HOT NEWS 2026 JULY January(174) February(168) March(221) April(222) May(261) June(255) July(464) August(10) September(0) October(0) November(0) December(0) | STATISTICS (7049)
DATE |
NAME |
INFO |
CATEGORY |
SUBCATE |
|
31.7.26 |
VPS.org one-click deployment templates contain multiple vulnerabilities | VPS.org's one-click deployment templates provision services with default passwords and predefined network bindings instead of generating randomized secrets or applying per-deployment hardening measures. | ALERT | ALERT |
|
31.7.26 |
Understanding
Implicit Trust Errors in Core Carrier Networks through Multi-Agent Flaw Discovery and Analysis |
Cellular core networks (CNs) are critical infrastructure, yet their internal security model has historically relied on physical isolation: interfaces between core components often operate within an assumed trust zone. As CNs transition to cloud-native deployments, this assumption weakens, expanding the attack surface and enabling external adversaries to reach previously internal interfaces. | PAPERS | PAPERS |
|
31.7.26 |
CVE-2026-4368 | Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mixup | VULNEREBILITY | VULNEREBILITY |
|
31.7.26 |
CVE-2026-3055 | Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread | VULNEREBILITY | VULNEREBILITY |
|
31.7.26 |
CVE-2026-8233 | A vulnerability was determined in Dotouch XproUPF 2.0.0-release-088aa7c4. Affected is an unknown function of the component UPF. This manipulation causes improper access controls. A high degree of complexity is needed for the attack. The exploitability is told to be difficult. The vendor was contacted early about this disclosure. | VULNEREBILITY | VULNEREBILITY |
|
S31.7.26 |
CVE-2026-3545 | Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | VULNEREBILITY | VULNEREBILITY |
|
31.7.26 |
ClickFix, EtherHiding & a DPRK Wallet Trail | A fake macOS "update" screen convinced a victim to paste one command into Terminal, installing a Node.js backdoor that takes its orders from an Ethereum smart contract. We reverse-engineered every stage, then followed the money on-chain. | HACKING | HACKING |
|
31.7.26 |
Malicious Cyber Actors Targeting Water and Wastewater Sector Internet Facing Programmable Logic Controllers, Causing Operational Disruptions | The Federal Bureau of Investigation (FBI) and Environmental Protection Agency (EPA) are issuing this Public Service Announcement (PSA) to warn critical infrastructure asset owners and operators that malicious cyber actors (MCAs) are conducting cyber attacks targeting Operational Technology (OT) devices, including Rockwell Automation/AllenBradley Programmable Logic Controllers (PLCs), specifically MicroLogix 1100 and 1400 series. | IC3 | IC3 |
|
31.7.26 |
SGLang contains six different vulnerabilities including RCE, data exfiltration, and credential disclosure | Six vulnerabilities have been discovered within the SGLang project, including remote code execution (RCE), server-side request forgery (SSRF), local file read, credential leakage, and model weight exfiltration on a target server. | ALERT | ALERT |
|
31.7.26 |
foreUP golf management platform's web API contains multiple vulnerabilities | Two vulnerabilities in the REST API were found in Golf Compete foreUP. The first exposes the merchant, Finix, API credentials directly in customer record responses, allowing any user to obtain and use the payment processor account. | ALERT | ALERT |
|
30.7.26 |
SilkLurk | OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia | MALWARE | BACKDOOR |
|
30.7.26 |
OctLurk | OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia | MALWARE | BACKDOOR |
|
30.7.26 |
Toy Ghouls | Toy Ghouls’ new toy: the GenieLocker ransomware | RANSOM | RANSOM |
|
30.7.26 |
Toy Ghouls | Toy Ghouls’ new toy: the GenieLocker ransomware | GROUP | GROUP |
|
30.7.26 |
CosmosEscape | CosmosEscape: Taking Over Every Database in Azure Cosmos DB | VULNEREBILITY | VULNEREBILITY |
|
30.7.26 |
Certighost | Certighost is an Active Directory Certificate Services (AD CS) vulnerability that allowed a low-privileged domain user to impersonate a Domain Controller and achieve domain compromise in the tested AD CS configuration. The issue was addressed in the July 2026 security updates. | VULNEREBILITY | VULNEREBILITY |
|
30.7.26 |
Operation Double Barrel | This technical analysis report was prepared as part of the joint cybersecurity advisory titled “Advisory on Cyberattacks Targeting Korean Citizens and Businesses by State-Sponsored Hacking Groups,” issued by the Republic of Korea’s National Intelligence Service (NIS), National Police Agency (NPA), Korea Internet & Security Agency (KISA), and Financial Security Institute (FSI). | OPERATION | OPERATION |
|
30.7.26 |
SIGNBT | Detailed Analysis of SIGNBT Malware Cluster | MALWARE | CLUSTER |
|
30.7.26 |
AtlasRAT | Not Every Fox is Silver: Inside an AtlasRAT loader chain | MALWARE | RAT |
|
30.7.26 |
SilverFox Evolves | Cato CTRL™ Threat Research: SilverFox Evolves: Abuse of New Drivers and Trusted Software Hijacking Enable Remote Access with ValleyRAT in Japan | GROUP | GROUP |
|
30.7.26 |
TA488 | Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | GROUP | GROUP |
|
30.7.26 |
Arbitrary File Overwrite in Develar app-builder (zipx.Unzip) via Symlink Following on macOS (APFS) | A vulnerability in the zipx.Unzip extraction routine of Develar’s app-builder allows an attacker to overwrite arbitrary files on macOS using Apple File System (APFS). The issue arises from a combination of Unicode normalization collisions and unsafe symlink-following behavior. APFS treats certain Unicode equivalent filenames as identical (e.g., ß ↔ ss), while app builder performs no canonical normalization before validating or writing paths. | ALERT | ALERT |
|
30.7.26 |
OPeNDAP Hyrax is vulnerable to SSRF and Credential Disclosure | A vulnerability has been discovered in the OPeNDAP Hyrax software solution. A remote attacker with the ability to submit crafted requests to an affected Hyrax instance could cause the application to communicate with unauthorized remote systems. Under certain conditions, the vulnerability may also result in the unintended disclosure of user authentication tokens to unauthorized destinations. | ALERT | ALERT |
|
30.7.26 |
CVE-2026-20316 | Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
30.7.26 |
CVE-2026-20316 | Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability | KEV | KEV |
|
30.7.26 |
CVE-2026-47876 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Application Testing Suite. | VULNEREBILITY | VULNEREBILITY |
|
30.7.26 |
CVE-2026-41703 | An unauthenticated remote attacker can cause a Denial of Service by turning off the output of the UPS via Modbus command. | VULNEREBILITY | VULNEREBILITY |
|
30.7.26 |
CVE-2026-41709 | An unauthenticated remote attacker can perform a command injection via Modbus-TCP or Modbus-RTU to gain read and write access on the affected device. | VULNEREBILITY | VULNEREBILITY |
|
30.7.26 |
CVE-2026-66066 | [CVE-2026-66066] Possible arbitrary file read and remote code execution in Active Storage variant processing | VULNEREBILITY | VULNEREBILITY |
|
30.7.26 |
CVE-2026-59726 | Unauthenticated RCE in ruflo MCP bridge default docker-compose deployment | VULNEREBILITY | VULNEREBILITY |
|
29.7.26 |
2026 Minimum Elements for a Software Bill of Materials (SBOM) |
The U.S. Cybersecurity and Infrastructure Security Agency
(CISA), in partnership with the co-authoring organizations, updated the
Minimum Elements for a Software Bill of Materials (SBOM) to reflect current
SBOM needs, while preserving the core principles of the document published
in 2021 by the National Telecommunications and Information Administration (NTIA). |
