveillance CAMPAIGN CAMPAIGN

18.7.26

Starland RAT Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025. MALWARE RAT

18.7.26

UAT-11795 Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025.

GROUP

GROUP

17.7.26

GoldenEyeDog

Introducing CylindricalCanine: The GoldenEyeDog subgroup responsible for the April DigiCert incident

GROUP

GROUP

17.7.26

Operation Dragon Breath

Since 2015, Qi An Xin Threat Intelligence Center has been closely monitoring the gambling and fraud industries in East Asia and Southeast Asia. In 2020, we published "A Glimpse into the Southeast Asian Gambling Industry: A Look at the Black Market"  , which provided a general analysis of the background and environment of the gambling industry.

OPERATION

OPERATION

17.7.26

Вектори первинної компрометації UAC-0145 станом на липень 2026 року

Тривалий час CERT-UA у взаємодії з основними суб'єктами забезпечення кібербезпеки України вживаються адресні заходи, спрямовані на дослідження кластера кіберзагроз UAC-0145 (субкластер UAC-0002, також відомий як Sandworm, APT44, Seashell Blizzard).

BATTLEFIELD UKRAINE

BATTLEFIELD UKRAINE

17.7.26 EVALUSION EVALUSION Campaign Delivers Amatera Stealer and NetSupport RAT CAMPAIGN CAMPAIGN
17.7.26 ACR Stealer ACR Stealer: Two observed intrusion chains amid increased threat activity MALWARE STEALER
17.7.26 TetrisPhantom Kaspersky uncovers APT campaign targeting APAC government entities CAMPAIGN CAMPAIGN
17.7.26 GoSerpent GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration MALWARE BACKDOOR
17.7.26 CVE-2026-58644 Microsoft SharePoint Remote Code Execution Vulnerability VULNEREBILITY VULNEREBILITY
16.7.26 Agent Data Injection Attacks are Realistic Threats to AI Agents AI agents act on behalf of user prompts, consumingexternal data and taking actions based on the agent context. Prior research on AI agent security has primarily focused on indirect prompt injection (IPI). Its most well-studied category is instruction injection, where attacker-controlled untrusted data is interpreted as an instruction. PAPERS PAPERS
16.7.26 TELEPUZ TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains MALWARE MaaS
16.7.26 ClickLock Stealer ClickLock Stealer: Paste Once, Lose Everything MALWARE STEALER
16.7.26 CVE-2026-59208 n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances configured with more than one trusted token-exchange issuer resolved external identities to local accounts using only the JWT sub claim and ignored the iss claim, allowing an attacker with a valid token from one trusted issuer and a sub matching a victim under another issuer to authenticate as that victim. This issue is fixed in versions 2.27.4 and 2.28.1. VULNEREBILITY VULNEREBILITY
16.7.26 TuxBot v3 TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development BOTNET IoT
16.7.26 CVE-2026-55040 Microsoft SharePoint Server Security Feature Bypass Vulnerability VULNEREBILITY VULNEREBILITY
16.7.26 CVE-2026-45659 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. VULNEREBILITY VULNEREBILITY
16.7.26 CVE-2026-32201 Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. VULNEREBILITY VULNEREBILITY
16.7.26 Anti-Ledger “Anti-Ledger” malware: The battle for Ledger Live seed phrases MALWARE CRYPTOCURRENCY
16.7.26 CVE-2026-53411 (CVSS score: 7.8) - An improper input validation vulnerability in the Zoom Workplace VDI Plugin for Windows before version 6.6.14 that may allow an authenticated user to conduct an escalation of privilege via local access. VULNEREBILITY VULNEREBILITY
16.7.26 CVE-2026-53410 (CVSS score: 7.0) - A time-of-check to time-of-use (TOCTOU) race condition vulnerability in the installation and uninstallation process of certain Zoom Clients for Windows that could allow an authenticated local user to escalate privileges. VULNEREBILITY VULNEREBILITY
16.7.26 CVE-2026-53409 (CVSS score: 7.8) - An improper privilege management vulnerability in Zoom Rooms for Windows before version 7.1.0 that may allow an authenticated user to conduct an escalation of privilege via local access. VULNEREBILITY VULNEREBILITY
16.7.26 CVE-2026-15765 Use after free in Ozone in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) VULNEREBILITY VULNEREBILITY
16.7.26 CVE-2026-15764 Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) VULNEREBILITY VULNEREBILITY
16.7.26 CVE-2026-15718 We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6. VULNEREBILITY VULNEREBILITY
16.7.26 CVE-2026-15719 We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6. VULNEREBILITY VULNEREBILITY
16.7.26 Daxin Returns Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor MALWARE BACKDOOR
16.7.26 OkoBot OkoBot: new sophisticated malware framework targets cryptocurrency users MALWARE FRAMEWORK
16.7.26 Miasma Botnet Loader Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader BOTNET BOTNET
16.7.26 Miasma RAT AsyncAPI Packages Compromised with Miasma RAT MALWARE RAT
15.7.26 CVE-2026-56164 Microsoft SharePoint Server Elevation of Privilege Vulnerability VULNEREBILITY VULNEREBILITY
15.7.26 CVE-2026-56155 Active Directory Federation Services Elevation of Privilege Vulnerability VULNEREBILITY VULNEREBILITY
15.7.26 CVE-2026-15409 (CVSS score: 10.0) - A Server-side request forgery (SSRF) vulnerability that a remote unauthenticated attacker could exploit to potentially cause the appliance to make requests to an unintended location. VULNEREBILITY VULNEREBILITY
15.7.26 CVE-2026-15410 (CVSS score: 7.2) - A post-authentication code injection vulnerability rooted in the Appliance Management Console (AMC) that a remote authenticated attacker could exploit to execute arbitrary operating system commands as administrator under certain conditions. VULNEREBILITY VULNEREBILITY
14.7.26 CVE-2026-44747 SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability. VULNEREBILITY VULNEREBILITY
14.7.26 CVE-2026-27690 (CVSS score: 9.1) - An HTTP request/response smuggling flaw in SAP Approuter deployments in non-Cloud Foundry environments that allows an unauthenticated attacker to send a specially crafted HTTP request that leads to request-response desynchronization and results in the exposure of user responses and triggers denial-of-service (DoS) attacks. VULNEREBILITY VULNEREBILITY
14.7.26 CVE-2026-44761 (CVSS score: 9.1) - A use of default credentials flaw in SAP Commerce Cloud that could retain a sample OAuth 2.0 client with publicly documented sample credentials originating from a sample configuration provided in SAP Help Portal documentation. VULNEREBILITY VULNEREBILITY
14.7.26 ClaudeBleed Reopened Eight Claude for Chrome releases later, the bypass is still six lines of JavaScript. We reported it to Anthropic in May. The code is unchanged in the latest version. HACKING AI
14.7.26 LabubaRAT LabubaRAT: A Rust Based Remote Access Tool Masquerading as NVIDIA Software MALWARE RAT
14.7.26 Forgotten UEFI shims undermining Secure Boot ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities VULNEREBILITY VULNEREBILITY
14.7.26 CVE-2026-57219 (CVSS score: 8.7) - An obsolete HTTP API endpoint ("GET /api/auth") that reveals client secret on RabbitMQ installations that had OAuth 2 configured to use the management.oauth_client_secret configuration key, allowing an attacker to exchange it for an administrator token and obtain full control of every message, queue, user, and broker setting. VULNEREBILITY VULNEREBILITY
14.7.26 CVE-2026-57221 (CVSS score: 5.3) - A missing authorization that allows any authenticated user who can connect to a virtual host to enumerate all queue and exchange names in that virtual host and read queue message counts and consumer counts, regardless of their actual permissions. VULNEREBILITY VULNEREBILITY
14.7.26 CVE-2026-8863 UEFI Secure Boot Security Feature Bypass Vulnerability VULNEREBILITY VULNEREBILITY
14.7.26 Is Your Wallet Snitching On You? An Analysis on the Privacy Implications of Web3 With the recent hype around the Metaverse and NFTs, Web3 is getting more and more popular. The goal of Web3 is to decentralize the web via decentralized applications. Wallets play a crucial role as they act as an interface between these applications and the user. PAPERS PAPERS
14.7.26 The Masks We (Think We) Wear: Privacy Threats of
Browser-ExtensionWallets in the Web3 Ecosystem
Cryptocurrency wallets are the primary interface for managing pseudonymous blockchain addresses, viewing balances, and interacting with Web3 applications. Although users typically assume that their addresses remain independent of each other unless intentionally revealed, modern wallets routinely communicate with both blockchain infrastructure and decentralized applications (dApps), generating network-side and web-side signals that may undermine this assumption. PAPERS PAPERS
14.7.26 CVE-2008-4128 Cisco IOS Cross-Site Request Forgery Vulnerability KEV KEV
14.7.26 Lucide Proxy Lucide Proxy: Turning Student Web Proxies into DDoS Bots BOTNET BOTNET
13.7.26 CrashStealer CrashStealer: C++ macOS infostealer posing as crash reporter MALWARE MacOS
13.7.26 ModHeader Malware ModHeader Malware: Inside the Chrome Spyware Google Removed MALWARE Spyware
13.7.26 codemado One Misconfigured Server, Three Active Campaigns: Full exposure of three AiTM Phishing Operators CAMPAIGN CAMPAIGN
13.7.26 mail-argenta One Misconfigured Server, Three Active Campaigns: Full exposure of three AiTM Phishing Operators CAMPAIGN CAMPAIGN
13.7.26 saroula01 One Misconfigured Server, Three Active Campaigns: Full exposure of three AiTM Phishing Operators CAMPAIGN CAMPAIGN
13.7.26 EchoLeak: The First Real-World Zero-Click Prompt Injection Exploit in a
Production LLM System
Large language model (LLM) assistants are increasingly integrated into enterprise workflows, raising new security concerns as they bridge internal and external data sources. This paper presents an in-depth case study of EchoLeak (CVE2025-32711), a zero-click prompt injection vulnerability in  Microsoft 365 Copilot that enabled remote, unauthenticated data exfiltration via a single crafted email. PAPERS PAPERS
13.7.26 SpAIware Spyware Injection Into Your ChatGPT's Long-Term Memory (SpAIware) MALWARE SpAIware
13.7.26 When Claws Remember but Do Not Tell: Stealthy Memory Injection in Persistent Personal Agents Persistent personal agents combine long-term memory with access to users’ external environments, enabling personalized foreground assistance and proactive background execution. This integration also creates a new path to compromise: untrusted external content can be silently written into persistent memory and later reused as trusted state. PAPERS PAPERS
13.7.26 AI-Assisted Cloud Attack Inside an AI-Assisted Cloud Attack: Familiar Techniques at Unfamiliar Speed ATTACK AI
13.7.26 GPPStorm GPPStorm: Fake Google Partner Invitations Target Workspace Credentials CAMPAIGN CAMPAIGN
12.7.26 Official jscrambler npm Package Compromised Official jscrambler npm Package Compromised Across Multiple Releases INCIDENT INCIDENT
12.7.26 Helix Helix, a New Name in the Data Extortion Ecosystem? GROUP Vishing
12.7.26 UNK_MassTraction One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation GROUP Cluster
12.7.26 Forg365 Inside Forg365: A Telegram-Distributed Sneaky 2FA-Style PhaaS Targeting Microsoft 365 PHISHING Phishing-as-a-service
11.7.26 CVE-2026-48939 iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability KEV KEV
11.7.26 CVE-2026-56291 Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability KEV KEV
11.7.26 GNU Wget enables SSRF via unvalidated FTP PASV IPs GNU Wget, versions 1.25.0 and earlier, contains a server-side request forgery (SSRF) vulnerability in its implementation of FTP passive mode. Because Wget does not properly validate IP addresses obtained from PASV responses, an attacker-controlled FTP endpoint can redirect the client’s connection to arbitrary IPs, potentially exposing internal network host and service responses. ALERT ALERT
11.7.26 Bypassing Tangem Card Security with a Laser Attack After uncovering a genuine check bypass on the Tangem Android application and a brute-force attack on the card's authentication protocol, the Ledger Donjon turned its attention to the card itself with more advanced tools and sophisticated techniques. What we found is a critical vulnerability that lets an attacker with physical access to a single Tangem card reset its password and steal all associated funds. HACKING CARD
11.7.26 Teardrop Attack A teardrop attack is when an attacker sends deliberately crafted IP fragments with overlapped offsets and payload lengths to exploit this vulnerability. As a result, the system becomes overwhelmed and may crash or experience severe performance degradation. ATTACK IP
11.7.26 Card tear-off attack A card tear-off attack (or tearing attack) is a type of fault injection that exploits how smart cards and NFC tags handle power interruptions during write operations. By pulling a card away from an RFID reader or cutting the power at a precise millisecond, an attacker can prevent the card's chip from finalizing state changes. ATTACK NFC
11.7.26 Injective npm Supply Chain Attack: 18 Packages Backdoored to Steal Crypto Wallet Keys attackers used access to a trusted developer's account to slip a backdoor into a widely used software development kit for the Injective blockchain. Disguised as harmless analytics, the code quietly captured wallet recovery phrases and private keys and sent them to an attacker-controlled server the moment a wallet was created or loaded. HACKING CRYPTOCURRENCY