IC3 | IC3 INDUSTRY |
|
29.7.26 |
CI Fortify - Advice for isolating vital systems | State-sponsored cyber actors routinely target critical infrastructure (CI) to conduct espionage or to pre-position for disruptive and destructive effects in the event of crisis or conflict.4 Cybercriminals continue to opportunistically target CI operators. The sensitivity of the data stored by these entities, and the importance of their services, makes them attractive for cybercriminals seeking to extort victims via data exfiltration or by conducting ransomware attacks for disruptive or destructive purposes | IC3 | IC3 INDUSTRY |
|
29.7.26 |
AT&T's Arris BGW210-700 gateway contains authentication bypass vulnerability in LAN-side management interface | Firmware versions 2.7.7 and earlier of the Arris BGW210-700 residential gateway contain an authentication bypass vulnerability, tracked as CVE-2026-16771, that allows any unauthenticated LAN-side user to read sensitive configuration data and modify device settings through web management endpoints | ALERT | ALERT |
|
29.7.26 |
CVE-2026-10702 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3. | VULNEREBILITY | VULNEREBILITY |
|
29.7.26 |
Flying Eagle | Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon | MALWARE | ANDROID RAT |
|
29.7.26 |
CVE-2025-60004 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-Of-Service (DoS). When an affected system receives a specific BGP EVPN update message over an established BGP session, this causes an rpd crash and restart. A BGP EVPN configuration is not necessary to be vulnerable. | VULNEREBILITY | VULNEREBILITY |
|
29.7.26 |
CryptanalysisBench: Can LLMs do Cryptanalysis? | Cryptanalysis—the task of finding attacks against cryptographic schemes—sits at the intersection of mathematical reasoning and cybersecurity, two areas where LLMs have advanced fastest. | PAPERS | PAPERS |
|
29.7.26 |
Cryptanalysis of 7-Round AES via the Algebraic Structure of its S-box | The AES S-Box is not a random permutation; we show that its algebraic structure allows for improved attacks on 7 rounds in the single-key setting. We focusour efforts on extending a 2 105 chosen plaintext and 2 99-time algorithm designed by | PAPERS | PAPERS |
|
29.7.26 |
HAWK-n Key Recovery Reduces to SVP in Dimension n/2 + 1 |
HAWK is a lattice signature scheme that is currently a
thirdround candidate in NIST’s post-quantum signature competition. We give an unconditional, deterministic polynomial-time reduction from HAWKn key recovery over Kn = Q(ζ2ℓ ) to poly(n) calls to an exact Shortest Vector Problem (SVP) oracle in dimension n/2 + 1, where n = 2ℓ−1 is the ring degree. |
PAPERS | PAPERS |
|
29.7.26 |
HAWK: Having Automorphisms Weakens Key | The search rank-2 module Lattice Isomorphism Problem (smLIP), over a cyclotomic ring of degree a power of two, can be reduced to an instance of the Lattice Isomorphism Problem (LIP) of at most half the rank if an adversary knows a nontrivial automorphism of the underlying integer lattice. | PAPERS | PAPERS |
|
29.7.26 |
HAWK | HAWK is a signature scheme inspired by the introduction of the lattice isomorphism problem (LIP) to signatures [DvW22], and this specification document is based on the article that first described a practical variant [DPPvW22a]. | PAPERS | PAPERS |
|
29.7.26 |
Status Report on the Second Round of the Additional Digital Signature Schemes for the NIST Post-Quantum Cryptography Standardization Process | The National Institute of Standards and Technology (NIST) initiated the public PostQuantum Cryptography (PQC) Standardization Process in December 2016 to select quantum-resistant public-key cryptographic algorithms for standardization in response to the substantial development and advancement of quantum computing. | DIRECTION | DIRECTION |
|
29.7.26 |
Status Report on the First Round of the Additional Digital Signature Schemes for the NIST Post-Quantum Cryptography Standardization Process |
The National Institute of Standards and Technology (NIST) initiated the public Post-Quantum Cryptography (PQC) Standardization Process in December 2016 to select quantum-resistant public-key cryptographic algorithms for standardization in response to the substantial development and advancement of quantum computing. After three rounds of evaluation and analysis, NIST announced the selection of the first algorithms to be standardized. | DIRECTION | DIRECTION |
|
29.7.26 |
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident | A companion technical writeup to our incident disclosure. This post walks through how the intrusion actually worked: the two initial-access vectors, how the agent pivoted and moved laterally, representative examples of the commands that were run and how we investigated with GLM 5.2 (an open-source model). Live credentials, internal hostnames, and specific indicators have been redacted or genericized, while the techniques are described exactly as observed by Hugging Face. | INCIDENT | AI |
|
29.7.26 |
DEV#POPPER | Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan | MALWARE | RAT |
|
29.7.26 |
Tengu | Tengu: A Modernized Mirai That Doesn’t Want to Leave | BOTNET | BOTNET |
|
28.7.26 |
MedusaHVNC | A Hidden Desktop That Steals Live Windows Sessions | MALWARE | RAT |
|
28.7.26 |
CVE-2013-4786 | The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC. | VULNEREBILITY | VULNEREBILITY |
|
28.7.26 |
AutoIT | For a long time, AutoIT has been pretty common in the malware ecosystem. Threat actors still use it because it’s easy to write and powerful. Indeed, it can perform all the required actions to inject a payload into a remote process as you’ll see below. | MALWARE | INJECTOR |
|
28.7.26 |
CVE-2026-62947 | ACL bypass and arbitrary root file read via cgi-io cgi-download | VULNEREBILITY | VULNEREBILITY |
|
28.7.26 |
CVE-2026-63921 | In the Linux kernel, the following vulnerability has been resolved: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). After patch 1/2 in this series, vti6_update() unlinks and relinks the tunnel through t->net. vti6_siocdevprivate() still uses dev_net(dev) for the collision lookup. | VULNEREBILITY | VULNEREBILITY |
|
28.7.26 |
NightLedger backdoor | NightLedger is a recently identified Windows backdoor that we attribute to Mirage Kitten based on code and behavioral similarities to the historical implants developed and used by the group. The implant masquerades as SspiCli.dll and appears to be designed for DLL search-order hijacking, targeting a legitimate AppVShNotify.exe binary. | MALWARE | BACKDOOR |
|
28.7.26 |
CVE-2026-64739 | Apple Libnotify/notifyd Stack Overflow (CVE-2026-64739) — Discovered by ThreatBook XGPT | VULNEREBILITY | VULNEREBILITY |
|
28.7.26 |
CyberGym-E2E:
Scalable Real-World Benchmark for AI Agents’ End-to-End Cybersecurity Capabilities |
AI has the potential to transform cybersecurity by enabling systems that can autonomously detect, analyze, and remediate software vulnerabilities. However, existing cybersecurity evaluations of AI systems are limited in scale or scope, and fail to capture the end-to-end lifecycle of real-world software vulnerability discovery and remediation | PAPERS | PAPERS |
|
28.7.26 |
CYBERGYM: EVALUATING AI AGENTS’ REAL-WORLD CYBERSECURITY CAPABILITIES AT SCALE |
AI agents have significant potential to reshape cybersecurity,
making a thorough assessment of their capabilities critical. However,
existing evaluations fall short, because they are based on small-scale benchmarks and only measure static outcomes, failing to capture the full, dynamic range of real-world security challenges. To address these limitations, we introduce CyberGym, a large-scale benchmark |