11.7.26 A Security Analysis of the OpenClaw AI Agent Framework AI agent frameworks that connect large language model (LLM) reasoning to host execution surfaces—shell, filesystem, containers, browser automation, and messaging platforms—introduce a class of security challenges that differs structurally from those of conventional software PAPERS PAPERS
10.7.26 Before Fraud Transacts Enabling Proactive Prevention for European Finance(In the Age of Al) WHITEPAPERS WHITEPAPERS
10.7.26 SCMBANKER - a PowerShell toolkit leveraged in a recent ClickFix campaign Researchers from Elastic reported on a new Mexican banking fraud operation dubbed REF6045. The attack begins when victims encounter deceptive verification screens mimicking CAPTCHA checks. These fraudulent pages trick users into manually executing a system command that downloads SCMBANKER, a malicious PowerShell-based toolkit. ALERTS VIRUS
10.7.26 Android Malware: Redwing Zimperium's zLabs team has published a report documenting RedWing, an Android spyware variant marketed as a subscription-based malware service through Telegram channels with apparent links to Russian threat actors. The MaaS integrates a customizable dropper constructor that generates convincing phishing sites mimicking legitimate app stores, delivering payloads that abuse Accessibility Services to achieve deep device compromise. ALERTS VIRUS
10.7.26 GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses Analysis of a recent GodDamn ransomware attack indicates that this seemingly new ransomware is in fact the latest rebrand of the Beast ransomware, which in itself was a rebrand of the Monster ransomware, which was first seen in 2022. The Symantec Threat Hunter Team tracks the developer behind these ransomware families as Hyadina. ALERTS RANSOM
10.7.26 Recent activities attributed to the Swallowtail threat group The 360 Advanced Threat Research Institute recently exposed a sophisticated cyberespionage campaign conducted by the notorious state-sponsored hacking group Swallowtail (aka APT-C-20, Fancy Bear, APT28). The group is known to leverage a multi-stage infection process starting with a deceptive, macro-enabled documents. To trick users, the file displays randomized characters and hides its malicious intent using visual object manipulation while presenting a fake Eastern European defense ministry decoy. ALERTS GROUP
10.7.26 Financially Motivated Actors Deploying Dual-Threat Vidar Stealer and XMRig Payloads Palo Alto Networks Unit 42 has recently identified a financially motivated campaign delivering a combination of info-stealing malware and cryptocurrency miners globally. The activity targets corporate and consumer endpoints primarily located in the United States and European Union by using malicious search advertisements for pirated applications. ALERTS VIRUS
10.7.26 MODBEACON Operation Phnom Penh: Silver Fox Ghost Distributor Targets Specific Victims with MODBEACON Custom Trojan MALWARE TROJAN
10.7.26 Operation Phnom Penh Operation Phnom Penh: Silver Fox Ghost Distributor Targets Specific Victims with MODBEACON Custom Trojan OPERATION OPERATION
10.7.26 XRING XRING: Crashing XQUIC with spec-compliant QPACK instructions HACKING VULNEREBILITY
10.7.26 WP-SHELLSTORM How WP-SHELLSTORM Exposed 1.4M WordPress Sites OPERATION OPERATION
10.7.26 Hidden Links: Analyzing Secret Families of VPN Apps Ownership transparency in the VPN ecosystem allows users to make informed decisions about who they trust with their data. Researchers have recently begun investigating the relationships between seemingly distinct providers and who operates them, but such analysis is currently limited to a small sample of providers in the VPN ecosystem. PAPERS PAPERS
10.7.26 CVE-2016-2183 The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack. VULNEREBILITY VULNEREBILITY
10.7.26 CVE-2016-6329 OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTP-over-OpenVPN session using Blowfish in CBC mode, aka a "Sweet32" attack. VULNEREBILITY VULNEREBILITY
10.7.26 MVPNalyzer: An Investigative Framework for
Auditing the Security & Privacy of Mobile VPNs
Mobile users increasingly rely on Virtual Private Networks (VPNs) to protect themselves from tracking, surveillance, and censorship. VPN apps operate from a privileged position by requiring interception of user traffic. While this safeguards end user traffic from malicious network intermediaries (e.g. surveilling ISPs), it leads to a critical “transfer of trust” from such network intermediaries to VPN providers. PAPERS PAPERS
10.7.26 O-UNC-066 Vishing actors target Entra passkey enrollment GROUP GROUP
10.7.26 Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal
and Transferable Adversarial HalluSquatting
The growing adoption of agentic LLM applicationshas introduced a new threat previously named as promptware. While prior work has established that adversaries can exploit direct channels to LLM applications to apply promptware (push adversarial prompts) under weak threat models (e.g., by sending emails or calendar invitations to a target), many applications do not provide any direct channels that could be exploited for prompt injection beyond the Internet. This raises a fundamental question: PAPERS PAPERS
10.7.26 PayRange Android app version 7.0.7 contains multiple vulnerabilities PayRange is a mobile payment app that allows users to pay for vending machines, laundromats, and other unattended machines using a smartphone with Bluetooth. Two vulnerabilities were discovered in version 7.0.7 of the PayRange app that is available in the Google Play store. ALERT ALERT
10.7.26 Xerte Online Toolkit contains an authentication bypass that allows for RCE Two vulnerabilities have been discovered in Xerte Online Toolkits, an open-source e-learning authoring toolsuite intended for the creation of learning materials within a web browser. ALERT ALERT
10.7.26 Adalo Database API Enables Cross-App User Data Extraction via Over-Fetching and Missing Authorization Controls Adalo’s no‑code application platform exposes complete user records through its database API for all applications built on both V1 and V2. Due to a platform-level flaw, authenticated users can retrieve full user data belonging to any Adalo application, regardless of configuration. This issue affects more than one million applications and placing developers and their end users at risk of data exposure that they cannot prevent or remediate. ALERT ALERT
10.7.26 BLUERABBIT BLUERABBIT: A Golang-Based Backdoor with Ransomware and Destructive Capabilities MALWARE BACKDOOR
10.7.26 GigaWiper GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware MALWARE WIPPER
9.7.26 Beast Ransomware The Nature of the Beast Ransomware RANSOM RANSOM
9.7.26 GodDamn Ransomware GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses RANSOM RANSOM
9.7.26 CVE-2026-50656 Microsoft Defender Elevation of Privilege Vulnerability VULNEREBILITY VULNEREBILITY
9.7.26 LapDogs Campaign Unmasking A New China-Linked Covert ORB Network: Inside the LapDogs Campaign CAMPAIGN CAMPAIGN
9.7.26 SymJack SymJack: the approval prompt is lying to you. A symlink-hijack RCE in six AI coding agents AI AI
9.7.26 TrustFall TrustFall: coding agent security flaw enables one-click RCE in Claude, Cursor, Gemini CLI and GitHub Copilot AI AI
9.7.26 CVE-2026-39861 Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processes from creating symlinks pointing to locations outside the workspace. VULNEREBILITY VULNEREBILITY
8.7.26 The Promptware Kill Chain: How Prompt Injections Gradually Evolved Into a Multistep Malware Delivery Mechanism Prompt injection was initially framed as the largelanguage model (LLM) analogue of SQL injection. However, over the past three years, attacks labeled as prompt injection have evolved from isolated input-manipulation exploits into multistep attack mechanisms that resemble malware. In this paper, we argue that prompt injections evolved into promptware, a new class of malware execution mechanism triggered through prompts engineered to exploit an application’s LLM. PAPERS PAPERS
8.7.26 Git Hash Chain Malleability Git commit signing is widely entrusted to serve as evidence that a commit hash uniquely and immutably identifies a specific piece of signed content. We show this invariant does not hold. Given any signed commit, an attacker without access to the signing key, and without breaking SHA2 can produce a second, distinct commit with an identical tree, identical metadata, a valid signature, and a “Verified” badge from a Git Forge such as Github, differing only in its commit hash. PAPERS PAPERS
8.7.26 Great, Now Write an Article About That:
The Crescendo Multi-Turn LLM Jailbreak Attack
Large Language Models (LLMs) have risen significantly in popularity and are increasingly being adopted across multiple applications. These LLMs are heavily aligned to resist engaging in illegal or unethical topics as a means to avoid contributing to responsible AI harms. However, arecent line of attacks, known as “jailbreaks”, seek to overcome this alignment. Intuitively, jailbreak attacks aim to narrow the gap between what the model can do and what it is willing to do. In this paper, we introduce a novel jailbreak attack called Crescendo PAPERS PAPERS
8.7.26 Smoke and Mirrors: Jailbreaking LLM-based Code Generation via Implicit Malicious Prompts The proliferation of Large Language Models (LLMs) has revolutionized natural language processing and significantly impactedcode generation tasks, enhancing software development efficiency and productivity. Notably, LLMs like GPT-4 have demonstrated remarkable proficiency in text-to-code generation tasks. However, the growing reliance on LLMs for code generation necessitates a critical examination of the safety implications associated with their outputs. Existing research efforts have primarily focused on verifying the functional correctness of LLMs, overlooking their safety
in code generation.
PAPERS PAPERS
8.7.26 RedCode: Risky Code Execution and Generation
Benchmark for Code Agents
With the rapidly increasing capabilities and adoption of code agents for AI-assistedcoding and software development, safety and security concerns, such as generating or executing malicious code, have become significant barriers to the real-world  deployment of these agents. To provide comprehensive and practical evaluations on the safety of code agents, we propose RedCode, an evaluation platform with benchmarks grounded in four key principles: real interaction with systems, holistic evaluation of unsafe code generation and execution, diverse input formats, and highquality safety scenarios and tests. PAPERS PAPERS
8.7.26 Refusal-Trained LLMs Are Easily Jailbroken
As Browser Agents
For safety reasons, large language models (LLMs) are trained to refuse harmful user instructions, such as assisting dangerous activities. We study an openquestion in this work: does the desired safety refusal, typically enforced in chat contexts, generalize to non-chat and agentic use cases? Unlike chatbots, LLM agents equipped with general-purpose tools, such as web browsers and mobile devices, can directly influence the real world, making it even more crucial to refuse harmful instructions. In this work, we primarily focus on red-teaming browser agents – LLMs that manipulate information via web browsers PAPERS PAPERS
8.7.26 Refused in Chat, Written in Code: Workflow-Level
Jailbreak Construction in IDE Coding Agents.
Large language models are increasingly deployed as IDE-integrated coding agents that decompose tasks, generate and edit files, run code, and refine outputs over many turns. Yet their safety is still often evaluated as if they were chatbots: one harmful prompt, one response, judged in isolation. We introduce workflowlevel jailbreak construction, a failure mode in which a harmful objective is assembled across ordinary stages of a softwaredevelopment workflow rather than generated through a single direct prompt. PAPERS PAPERS
8.7.26 CVE-2026-55116 A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices. VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2026-54402 A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device. VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2026-55115 A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device. VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2026-54400 A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device. VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2026-50748 A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2026-50747 A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to escalate privileges on the host device. VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2026-50746 A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device. VULNEREBILITY VULNEREBILITY
8.7.26 SCMBANKER ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit VULNEREBILITY VULNEREBILITY
8.7.26 UAT-7810 UAT-7810 continues building ORB networks using new malware MALWARE BANKING