PAPERS | PAPERS |
|
28.7.26 |
CVE-2026-53264 | In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: use RCU with deferred freeing for action lifecycle When NEWTFILTER and DELFILTER are run concurrently it is possible to create a race with an associated action. | VULNEREBILITY | VULNEREBILITY |
|
28.7.26 |
CVE-2026-63077 | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol | VULNEREBILITY | VULNEREBILITY |
|
28.7.26 |
CVE-2025-68686 | Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
28.7.26 |
CVE-2026-16812 | Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
28.7.26 |
CVE-2025-68686 | Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | KEV | KEV |
|
28.7.26 |
CVE-2026-16812 | Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability | KEV | KEV |
|
28.7.26 |
CVE-2025-9528 | A vulnerability was determined in Linksys E1700 1.0.0.4.003. This vulnerability affects the function systemCommand of the file /goform/systemCommand. Executing manipulation of the argument command can lead to os command injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. | VULNEREBILITY | VULNEREBILITY |
|
28.7.26 |
Dysphoria | Dysphoria: A Rising Star in Botnets – Evolution and In-Depth Technical Analysis | BOTNET | BOTNET |
|
28.7.26 |
CVE-2026-61511 | vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. | VULNEREBILITY | VULNEREBILITY |
|
27.7.26 |
DNS Poisoning Tactics | DNS Poisoning Tactics Expand to Hospitality Wi-Fi | HACKING | HACKING |
|
27.7.26 |
JIVS PhishKit | Inside JIVS PhishKit: A Domain-Adaptive Credential Harvester | PHISHING | KIT |
|
27.7.26 |
Bypassing n8n's CVE-2026-27577 | Breaking the Sandbox Again: Bypassing n8n's CVE-2026-27577 Patch | VULNEREBILITY | VULNEREBILITY |
|
27.7.26 |
Operation BlueDash | Operation BlueDash: Multi-RMM Workplace Phishing | OPERATION | OPERATION |
|
27.7.26 |
[Op Report] From SSA Phish to AdaptixC2: A Multi-RAT Intrusion | Over five days in mid-May 2026, an operator engaged a deception workstation in the Deception.Pro environment and executed a near-complete commodity intrusion chain from initial access through domain reconnaissance. | OPERATION | OPERATION |
|
27.7.26 |
Unpacking “Cruciferra”: An Analysis of a Sophisticated Crypter Service |
|||
|
27.7.26 |
Targeted Attack on Government Entities in the Middle East | Part 1 |
|||
|
26.7.26 |
20th USENIX Symposium |
The full Proceedings published by USENIX for the symposium are available for download below. Individual papers can also be downloaded from their respective presentation pages. Copyright to the individual works is retained by the author[s]. |
||
|
26.7.26 |
Slopsquatting | Slopsquatting is a type of cybersquatting. It is the practice of registering a non-existent software package name that a large language model (LLM) may hallucinate in its output, whereby someone unknowingly may copy-paste and install the software package without realizing it is fake. Attempting to install a non-existent package should result in an error, but some have exploited this for their gain in the form of typosquatting | HACKING | Cybersquatting |
|
26.7.26 |
CVE-2026-12569 | A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030 | VULNEREBILITY | VULNEREBILITY |
|
26.726 |
CVE-2025-56383 | Notepad++ v8.8.3 has a DLL hijacking vulnerability, which can replace the original DLL file to execute malicious code. NOTE: this is disputed by multiple parties because the behavior only occurs when a user installs the product into a directory tree that allows write access by arbitrary unprivileged users. | VULNEREBILITY | VULNEREBILITY |
|
26.7.26 |
SourTrade Ad Campaigns | SourTrade: Browser-Assembled Malware Delivered Through Malvertising | CAMPAIGN | CAMPAIGN |
|
25.7.26 |
The NIST Cybersecurity Framework (CSF) 2.0 | The Cybersecurity Framework (CSF) 2.0 is designed to help organizations of all sizes and sectors— including industry, government, academia, and nonprofit — to manage and reduce their cybersecurity risks. It is useful regardless of the maturity level and technical sophistication of an organization’s cybersecurity programs. Nevertheless, the CSF does not embrace a one-size-fitsall approach. | DIRECTION | DIRECTION |
|
25.7.26 |
The Gentlemen RaaS | The Gentlemen RaaS: Origins, OPSEC & OSINT | RANSOM | RaaS |
|
25.7.26 |
Cl0p Exploitation of PTC Windchill & FlexPLM (CVE-2026-12569) | A coordinated Unified Threat Advisory covering active Cl0p ransomware affiliate exploitation of internet-exposed PTC Windchill and FlexPLM deployments — chaining a pre-auth FlexPLM WSDL information disclosure with a Windchill login servlet flaw for unauthenticated RCE, JSP webshell deployment, and double-extortion data theft. | EXPLOIT | EXPLOIT |
|
25.7.26 |
Fastjson RCE (≤1.2.83): Active Exploitation Detected — Detection & Mitigation | A remote code execution vulnerability in Fastjson affects every version up to and including 1.2.83. A remote attacker can run arbitrary code on a vulnerable server by sending it specially crafted JSON — no user privileges, no victim interaction, and no third-party libraries required. ThreatBook TDP® (Threat Detection Platform) has already captured this vulnerability being exploited in the wild, so if you run an affected version without SafeMode enabled, treat remediation as urgent. | EXPLOIT | EXPLOIT |
|
25.7.26 |
FastJson 1.2.83 Remote Code Execution | Everyone used to treat fastjson 1.2.83 as the safe one. It's the last release of the 1.x line, it ships with AutoType turned off by default, and for years the advice has been "just move to 1.2.83 and you are good." Not anymore! | VULNEREBILITY | VULNEREBILITY |
|
25.7.26 |
DevMan Ransomware Threat Actor Report |
In early April 2025, an actor presenting itself as “DevMan” has claimed on X1 to gain access and perform a ransomware attack against the French transport company “doumen”. Since then, the threat actor has proved itself as being highly prolific and was named as one of the top active ransomware attackers in the following months.2 As of July 2025, DevMan has claimed at least 54 victims. | REPORT | REPORT |
|
25.7.26 |
DEVMAN Ransomware | DEVMAN Ransomware: Analysis of New DragonForce Variant | RANSOM | RANSOM |
|
25.7.26 |
Funky Mantis | Funky Mantis operates as a centralized ransomware-as-a-service model. Administrators manage affiliates, distribute access, and support extortion through private communications and a dedicated web platform. The platform combines payload building, finance, negotiation, support, and victim management, giving the service control over affiliate access and operational progress. | GROUP | GROUP |
|
25.7.26 |
CVE-2026-16723 | A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required. | VULNEREBILITY | VULNEREBILITY |
|
25.7.26 |
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite |
A group of Russian state-supported cyber actors has been
targeting and compromisingvarious Western government and commercial
organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian statesupported advanced persistent threat (APT) group’s activity is tracked in thecybersecurity community under several names (see Cybersecurity industry tracking), primarily as “LAUNDRY BEAR,” a name initially coined by the Netherlands General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD). |
IC3 | IC3 INDUSTRY |
|
25.7.26 |
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure | This advisory was originally published on April 7, 2026, to provide tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) related to ongoing cyber exploitation of internetconnected operational technology (OT) devices by Iranian-affiliated advanced persistent threat (APT) actors. The authoring agencies updated this advisory on July 22, 2026, to add new guidance on detecting malicious changes in reusable code modules leveraged within Rockwell Automation PLC programs. | IC3 | IC3 INDUSTRY |
|
25.7.26 |
Cybercrime in the age of AI | AI is rewiring the cybercrime ecosystem. You have six months to prepare. | REPORT | REPORT |
|
24.7.26 |
Logto Identity Platform has authentication and authorization failures in core protocol handling | The Logto platform contains multiple vulnerabilities affecting the identity‑processing pipeline. These flaws reduce the reliability of authentication and authorization decisions and may allow attackers to bypass account‑ownership checks, skip MFA, replay externally issued SSO responses, or submit identity assertions without proper cryptographic or validity checks. Collectively, the issues create several paths for unauthorized access across both local and federated sign‑in flows. | ALERT | ALERT |
|
24.7.26 |
Duplicati backup software v2.3.0.1 is vulnerable to an incorrect permission assignment vulnerability | Duplicati v2.3.0.1 is vulnerable to arbitrary code execution when installed outside the default C:\Program Files\Duplicati 2\ directory. An attacker with local user privileges who can write files to the Duplicati installation directory can execute arbitrary code by placing malicious files, such as DLLs, in that directory. To mitigate this vulnerability, install Duplicati in the default C:\Program Files\ directory or update to the latest fixed version. | ALERT | ALERT |
|
24.7.26 |
Analog Way Picturall Quad Compact Mark II contains a local privilege escalation vulnerability | Version 3.5.8 of Analog Way's Picturall Quad Compact Mark II server contains a local privilege escalation vulnerability, tracked as CVE-2026-14985, due to improper privilege delegation and insufficient input validation in a maintenance script. | ALERT | ALERT |
|
24.7.26 |
Plane contains multi-tenant authorization bypass vulnerability | The project management tool Plane, versions 1.3.0 and earlier, contains a multi-tenant authorization bypass vulnerability in its asset-management API that allows unauthorized users to access, delete, or duplicate assets that belong to other workspaces. | ALERT | ALERT |
|
24.7.26 |
BlueNoroff ClickFix Kit | JUMPSEC has obtained and analysed the source code behind an active BlueNoroff phishing kit used to impersonate Zoom and Microsoft Teams meetings. Unlike previous reporting, this research provides source-level visibility into how the operation works after operators mistakenly exposed JavaScript source maps on live infrastructure. | PHISHING | KIT |
|
24.7.26 |
CVE-2026-54121 | Active Directory Certificate Services Elevation of Privilege Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
24.7.26 |
Disrupting the first reported AI-orchestrated cyber espionage campaign | We have developed sophisticated safety and security measures to prevent the misuse of our AI models. While these measures are generally effective, cybercriminals and other malicious actors continually attempt to find ways around them. | REPORT | REPORT |
|
24.7.26 |
ClickFix Campaigns Targeting Windows and macOS |
Insikt Group identified five distinct ClickFix clusters
sharing the same core human-verification lure despite notable differences in
themes, delivery patterns, and infrastructure. |
REPORT | REPORT |
|
24.7.26 |
TAG-195 Upgrades MaaS Ecosystem with Modular Tools | Insikt Group identified four new TAG-195 malware families that indicate sustained active development and a deliberate architectural transition toward modular, operator-driven tooling. | REPORT | REPORT |
|
24.7.26 |
CVE-2026-21536 | Microsoft Devices Pricing Program Remote Code Execution Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
24.7.26 |
TAG-195 | TAG-195 Upgrades MaaS Ecosystem with Modular Tools | GROUP | GROUP |
|
24.7.26 |
CVE-2026-32194 | filed as command injection under CWE-77, is the public "Search by Image" upload, with the SVG going in base64 as the imageBin field to /images/kblob. | VULNEREBILITY | VULNEREBILITY |
|
24.7.26 |
CVE-2026-32191 | filed as OS command injection under CWE-78, is the crawler route: host the SVG anywhere, hand its URL to the search through the imgurl parameter, and bingbot/2.0 fetches it into the same pipeline. Neither needs authentication, cookies, session state or a click. | VULNEREBILITY | VULNEREBILITY |
|
24.7.26 |
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite | A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian statesupported advanced persistent threat (APT) group’s activity is tracked in the cybersecurity community under several names (see Cybersecurity industry tracking), primarily as “LAUNDRY BEAR,” a name initially coined by the Netherlands General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD). | REPORT | REPORT |
|
24.7.26 |
CVE-2025-27915 | An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. | VULNEREBILITY | VULNEREBILITY |
|
24.7.26 |
0day .ICS attack in the wild | Earlier in 2025, an apparent sender from 193.29.58.37 spoofed the Libyan Navy’s Office of Protocol to send a then-zero-day exploit in Zimbra’s Collaboration Suite, CVE-2025-27915, targeting Brazil’s military. | VULNEREBILITY | ICS |
|
24.7.26 |
CVE-2026-58593 | NodeBB does not bind the claimed author of an inbound ActivityPub object to the authenticated remote actor. The inbound middleware verifies the HTTP-signature actor and checks the origin of object.id, but never validates that attributedTo corresponds to the sender. | VULNEREBILITY | VULNEREBILITY |
|
24.7.26 |
CVE-2026-25589 | RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does not properly validate serialized values processed through the Redis RESTORE command. | VULNEREBILITY | VULNEREBILITY |
|
24.7.26 |
CVE-2026-25243 | Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to execute RESTORE can supply a crafted serialized payload that triggers invalid memory access and may lead to remote code execution. | VULNEREBILITY | VULNEREBILITY |
|
24.7.26 |
CVE-2026-8496 | A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version 5.12.7. A maliciously crafted ICS calendar invitation files allows arbitrary JavaScript execution within the authenticated SOGo webmail session. | VULNEREBILITY | VULNEREBILITY |
|
24.7.26 |
CVE-2025-66376 | Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message. | VULNEREBILITY | VULNEREBILITY |
|
23.7.26 |
Lampion malware returns in campaign targeting Portuguese users | The Acronis Threat Research Unit has uncovered an active Lampion malware campaign targeting users in Portugal through localized administrative and financial phishing lures. The infection vector commences with compressed archives attached to emails containing heavily obfuscated HTML documents. | ALERTS | CAMPAIGN |
|
23.7.26 |
New TrickBot vartiant adopts DNS Tunneling to evade detection | Cybersecurity researchers at FortiGuard Labs recently investigated a novel iteration of the well-known TrickBot malware family that exhibits an evolution in command-and-control (C2) communication tactics. Unlike historical variants that primarily depended on standard HTTP traffic to interact with attacker infrastructure, this variant utilizes DNS tunneling. | ALERTS | VIRUS |
|
23.7.26 |
Multi-Stage Phishing Campaign Uses Fileless Execution to Deploy Phantom Stealer v3.5.0 | Researchers from Seqrite reported on a recently observed phishing operation that leverages realistic corporate lures to compromise enterprise networks. Attackers distribute malicious JavaScript payloads within compressed email attachments, pretending to represent reliable institutions such as the Malaysian Inland Revenue Board or UPS Forwarding Hub. | ALERTS | PHISHING |