8.7.26 CVE-2025-2492 An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted request, potentially leading to unauthorized execution of functions. Refer to the 'ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information. VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2023-25717 Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$(curl substring. VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2020-22658 In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300) before 3.6.2.0.795, Virtual SmartZone (vSZ) before 3.6.2.0.795, ZoneDirector 1100 9.10.2.0.130, ZoneDirector 1200 10.2.1.0.218, ZoneDirector 3000 10.2.1.0.218, ZoneDirector 5000 10.0.1.0.151, a vulnerability allows attackers to switch completely to unauthorized image to be Boot as primary verified image. VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2020-22653 In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300) before 3.6.2.0.795, Virtual SmartZone (vSZ) before 3.6.2.0.795, ZoneDirector 1100 9.10.2.0.130, ZoneDirector 1200 10.2.1.0.218, ZoneDirector 3000 10.2.1.0.218, ZoneDirector 5000 10.0.1.0.151, a vulnerability allows attackers to exploit the official image signature to force injection unauthorized image signature. VULNEREBILITY VULNEREBILITY
8.7.26 Newly Unveiled Cavern C2 Toolset Targets Israeli Government and IT Sectors A sophisticated Iran-nexus threat actor dubbed Cavern Manticore has deployed a new post-exploitation framework targeting Israeli networks. Known as "Cavern," this highly modular toolset stands out because it deliberately splits its components across three distinct .NET compilation formats. By blending pure .NET, Mixed-Mode C++/CLI, and NativeAOT binaries, the malware forces defenders to switch between entirely different reverse-engineering workflows, serving as an effective anti-analysis barrier. ALERTS APT
8.7.26 FBI Warns of TeamPCP Cybercrime Group Compromising CI/CD Pipelines An FBI flash alert warns of extensive software supply chain breaches conducted by the cybercriminal organization TeamPCP. Security teams should monitor for specific custom malware deployed during these operations. This includes CanisterWorm, which is built to harvest cloud access tokens and API keys across AWS, Azure, and GCP infrastructure. ALERTS GROUP
8.7.26 Fake VPN and Media Tools Deliver MarkiRAT According to Insikt Group, an Iran-linked surveillance campaign is distributing MarkiRAT through fraudulent VPN, media-player and utility applications. The activity primarily targets Farsi-speaking users in Iran, as well as Iranian dissidents and anti-government communities in Europe and North America. ALERTS VIRUS
8.7.26 WriteOut WriteOut: Abusing the Sandbox for a Critical Cross-Tenant Vulnerability in Writer AI VULNEREBILITY VULNEREBILITY
8.7.26 GitLost GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2026-26030 Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within the `InMemoryVectorStore` filter functionality. VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2026-25592 Semantic Kernel is an SDK used to build, orchestrate, and deploy AI agents and multi-agent systems. Prior to 1.71.0, an Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the SessionsPythonPlugin. VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2026-48282 (CVSS score: 10.0) - A path traversal vulnerability in Adobe ColdFusion that could lead to arbitrary code execution in the context of the current user. VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2026-56290 (CVSS score: 10.0) - An improper access control vulnerability in Joomlack Page Builder that could allow for remote code execution via unauthenticated arbitrary file upload. VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2026-55255 (CVSS score: 6.1) - An authorization bypass through a user-controlled key vulnerability in Langflow that could allow an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2026-48908 (CVSS score: 10.0) - An unrestricted upload of a file with a dangerous type vulnerability in JoomShaper SP Page Builder that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code. VULNEREBILITY VULNEREBILITY
8.7.26 GhostLock 15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros VULNEREBILITY VULNEREBILITY
8.7.26 CVE-2026-43499 In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from futex_requeue(). VULNEREBILITY VULNEREBILITY
8.7.26 Oblivion Oblivion: The New $300 Android RAT That Beats Every Major Phone Manufacturer’s Security MALWARE RAT
8.7.26 RedWing RedWing: A Mobile Malware-as-a-Service Operation MALWARE ANDROID
8.7.26 Rogue Agent Rogue Agent: How a Single Code Block Could Hijack Your AI Conversations in Google’s DialogFlow CAMPAIGN CAMPAIGN
7.7.26 DEBULL DEBULL: Storm-2372-Style Microsoft Device-Code Phishing With GraphSpy Post-Exploitation MALWARE TOOL
7.7.26 Vshell Vshell: A Chinese-Language Alternative to Cobalt Strike MALWARE TOOL
7.7.26 CVE-2026-11405 The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8. - The function contains a normal authentication path using MD5/hash-based password verification (prod_encode64/PasswordToMd5/check_rand_key). VULNEREBILITY VULNEREBILITY
7.7.26 Tenda firmware (multiple versions) contains hidden authentication backdoor Several versions of Tenda firmware contain an undocumented authentication backdoor that grants administrative access to the devices' web management interfaces. An attacker can expoit this vulnerability, tracked as CVE-2026-11405, to bypass the password verification process and obtain full administrative control without valid credentials. ALERT ALERT
7.7.26 HP Deskjet 2800 Printer Series Webservers contain Missing Authorization Vulnerability HP Printers in the Deskjet 2800 Series running firmware version <=TBP1CN2612AR contain a missing authorization vulnerability tracked as CVE-2026-13753. This vulnerability allows unauthenticated access to the printer's webserver API endpoints, exposing Wi-Fi credentials, management configuration details, and sensitive security data normally restricted to administrative users. ALERT ALERT
7.7.26 CVE-2026-40138 A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. VULNEREBILITY VULNEREBILITY
7.7.26 CVE-2026-40139 A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. VULNEREBILITY VULNEREBILITY
7.7.26 CVE-2026-40140 BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the network communication subsystem. VULNEREBILITY VULNEREBILITY
7.7.26 CVE-2026-40141 A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. VULNEREBILITY VULNEREBILITY
7.7.26 Cavern Manticore Cavern Manticore: Exposing Iran-Linked Modular C2 Framework GROUP GROUP
7.7.26 CVE-2025-52691 SmarterMail remote code execution vulnerability VULNEREBILITY VULNEREBILITY
7.7.26 CVE-2025-68613 n8n remote code execution vulnerability VULNEREBILITY VULNEREBILITY
7.7.26 CVE-2025-9316 N-Central unauthenticated sessionID generation vulnerability VULNEREBILITY VULNEREBILITY
7.7.26 CVE-2025-34291 Langflow remote code execution vulnerability VULNEREBILITY VULNEREBILITY
7.7.26 CVE-2025-54068 Laravel Livewire remote code execution vulnerability VULNEREBILITY VULNEREBILITY
6.7.26 Januscape Januscape: Guest-to-Host Escape in KVM/x86 VULNEREBILITY VULNEREBILITY
6.7.26 CVE-2026-53359 In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free due to unexpected GFN") fixed a shadow paging mismatch between stored and computed GFNs; the bug could be triggered by changing a PDE mapping from outside the guest, and then deleting a memslot. VULNEREBILITY VULNEREBILITY
6.7.26 CVE-2026-20896 Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` VULNEREBILITY VULNEREBILITY
6.7.26 Reflecthernet: Exfiltrating 100BASE-TX Ethernet Traffic Using a Retroreflector Hardware Trojan This work has been submitted to the IEEE for possible publication. Copyright may be transferred without notice, after which this version may no longer be accessible. Electromagnetic eavesdropping is a well-established attack vector for remotely monitoring a target activity, most notably displays, over considerable ranges. PAPERS PAPERS
6.7.26 TEMPEST-LoRa: Cross-Technology Covert Communication Electromagnetic (EM) covert channels pose significant threats to computer and communications security in air-gapped networks. Previous works exploit EM radiation from various components (e.g., video cables, memory buses, CPUs) to secretly send sensitive information. PAPERS PAPERS
6.7.26 TrojPix: Electromagnetic Covert Channels via Imperceptible Pixel Modulation Air-gapped networks rely on physical isolation to prevent external connectivity. Prior electromagnetic (EM) covert channels have exploited emissions from video cables, memory buses, and CPUs, yet they rarely achieve high throughput, long range, and visual imperceptibility simultaneously, limiting practical utility in air-gapped settings. PAPERS PAPERS
6.7.26 QuimaRAT Novel Java-Based QuimaRAT Targets Windows, macOS, and Linux MALWARE RAT
6.7.26 Cyber Criminal Group TeamPCP The Federal Bureau of Investigation (FBI) is releasing this FLASH to highlight the tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) associated with the cyber criminal group TeamPCP. TeamPCP actors have conducted large-scale software supply chain compromises by targeting
widely used developers and security tools, gaining access to victim environments and extracting sensitive data, including but not limited to cloud access tokens, SSH keys, and Kubernetes secrets.
IC3 IC3 INDUSTRY
6.7.26 Cloak and Detonate: Scanner Evasion and Dynamic Detection of Agent Skill Malware LLM coding agents increasingly rely on third-party agent skills from public marketplaces, which execute with the agent's privileges and create a software supply-chain attack surface: a malicious skill can steal credentials, exfiltrate source code, or install backdoors. Existing defenses use static skill scanners based on pattern matching or LLM-as-judge analysis, but it remains unclear whether they withstand adaptive evasions that preserve malicious behavior while changing payload appearance. PAPERS PAPERS
6.7.26 Cloak and Detonate: Scanner Evasion and Dynamic Detection of Agent Skill Malware LLM coding agents increasingly rely on third-party agent skills from public marketplaces, which execute with the agent's privileges and create a software supply-chain attack surface: a malicious skill can steal credentials, exfiltrate source code, or install backdoors. Existing defenses use static skill scanners based on pattern matching or LLM-as-judge analysis, but it remains unclear whether they withstand adaptive evasions that preserve malicious behavior while changing payload appearance. MALWARE AI MALWARE
5.7.26 ChocoPoC This article details a campaign targeting vulnerability researchers with "ChocoPoC" malware embedded inside trojanised Python dependencies. Exploiting the pressure to quickly test new vulnerabilities, threat actors distribute a persistent Remote Access Trojan (RAT) that exfiltrates data and harvests credentials from compromised developer environments. MALWARE RAT
5.7.26 CVE-2026-20230 A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. VULNEREBILITY VULNEREBILITY
5.7.26 CVE-2026-46817 Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. VULNEREBILITY VULNEREBILITY
5.7.26 Operation Navy Ghost Operation Navy Ghost: How Attackers Planted a Telegram-Powered Backdoor Across Fake pyrogram Packages on PyPI OPERATION OPERATION
5.7.26 CVE-2026-33825 Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally. VULNEREBILITY VULNEREBILITY
5.7.26 Operation Contagious Interview The most effective social engineering campaigns don’t rely on obvious red flags or technical exploits. They move through familiar business interactions, like hiring conversations, project discussions, and routine follow-ups that are designed to feel legitimate from the start. OPERATION OPERATION
5.7.26 PolinRider PolinRider: North Korea-Linked Supply Chain Campaign Expands Across Open Source Ecosystems CAMPAIGN CAMPAIGN
4.7.26 PureLog Stealer distributed via Veil#Drop framework Veil#Drop is a sophisticated, multi-phase malware delivery framework designed to deploy PureLog Stealer directly into a system's memory. As reported by researchers from Securonix, the infection chain begins with social engineering, tricking victims into opening a malicious JavaScript file disguised as a legitimate PDF. ALERTS VIRUS
4.7.26 Silent Swap Campaign Deploys Malicious Notes Extension to Intercept Crypto Transactions In a recent write-up, McAfee Advanced Threat Research details an active campaign, dubbed Silent Swap, that distributes a cryptocurrency-stealing browser extension via sideloading. Delivered via unsigned .NET and Golang installers, the malware targets Chromium-based browsers on Windows endpoints, opportunistically scanning for active browser profiles. ALERTS VIRUS
4.7.26 QuimaRAT: Cross-Platform Remote Access Trojan LevelBlue has published a report on QuimaRAT, a subscription-based Java remote access trojan designed for Windows, Linux, and macOS. Per their analysis, QuimaRAT decrypts its embedded configuration, validates the host environment, installs platform-specific persistence, and connects to operator infrastructure. ALERTS VIRUS
4.7.26 CVE-2026-55255 - LangFlow vulnerability CVE-2026-55255 is a recently disclosed critical (CVSS score 9.9) Authentication Bypass vulnerability affecting Langflow (pip), which is an open-source tool for building and deploying AI-powered agents and workflows. If successfully exploited the flaw might allow an authenticated attacker to execute any flow belonging to another user leading to cross-tenant access and potential data exposure. The vulnerability has been fixed in 1.9.2 version of the product. ALERTS VULNEREBILITY