|
23.7.26 |
PylangGhost and GolangGhost RATs delivered by Purseweb in the latest ClickFake Interview campaign | SOCRadar’s Threat Research Unit recently detailed the "ClickFake Interview" campaign, a sophisticated social engineering scheme conducted by the North Korea-aligned threat actor Purseweb (aka Famous Chollima, Wagemole). Posing as recruiters on social media platforms, the attackers entice prospects with high-paying opportunities before directing them to fake skill-assessment websites. | ALERTS | VIRUS |
|
23.7.26 |
HollowGraph malware leverages Microsoft 365 Calendar events for C2 communication | Group-IB researchers have uncovered HollowGraph, a novel malware variant attributed with to the Cavern backdoor framework, which is associated with Iranian threat actors targeting organizations in Israel. The malware covertly manages command-and-control (C2) operations by abusing the Microsoft Graph API through a compromised Microsoft 365 accounts, seamlessly blending malicious activity into legitimate network traffic. | ALERTS | VIRUS |
|
23.7.26 |
CVE-2026-62144 | (CVSS score of 9.3): A critical authentication bypass flaw in Security Management and Multi-Domain Security Management that enables unauthenticated remote attackers to execute administrative actions on the Management Server, including run-script and exec-command operations on Security Gateways. | VULNEREBILITY | VULNEREBILITY |
|
23.7.26 |
CVE-2026-62145 | (CVSS score of 7.5): An improper privilege management issue in the Gaia Portal that allows authenticated users with read-only access to escalate privileges and execute commands as root. | VULNEREBILITY | VULNEREBILITY |
|
23.7.26 |
Cookie Crumbles | Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware | VULNEREBILITY | VULNEREBILITY |
|
23.7.26 |
CVE-2026-0257 | Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues. | VULNEREBILITY | VULNEREBILITY |
|
23.7.26 |
FakeGit campaign | AI-Assisted Fake GitHub Repositories Fuel SmartLoader and LummaStealer Distribution | CAMPAIGN | CAMPAIGN |
|
23.7.26 |
SharedRoot | SharedRoot; Escaping the Claude Cowork sandbox | VULNEREBILITY | VULNEREBILITY |
|
23.7.26 |
Chaos RaaS | Unmasking the new Chaos RaaS group attacks | GROUP | GROUP |
|
23.7.26 |
msaRAT | Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel | MALWARE | RAT |
|
23.7.26 |
JadeProx | JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake | OPERATION | OPERATION |
|
23.7.26 |
Large-Scale campaigne | Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign | CAMPAIGN | CAMPAIGN |
|
23.7.26 |
Operation Muck and Load | Malicious Go Module Exposes GitHub Malware Lure Network Spanning 222 Repositories | OPERATION | OPERATION |
|
23.7.26 |
RefluXFS | RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600) | VULNEREBILITY | VULNEREBILITY |
|
23.7.26 |
CVE-2026-64600 | In the Linux kernel, the following vulnerability has been resolved: net: hsr: fix potential OOB access in supervision frame handling Ensure the entire TLV header is linearized before access by adding sizeof(struct hsr_sup_tlv) to the pskb_may_pull() calls. Without this, a truncated frame could cause an out-of-bounds access. | VULNEREBILITY | VULNEREBILITY |
|
23.7.26 |
CVE-2026-16232 | Authentication bypass with SmartConsole login process using application token | VULNEREBILITY | VULNEREBILITY |
|
23.7.26 |
Hermeticreader | The Vulnerability That Turned Adobe's 300M-Install Extension Into a Full WhatsApp Takeover | VULNEREBILITY | VULNEREBILITY |
|
23.7.26 |
CVE-2026-8933 | CVE-2026-8933: Local Privilege Escalation in Set-Capabilities snap-confine | VULNEREBILITY | VULNEREBILITY |
|
23.7.26 |
CVE-2026-48294 | Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origin data disclosure vulnerability. An attacker could exploit this vulnerability to gain access to data regarding the victim's session. | VULNEREBILITY | VULNEREBILITY |
|
23.7.26 |
CVE-2026-29059 | Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to version 1.603.3, an unauthenticated path traversal vulnerability exists in Windmill's get_log_file endpoint "(/api/w/{workspace}/jobs_u/get_log_file/{filename})". | VULNEREBILITY | VULNEREBILITY |
|
22.7.26 |
UAC-0099: LUNCHPOKE, BURNYBEAR, оновлений MATCHBOIL.V2 та використання Notepad++ 8.8.3 | Із середини літа 2026 року CERT-UA відзначено зміну в тактиках, техніках та процедурах кластера кіберзагроз UAC-0099. Зокрема, задокументовано факт запуску програмного засобу реалізації кіберзагроз у вигляді DLL-файлу, замаскованого під плагін з назвою "NppExport.dll", за допомогою легітимного файлу програми Notepad++ 8.8.3, доставленого на комп'ютер у вигляді архіву з іншими штатними програмними компонентами. Крім того, оновлено завантажувач MATCHBOIL та застосовано нові програмні засоби: LUNCHPOKE і BURNYBEAR. | BATTLEFIELD UKRAINE | BATTLEFIELD UKRAINE |
|
22.7.26 |
ExploitGym: Can AI
Agents Turn Security Vulnerabilities into Real Attacks? |
AI agents are rapidly gaining capabilities that could significantly reshape cybersecurity, making rigorous evaluation urgent. A critical capability is exploitation: turning a vulnerability, which is not yet an attack, into a concrete security impact, such as unauthorized file access or code execution. | PAPERS | PAPERS |
|
21.7.26 |
FBI Warns of Scammers Impersonating the IC3 | FBI Warns of Scammers Impersonating the IC3 | IC3 | IC3 PRESS |
|
21.7.26 |
Backdoor.Win32.TOFSEE.VSNTGE26 | This Backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites. | MALWARE | BACKDOOR |
|
21.7.26 |
Trojan.Win64.COROXY.A | This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.It does not have any propagation routine. | MALWARE | TROJAN |
|
21.7.26 |
TrojanSpy.Win32.XTRAT.A | This Trojan Spy arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.It does not have any propagation routine. | MALWARE | TROJAN |
|
21.7.26 |
Anatomy of a Cyber World | Effectively prioritize your investment in cybersecurity through understanding your adversaries and the attack methods targeting your industry and region | REPORT | REPORT |
|
21.7.26 |
CVE-2021-27137 | DD-WRT Stack-Based Buffer Overflow Vulnerability | KEV | KEV |
|
21.7.26 |
CVE-2026-0770 | Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability | KEV | KEV |
|
21.7.26 |
CVE-2026-63030 | WordPress Core Interpretation Conflict Vulnerability | KEV | KEV |
|
21.7.26 |
CVE-2026-60137 | WordPress Core SQL Injection Vulnerability | KEV | KEV |
|
21.7.26 |
CVE-2026-10591 | CVE-2026-10591 - Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths | VULNEREBILITY | VULNEREBILITY |
|
21.7.26 |
CVE-2026-50522 | Microsoft SharePoint Remote Code Execution Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
21.7.26 |
Cybersecurity researchers at XLab identified NadMesh, a new Go-based botnet designed to target exposed artificial intelligence (AI) frameworks and Model Context Protocol (MCP) environments. Operating as an autonomous threat platform, NadMesh integrates expansive cloud network scanning with more than twenty exploitation pathways to compromise systems running Kubernetes, Docker, Redis and more. | ALERTS | AI | |
|
21.7.26 |
A new campaign documented by Fortinet highlights a loader operation targeting global organizations. Attackers initiate the intrusion by impersonating trusted business entities via phishing emails that contain malicious archives. These archives contain heavily obfuscated JScript droppers designed to bypass signature-based detection using string array mapping and control flow flattening. | ALERTS | VIRUS | |
|
21.7.26 |
Researchers from Group-IB recently uncovered a novel macOS malware dubbed ClickLock Stealer. Operating without requiring administrative privileges or system exploits, this modular shell script spreads through deceptive ClickFix prompts hosted on compromised WordPress sites, utilizing Telegram for its C2 infrastructure. | ALERTS | VIRUS | |
|
21.7.26 |
Elastic Security Labs shared details of an emerging threat named Telepuz, a lightweight and modular malware-as-a-service (MaaS) family that has been active since late April 2026. Distributed broadly through ClickFix social engineering campaigns, the attack chain begins when an unsuspecting user executes a malicious PowerShell command on a compromised web page. | ALERTS | VIRUS | |
|
21.7.26 |
UAT-11795 Leverages Trojanized Software Installers to Deliver Custom Python and PowerShell Payloads |
In a recent write-up, Cisco Talos details a financially motivated campaign attributed to the Russian-speaking threat group UAT-11795, which has been active since at least June 2025 against users in the U.S. and Europe. Initial intrusion is achieved via ClickFix social engineering tricks that trigger a weaponized HTA stager, ultimately placing trojanized installers for common administration and collaboration utilities on the endpoint. | ALERTS | APT |
|
21.7.26 |
(A)I Sees What You Don’t: Exploiting New Attack Surfaces in Third-Party Mobile Agents | Third-party mobile agents powered by VisionLanguage Models (VLMs) have emerged as a promising paradigm for automating smartphone interactions. These agents act as high-privilege decision-makers, perceiving device states through screenshots and executing actions via VLM reasoning, transforming how an agent app interacts with the environment (i.e., other apps or the OS). | PAPERS | PAPERS |
|
21.7.26 |
CVE-2026-0257 | Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues. | VULNEREBILITY | VULNEREBILITY |
|
21.7.26 |
LegacyHive | Free micropatches available for "LegacyHive" 0day | VULNEREBILITY | VULNEREBILITY |
|
21.7.26 |
SonicWall Secure Mobile Access 0-day Exploitation | Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation | EXPLOIT | EXPLOIT |
|
21.7.26 |
Considering Simultaneous Voltage-Sensitive Load Reductions | Operators and planners of the Bulk Electric System (BES) should be aware of the risks and challenges associated with voltage-sensitive large loads that are rapidly being connected to the power system. Specifically, when considering data centers and cryptocurrency mining facilities, entities should be aware of the potential for large amounts of voltage-sensitive load loss during normally cleared faults on the BES | REPORT | REPORT |
|
21.7.26 |
PowerHammer: Exfiltrating Data from Air-Gapped Computers through Power Lines |
In this paper we provide an implementation, evaluation, and
analysis of PowerHammer, a malware (bridgeware that uses power lines to
exfiltrate data from air-gapped computers. In this case, a malicious code
running on a compromised computer can control the powerconsumption of the system by intentionally regulating the CPU utilization. |
PAPERS | PAPERS |
|
21.7.26 |
Power Stabilization for AI Training Datacenters |
Large Artificial Intelligence (AI) training workloads
spanning several tens of thousands of GPUs present unique power management challenges. These arise due to the high variability in power consumption during the training. |
PAPERS | PAPERS |
|
21.7.26 |
Bit2Watt: A CyberPhysical Vulnerability Exploiting GPU Workloads Across Power and Computing Infrastructures | Modern data centers increasingly rely on large-scale GPU clusters and on-site renewable energy resources, resulting in a tightly coupled cyberphysical system between computing workloads and power-electronic-dominated grids. | PAPERS | PAPERS |
|
21.7.26 |
CVE-2026-63030 | WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution | VULNEREBILITY | VULNEREBILITY |
|
21.7.26 |
CVE-2025-3248 |
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code. | VULNEREBILITY | VULNEREBILITY |
|
21.7.26 |
JADEPUFFER | JADEPUFFER evolves: The agentic threat actor deploys ransomware built to destroy AI models | RANSOM | AI |
|
21.7.26 |
CVE-2026-6875 | ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. | VULNEREBILITY | VULNEREBILITY |
|
21.7.26 |
AgentBaiting | AgentBaiting: How 800+ Fake AI Skills and MCP Servers Delivered Malware | AI | AI |
|
20.7.26 |
CVE-2025-33053 | External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network. | VULNEREBILITY | VULNEREBILITY |
|
20.7.26 |
HOLLOWGRAPH | HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels | MALWARE | BACKDOOR |
|
20.7.26 |
Russian state actors are compromising IP cameras in Europe for military purposes | Cybersecurity advisory Russian state actors are compromising IP cameras in Europe for military purposes | REPORT | REPORT |
|
20.7.26 |
CVE-2026-14266 | 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
20.7.26 |
Patriot Bait | One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign | CAMPAIGN | CAMPAIGN |
|
20.7.26 |
CVE-2026-42533 |
A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable | VULNEREBILITY | VULNEREBILITY |
|
19.7.26 |
OpenSSL HollowByte | OpenSSL HollowByte: A DoS Hiding in 11 Bytes | VULNEREBILITY | VULNEREBILITY |
|
18.7.26 |
BoryptGrab | Malicious GitHub Campaign: Fake “Arctic Wolf” and 290+ Brand-Impersonation Repositories Deliver BoryptGrab-Lineage Infostealer | MALWARE | INFOSTEALER |
|
18.7.26 |
CVE-2026-53410 | high-severity TOCTOU (time-of-check to time-of-use) race condition affecting Zoom Workplace for Windows before 7.0.5, Zoom Workplace VDI Client and VDI Plugin before 6.5.17/6.6.14, Zoom Rooms for Windows before 7.0.5, and Remote Control for Zoom Contact Center before 7.0.0. | VULNEREBILITY | VULNEREBILITY |
|
18.7.26 |
CVE-2026-53409 | high-severity improper privilege management flaw affecting Zoom Rooms for Windows before version 7.1.0 that could allow an authenticated user with local access to escalate privileges. | VULNEREBILITY | VULNEREBILITY |
|
18.7.26 |
CVE-2026-53411 | high-severity improper input validation flaw affecting the Zoom Workplace VDI Plugin for Windows before version 6.6.14 that could allow an authenticated user with local access to escalate privileges. | VULNEREBILITY | VULNEREBILITY |
|
18.7.26 |
CVE-2026-60137 | WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter. | VULNEREBILITY | VULNEREBILITY |
|
18.7.26 |
CVE-2026-63030 | WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution. | VULNEREBILITY | VULNEREBILITY |
|
18.7.26 |
GTIG AIThreat Tracker: Advances in Threat Actor Usage of AI Tools | Advances in Threat Actor Usage of AI Tools | REPORT | REPORT |
|
18.7.26 |
m-trends-2026-en | m-trends-2026 | REPORT | REPORT |
|
18.7.26 |
AI
Security Report 2026 |
AI SecurityReport 2026 Check Point AI Report • 2nd Annual EditionCheck Point Research AI Security Report 202 | REPORT | REPORT |
|
18.7.26 |
CVE-2026-46817: Vulnerability in the Oracle Payments product of Oracle E-Business Suite | In a recent write-up, Oracle details a critical security flaw in the Oracle Payments module of its E-Business Suite, tracked as CVE-2026-46817. The vulnerability impacts product versions 12.2.3 through 12.2.15 and stems from missing authentication and improper privilege management within the file transmission component. | ALERTS | VULNEREBILITY |
|
18.7.26 |
Operation ShadowRecruit Deploys RMM and SheetAgent RAT | A new campaign documented by Seqrite, dubbed Operation ShadowRecruit, targets Indian job seekers with recruitment-themed lures. Specifically focused on candidates applying for government roles, the attack relies on malicious ZIP archives containing disguised Windows shortcuts. | ALERTS | OPERATION |
|
18.7.26 |