4.7.26 Multiple local privilege escalation vulnerabilities in Little Orbits GameFirst Anti-Cheat The GamersFirst Anti-Cheat (GFAC) driver GFAC.sys contains multiple local privilege escalations and denial-of-service vulnerabilities stemming from insecure handling of user-controlled input through a minifilter communication port. A local attacker can abuse these flaws to perform arbitrary kernel memory writes, obtain privilege escalation to SYSTEM, or trigger a system crash. ALERT ALERT
4.7.26 Bad Epoll In the Linux kernel, the following vulnerability has been resolved: eventpoll: fix ep_remove struct eventpoll / struct file UAF ep_remove() (via ep_remove_file()) cleared file->f_ep under file->f_lock but then kept using @file inside the critical section (is_file_epoll(), hlist_del_rcu() through the head, spin_unlock). A concurrent __fput() taking the eventpoll_release() fastpath in that window observed the transient NULL, skipped eventpoll_release_file() and ran to f_op->release / file_free(). VULNEREBILITY VULNEREBILITY
4.7.26 CVE-2026-46242 In the Linux kernel, the following vulnerability has been resolved: eventpoll: fix ep_remove struct eventpoll / struct file UAF ep_remove() (via ep_remove_file()) cleared file->f_ep under file->f_lock but then kept using @file inside the critical section (is_file_epoll(), hlist_del_rcu() through the head, spin_unlock). A concurrent __fput() taking the eventpoll_release() fastpath in that window observed the transient NULL, skipped eventpoll_release_file() and ran to f_op->release / file_free(). VULNEREBILITY VULNEREBILITY
4.7.26 CVE-2026-31694 In the Linux kernel, the following vulnerability has been resolved: fuse: reject oversized dirents in page cache fuse_add_dirent_to_cache() computes a serialized dirent size from the server-controlled namelen field and copies the dirent into a single page-cache page. VULNEREBILITY VULNEREBILITY
4.7.26 Avalon New Avalon Malware Framework MALWARE FRAMEWORK
4.7.26 CVE-2026-6684  (CVSS 4.6, Medium) – CVE-2026-6684 covers a GPT entry-count abuse case that can trigger effectively unbounded scanning in older trees. That creates a severe mount-time DoS in affected pre-R0.16 implementations, especially painful in boot paths, but it is ranked last here because upstream R0.16 added protective GPT validation. Now, it's up to implementers to upgrade. VULNEREBILITY VULNEREBILITY
4.7.26 CVE-2026-6686 (CVSS 4.6, Medium) – CVE-2026-6686 describes an uninitialized-cluster exposure path where extending files beyond EOF can leak stale data from previously deleted content. It is an information-disclosure bug with real consequences in multi-stage boot/update and shared-media environments. VULNEREBILITY VULNEREBILITY
4.7.26 CVE-2026-6683 (CVSS 4.6, Medium) – CVE-2026-6683 documents a divide-by-zero condition in exFAT sync/write flows that can be triggered by crafted media and produce reliable crash behavior. In update contexts, this can become a practical bricking vector. While generally more "DoS than RCE," it still offers meaningful attacker value against availability, especially given the OTA implications. VULNEREBILITY VULNEREBILITY
4.7.26 CVE-2026-6685 (CVSS 6.1, Medium) – CVE-2026-6685 describes a condition where on fragmented volumes, arithmetic wrap can drive stale dirty-cache behavior and out-of-bounds memory effects in read/write paths. This can manifest as silent corruption, which is exactly the kind of bug operators hate most: hard to detect, easy to misdiagnose, and dangerous in control/data-logging workloads. VULNEREBILITY VULNEREBILITY
4.7.26 CVE-2026-6688 (CVSS 7.6, High) – With LFN enabled, fno.fname can be much larger than many caller buffers expect, as described by CVE-2026-6688. The bug class appears repeatedly in integrations (strcpy, sprintf, fixed-size name/path fields). This one is tricky to fix entirely in FatFs directly (since exploitation depends on wrappers copying long filenames into undersized local buffers), but it could be mitigated by FatFs changes that make filename lengths and truncation/validation outcomes more explicit to callers. VULNEREBILITY VULNEREBILITY
4.7.26 CVE-2026-6687 (CVSS 7.6, High) – CVE-2026-6687 describes a condition where the exFAT label length field is not adequately capped, enabling oversized writes into caller-provided label buffers. This is especially painful where canonical examples and generated code use small stack buffers. It is a clean memory-corruption primitive in a path many firmware projects expose, at least where exFAT has been enabled. VULNEREBILITY VULNEREBILITY
4.7.26 CVE-2026-6682 In FatFS R0.16 and earlier contains a FAT32 integer overflow bug in mount_volume() where fasize *= fs->n_fats can wrap, leading to attacker-controlled file-size metadata and unsafe read lengths in downstream callers. VULNEREBILITY VULNEREBILITY
4.7.26 Glitch SPY CRIL analyzes Glitch SPY, an Android RAT with 70+ commands, crypto-clipping, and a silent remote browser, giving attackers full device control. MALWARE RAT
4.7.26 Banana RAT In this blog entry, researchers from the TrendAI™ MDR team discuss how they mapped the full end-to-end operation of SHADOW-WATER-063’s Banana RAT banking malware by analyzing server-side artifacts and victim-side data. MALWARE RAT
4.7.26 Void Dokkaebi’s Void Dokkaebi, a North Korea-aligned intrusion set, has updated its information-stealing malware, InvisibleFerret, shifting its delivery format to evade script-based detections. MALWARE STEALER
4.7.26 TONResolver RAT In this blog entry, TrendAI™ Research examines a wave of phishing emails observed in May 2026 that targeted Japanese accommodation facilities using Booking.com, detailing the victims, attack techniques used, and characteristics of the malware involved. MALWARE ANDROID
4.7.26 Arsink RAT The SonicWall Capture Labs threat research team identified an ongoing Android Remote Access Trojan (RAT) campaign that employs multiple techniques to harvest sensitive user information through phishing and data exfiltration activities by impersonating the actual app icons and using similar names. MALWARE ANDROID
4.7.26 Operation DragonReturn Authors: Dixit Panchal & Soumen Burma Table of Contents: Introduction: Key Targets: Infection Chain: Initial Findings about Campaign: Initial Mail: Email Attachment: Lure: Official GoI, Income Tax Document: Technical Analysis: Infrastructural Artefacts & Threat actor Attributions. Campaign Timeline. OPERATION OPERATION