Active Directory Federation Services Privilege Escalation Flaw (CVE-2026-56155) | According to Microsoft, a high-severity vulnerability (CVE-2026-56155) in Active Directory Federation Services (AD FS) is actively being exploited in the wild. The flaw stems from insufficient granularity of access control, allowing an authenticated, local attacker to improperly elevate their privileges on compromised machines. | ALERTS | VULNEREBILITY |
|
18.7.26 |
TuxBot v3 Targets IoT for DDoS Operations | In a recent write-up, Palo Alto Networks details TuxBot v3 Evolution, an advanced internet-of-things botnet framework designed for distributed denial-of-service operations. T | ALERTS | BOTNET |
|
18.7.26 |
Spirals: New Stealthy Ransomware Deployed Against Asian IT Company | A previously unseen ransomware family, named Spirals by its operators, was deployed in a double extortion attack against an IT services company in South Asia in June 2026, the Symantec Threat Hunter Team can reveal. The Rust-based payload is either a new ransomware threat or one purpose-built for this attack. The actor behind the attack remains unknown | ALERTS | RANSOM |
|
18.7.26 |
BoryptGrab-Lineage Infostealer via Fake GitHub Repositories | Researchers at Arctic Wolf recently reported a malicious campaign leveraging hundreds of fake GitHub repositories to deliver a BoryptGrab-lineage infostealer. Actors behind this activity established over 290 deceptive project pages impersonating various legitimate software and security vendors. | ALERTS | VIRUS |
|
18.7.26 |
Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor | More than four years after Symantec first uncovered Backdoor.Daxin, the malware has resurfaced. Symantec's Threat Hunter Team uncovered Daxin in active use on a compromised host in Taiwan in May 2026, long after the tool was last found. | ALERTS | VIRUS |
|
18.7.26 |
LabubaRAT | Blackpoint's Adversary Pursuit Group (APG) has recently identified a previously undocumented Rust-based remote access tool, tracked as LabubaRAT, that masquerades as NVIDIA software. | ALERTS | VIRUS |
|
18.7.26 |
CrashStealer Malware Targets macOS Users via Mimicked Crash Reporter | In a recent write-up, Jamf Threat Labs researchers detail CrashStealer, a native C++ macOS infostealer designed to masquerade as the operating system's built-in crash-reporting framework. The malware is initially distributed via a signed and Apple-notarized dropper disguised as a meeting application, allowing it to easily bypass Gatekeeper protections. | ALERTS | VIRUS |
|
18.7.26 |
Albiriox Android RAT Spread via Fake Bank Rewards | Researchers at D3Lab recently reported an Android campaign abusing a major Italian banking brand to distribute the Albiriox banking RAT. A lookalike domain advertises a fake cash reward and redirects victims to a Telegram bot, which offers money for installing an APK and more for referrals, turning the fraud into a self-propagating distribution channel. | ALERTS | VIRUS |
|
18.7.26 |
CrySome RAT Delivered via Logistics-Themed Phishing Campaign | Researchers at LevelBlue's recently reported a multi-stage intrusion that culminates in deployment of the CrySome remote access trojan. Initial access came from a spear-phishing email impersonating a freight rate confirmation, directing the recipient to an actor-controlled portal that delivered a batch file rather than the expected PDF. | ALERTS | VIRUS |
|
18.7.26 |
GigaWiper Implant Employs Modular Design for Espionage and Irreversible Wiping | A new malware family documented by Microsoft Threat Intelligence, known as GigaWiper, combines multiple legacy destructive payloads into a single Go-based backdoor platform4. Operating in compromised Windows environments since late 2025, this threat masquerades as a OneDrive executable and utilizes legitimate messaging and storage services for command-and-control communication. | ALERTS | VIRUS |
|
18.7.26 |
Salat Stealer deployments bundled with Xeno Executor tool | Salat Stealer is a Go-based information-gathering and spying utility that targets unsuspecting gamers and cryptocurrency holders. The malware spreads primarily via social engineering campaigns, or as recently observed by the Splunk researchers, bundled with third-party game modification tools such as Xeno Executor, a Roblox scripting utility. | ALERTS | VIRUS |
|
18.7.26 |
Everest Ransomware variant | Active since late 2020, Everest is a sophisticated double-extortion ransomware operation targeting diverse global industries including government and healthcare across North America, Europe, and Asia. Initial access is typically gained via phishing, stolen credentials, or exploitation of vulnerable applications. | ALERTS | RANSOM |
|
18.7.26 |
Operation Henhouse | Operation Henhouse: Hundreds of arrests and millions in assets seized in month tackling fraud | OPERATION | OPERATION |
|
18.7.26 |
CVE-2026-44761 | SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data. Successful exploitation results in high impact on confidentiality and integrity, with no impact on availability. | VULNEREBILITY | VULNEREBILITY |
|
18.7.26 |
CVE-2026-44747 | SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability. This has high impact on confidentiality, integrity, and availability of the application. | VULNEREBILITY | VULNEREBILITY |
|
18.7.26 |
Jalisco Toolkit | The Jalisco Toolkit and AI-Powered Phishing Surge | PHISHING | TOOL |
|
18.7.26 |
CVE-2026-25089 | Fortinet FortiSandbox OS Command Injection Vulnerability | KEV | KEV |
|
18.7.26 |
CVE-2026-39808 | Fortinet FortiSandbox OS Command Injection Vulnerability | KEV | KEV |
|
18.7.26 |
CVE-2026-58644 | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | KEV | KEV |
|
18.7.26 |
CVE-2026-46817 | Oracle E-Business Suite Improper Privilege Management Vulnerability | KEV | KEV |
|
18.7.26 |
CVE-2023-4346 | KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability | KEV | KEV |
|
18.7.26 |
CVE-2026-56164 | Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability | KEV | KEV |
|
18.7.26 |
CVE-2026-56155 | Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability | KEV | KEV |
|
18.7.26 |
CVE-2026-15410 | SonicWall SMA1000 Appliances Code Injection Vulnerability | KEV | KEV |
|
18.7.26 |
CVE-2026-15409 | SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability | KEV | KEV |
|
18.7.26 |
Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditions | A denial-of-service (DoS) vulnerability exists in some HTTP/2 server implementations that fail to adequately limit resource consumption when buffering response data under stalled flow-control conditions. A remote, unauthenticated attacker can trigger memory exhaustion and service interruption by using standard flow-control parameters such as SETTINGS_INITIAL_WINDOW_SIZE = 0 to stall outbound data for multiple simultaneous request streams. | ALERT | ALERT |
|
18.7.26 |
SGLang contains a vulnerable pickle deserialization vulnerability through the expert-parallel subsystem | A Pickle deserialization vulnerability has been discovered within the SGLang project, enabling an attacker to perform remote code execution (RCE) on the target vulnerable server. In order for an attacker to exploit this vulnerability, the expert-parallel backup subsystem must be enabled, and an attacker must have network access to the SGLang service. No patch is available at this time, and no response was obtained from the project maintainers during coordination. | ALERT | ALERT |
|
18.7.26 |
Privilege escalation vulnerability via unprotected IOCTL interface in Pegatron Tdelo64.sys | A privilege escalation vulnerability exists in the tdeio64.sys driver due to an unprotected input/output control (IOCTL) dispatch routine that fails to validate the origin and permissions of user-supplied requests. An unprivileged local attacker can abuse exposed IOCTL dispatch routines [RM1.1][MB1.2]to perform arbitrary kernel memory read and write operations, ultimately obtaining NT AUTHORITY\SYSTEM privileges and compromising the security of the affected system. | ALERT | ALERT |