3.7.26 BusySnake Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign MALWARE STEALER
3.7.26 PamStealer PamStealer: a Rust-based macOS infostealer that validates credentials through PAM MALWARE STEALER
3.7.26 Vect Analysis Vect is a newly observed RaaS operation that emerged in December of 2025, with affiliate recruitment and victim postings following shortly after in January 2026. Following the 19th of March 2026 Trivy/LiteLLM supply chain attack conducted by TeamPCP, in which ~340 GB uncompressed data was stolen, Vect announced on the dark web forum “Breached” that they would be partnering with TeamPCP. ANALÝZA ANALÝZA
3.7.26 ‘Popa’ Botnet For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. BOTNET BOTNET
2.7.26 ToddyCat ToddyCat: your hidden email assistant. Part 2 APT APT
2.7.26 JADEPUFFER JADEPUFFER: Agentic ransomware for automated database extortion RANSOM RANSOM
2.7.26 CVE-2026-45659 Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability VULNEREBILITY VULNEREBILITY
2.7.26 CVE-2026-42880 Kubernetes Secret Extraction via ArgoCD ServerSideDiff VULNEREBILITY VULNEREBILITY
2.7.26 CVE-2025-55190 Project API Token Exposes Repository Credentials VULNEREBILITY VULNEREBILITY
2.7.26 CVE-2024-31989 Use of Risky or Missing Cryptographic Algorithms in Redis Cache VULNEREBILITY VULNEREBILITY
2.7.26 AsyncRAT Reloaded AsyncRAT Reloaded: Using Python and TryCloudflare for Malware Delivery Again MALWARE RAT
2.7.26 Veil#Drop Veil#Drop: Blogspot-Hosted PowerShell Loader Delivers PureLog Stealer Through XOR-Encoded In-Memory .NET Payloads MALWARE LOADER
1.7.26 CVE-2026-50548 abuses a setting. The sandbox permits writes into a command's working folder, and that folder is an optional parameter, working_directory, on Cursor's run_terminal_cmd tool. When the agent sets it to a non-default path, Cursor adds that path to the allowed-write list without question. Injected instructions point it at a system file instead of the project. Overwrite the sandbox helper itself (on macOS, /Applications/Cursor.app/Contents/Resources/app/resources/helpers/cursorsandbox), and later commands run with no sandbox at all. Startup files like ~/.zshrc work as targets too. VULNEREBILITY VULNEREBILITY
1.7.26 CVE-2026-50549 abuses a safety check. Before writing, Cursor resolves shortcuts (symlinks) to confirm the real destination sits inside your project. The bug is the fallback: when that check fails, because the target does not exist or the attacker removes read access from a folder in the path, Cursor gives up and trusts the shortcut's in-project path instead. An attacker creates a shortcut that points outside the project, forces the check to fail, and Cursor writes straight through it to the same sandbox helper. Same escape, different door. VULNEREBILITY VULNEREBILITY
1.7.26 DuneSlide DuneSlide: Two Critical RCE vulnerabilities via Zero-Click Prompt Injection in Cursor IDE VULNEREBILITY VULNEREBILITY
1.7.26 LSHIY CAMPAIGN No (Bad) CAP: Inside an Ongoing LSHIY Password Spray Attack CAMPAIGN CAMPAIGN
1.7.26 Global Incident Response Report 2026 While these four trends each present a challenge, attacker success is rarely determined by a single attack vector. In more than 750 incident response (IR) engagements, 87% of intrusions involved activity across multiple attack surfaces. This means defenders must protect endpoints, networks, cloud infrastructure, SaaS applications and identity together. REPORT REPORT
1.7.26 Phantom Squatting Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector HACKING AI
1.7.26 ClickFix: The Gift That Keeps On Giving In the beginning of June I presented the session ClickFix: The Gift That Keeps On Giving at OrangeCon. ClickFix emerged around 2024 and saw a 517% increase in 2025 as described by SANS, the effectiveness of this technique is something we will have to deal with for the upcoming years. HACKING ClickFix
1.7.26 Microsoft Digital Defense Report 2025 Lighting the path to a secure future REPORT REPORT
1.7.26 Espionage Group Abuses Legitimate Cloud Platform in Campaigns Against India In a recent write-up, Acronis TRU Security details two cyber espionage campaigns orchestrated by the China-aligned threat actor Fireant (aka Mustang Panda) against the government and hydropower sectors in India. The threat group compromised public networks, including workstations used by senior administrative personnel, using spear-phishing emails containing malicious ZIP archives. ALERTS CAMPAIGN
1.7.26 TinyRCT backdoor delivered in CL-STA-1062 campaign Active since early 2022, a Chinese-speaking cyberespionage collective tracked as CL-STA-1062 (aka UAT-7237) has maintained a persistent focus on strategic entities across East and Southeast Asia. As reported by Palo Alto researchers, lately the group targeted state-owned energy and governmental organizations in Southeast Asia. To execute their operations, these threat actors employ a blended toolkit. ALERTS CAMPAIGN
1.7.26 CVE-2026-8451 (CVSS score: 8.8) - An insufficient input validation vulnerability leading to memory overread when NetScaler ADC or NetScaler Gateway is configured as a SAML IDP VULNEREBILITY VULNEREBILITY
1.7.26 CVE-2026-8452 (CVSS score: 8.8) - A memory overflow vulnerability leading to unpredictable or erroneous behavior and denial-of-service when the appliance is configured as a Gateway or an AAA virtual server VULNEREBILITY VULNEREBILITY
1.7.26 CVE-2026-8655 (CVSS score: 8.8) - Multiple memory overflow vulnerabilities leading to unpredictable or erroneous behavior and denial-of-service when NetScaler ADC is configured as an LB of type Oracle, a DNS Proxy, or a DNS recursive resolver deployment VULNEREBILITY VULNEREBILITY
1.7.26 CVE-2026-10816 (CVSS score: 7.7) - An external control of the file name of the path vulnerability leading to unauthenticated, arbitrary file read when access to NSIP, Cluster Management IP, or SNIP with management access is enabled VULNEREBILITY VULNEREBILITY
1.7.26 CVE-2026-10817 (CVSS score: 6.9) - An insufficient input validation vulnerability leading to memory overread when TCP TimeStamp is enabled in TCP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler VULNEREBILITY VULNEREBILITY
1.7.26 CVE-2026-13474 (CVSS score: 8.7) - A missing release of memory after effective lifetime vulnerability leading to denial-of-service via malformed HTTP/2 requests when HTTP/2 is enabled in the HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler VULNEREBILITY VULNEREBILITY
1.7.26 Securing AI agents Securing AI agents: When AI tools move from reading to acting AI AI
1.7.26 RustDuck RustDuck: An In-Depth Analysis of a Two-Stage Botnet BOTNET BOTNET