|
18.7.26 |
node-forge Signature Forgery Vulnerabilities in RSA-PKCS and ED25519 Implementations | Two distinct cryptographic signature verification vulnerabilities exist in Digital Bazaar node-forge, a widely used JavaScript library implementing cryptographic primitives for Node.js and browser environments. These vulnerabilities allow attackers to forge RSA (PKCS#1 v1.5) and Ed25519 signatures under specific, exploitable conditions. | ALERT | ALERT |
|
18.7.26 |
SuccessKey | ChainVeil: A Malicious npm Supply Chain Attack by SuccessKey | ||
|
18.7.26 |
ChainVeil | Sequel to ChainVeil npm Malware Targets Vite Ecosystem | MALWARE | PYTHON |
|
18.7.26 |
NadMesh | NadMesh Botnet Analysis: A Product-Grade Threat for the AI Service Era | BOTNET | BOTNET |
|
18.7.26 |
HelloNet campaign | We identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks). | CAMPAIGN | CAMPAIGN |
|
18.7.26 |
Operation ShadowRecruit | Contents Introduction Key Targets Industries Affected Geographical focus Infection Chain Initial Findings Looking into the Decoy Document Technical Analysis Stage 1 – Initial Infection through LNK file Stage 2 – PowerShell Downloader Analysis Stage 3 – The .NET Dropper... | ||
|
18.7.26 |
CVE-2025-40948 | An attacker leverages an insecure configuration of the xz utility, which executes with root privileges, to read any file on the switch’s file system. This vulnerability enables initial reconnaissance that could reveal critical information such as sensitive configuration files, password hashes and private cryptographic keys. | VULNEREBILITY | VULNEREBILITY |
|
18.7.26 |
CVE-2025-40947 | This critical flaw resides in the feature key validation function. The function fails to sanitize an attacker-controlled payload before inserting it directly into a command executed with root privileges. Exploiting this allows for direct command injection and full root access. | VULNEREBILITY | VULNEREBILITY |
|
18.7.26 |
CVE-2025-40949 | Following privilege escalation, the final vulnerability is exploited in the switch’s web management task scheduler. Improper input sanitization allows an authenticated attacker to inject malicious commands into the system’s root cron table. This establishes persistent code execution, surviving system reboots and maintaining full control. | VULNEREBILITY | VULNEREBILITY |
|
18.7.26 |
PhantomGate Campaign | The PhantomGate Campaign — Obfuscation, Persistence, and Covert Surveillance | CAMPAIGN | CAMPAIGN |
|
18.7.26 |
Starland RAT | Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025. | MALWARE | RAT |
|
18.7.26 |
UAT-11795 | Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025. | ||
|
17.7.26 |
Introducing CylindricalCanine: The GoldenEyeDog subgroup responsible for the April DigiCert incident |
|||
|
17.7.26 |
Since 2015, Qi An Xin Threat Intelligence Center has been closely monitoring the gambling and fraud industries in East Asia and Southeast Asia. In 2020, we published "A Glimpse into the Southeast Asian Gambling Industry: A Look at the Black Market" , which provided a general analysis of the background and environment of the gambling industry. |
|||
|
17.7.26 |
Вектори первинної компрометації UAC-0145 станом на липень 2026 року |
Тривалий час CERT-UA у взаємодії з основними суб'єктами забезпечення кібербезпеки України вживаються адресні заходи, спрямовані на дослідження кластера кіберзагроз UAC-0145 (субкластер UAC-0002, також відомий як Sandworm, APT44, Seashell Blizzard). |
||
| 17.7.26 | EVALUSION | EVALUSION Campaign Delivers Amatera Stealer and NetSupport RAT | CAMPAIGN | CAMPAIGN |
| 17.7.26 | ACR Stealer | ACR Stealer: Two observed intrusion chains amid increased threat activity | MALWARE | STEALER |
| 17.7.26 | TetrisPhantom | Kaspersky uncovers APT campaign targeting APAC government entities | CAMPAIGN | CAMPAIGN |
| 17.7.26 | GoSerpent | GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration | MALWARE | BACKDOOR |
| 17.7.26 | CVE-2026-58644 | Microsoft SharePoint Remote Code Execution Vulnerability | VULNEREBILITY | VULNEREBILITY |
| 16.7.26 | Agent Data Injection Attacks are Realistic Threats to AI Agents | AI agents act on behalf of user prompts, consumingexternal data and taking actions based on the agent context. Prior research on AI agent security has primarily focused on indirect prompt injection (IPI). Its most well-studied category is instruction injection, where attacker-controlled untrusted data is interpreted as an instruction. | PAPERS | PAPERS |
| 16.7.26 | TELEPUZ | TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains | MALWARE | MaaS |
| 16.7.26 | ClickLock Stealer | ClickLock Stealer: Paste Once, Lose Everything | MALWARE | STEALER |
| 16.7.26 | CVE-2026-59208 | n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances configured with more than one trusted token-exchange issuer resolved external identities to local accounts using only the JWT sub claim and ignored the iss claim, allowing an attacker with a valid token from one trusted issuer and a sub matching a victim under another issuer to authenticate as that victim. This issue is fixed in versions 2.27.4 and 2.28.1. | VULNEREBILITY | VULNEREBILITY |
| 16.7.26 | TuxBot v3 | TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development | BOTNET | IoT |
| 16.7.26 | CVE-2026-55040 | Microsoft SharePoint Server Security Feature Bypass Vulnerability | VULNEREBILITY | VULNEREBILITY |
| 16.7.26 | CVE-2026-45659 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | VULNEREBILITY | VULNEREBILITY |
| 16.7.26 | CVE-2026-32201 | Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | VULNEREBILITY | VULNEREBILITY |
| 16.7.26 | Anti-Ledger | “Anti-Ledger” malware: The battle for Ledger Live seed phrases | MALWARE | CRYPTOCURRENCY |
| 16.7.26 | CVE-2026-53411 | (CVSS score: 7.8) - An improper input validation vulnerability in the Zoom Workplace VDI Plugin for Windows before version 6.6.14 that may allow an authenticated user to conduct an escalation of privilege via local access. | VULNEREBILITY | VULNEREBILITY |
| 16.7.26 | CVE-2026-53410 | (CVSS score: 7.0) - A time-of-check to time-of-use (TOCTOU) race condition vulnerability in the installation and uninstallation process of certain Zoom Clients for Windows that could allow an authenticated local user to escalate privileges. | VULNEREBILITY | VULNEREBILITY |
| 16.7.26 | CVE-2026-53409 | (CVSS score: 7.8) - An improper privilege management vulnerability in Zoom Rooms for Windows before version 7.1.0 that may allow an authenticated user to conduct an escalation of privilege via local access. | VULNEREBILITY | VULNEREBILITY |
| 16.7.26 | CVE-2026-15765 | Use after free in Ozone in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) | VULNEREBILITY | VULNEREBILITY |
| 16.7.26 | CVE-2026-15764 | Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) | VULNEREBILITY | VULNEREBILITY |
| 16.7.26 | CVE-2026-15718 | We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6. | VULNEREBILITY | VULNEREBILITY |
| 16.7.26 | CVE-2026-15719 | We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6. | VULNEREBILITY | VULNEREBILITY |
| 16.7.26 | Daxin Returns | Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor | MALWARE | BACKDOOR |
| 16.7.26 | OkoBot | OkoBot: new sophisticated malware framework targets cryptocurrency users | MALWARE | FRAMEWORK |
| 16.7.26 | Miasma Botnet Loader | Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader | BOTNET | BOTNET |
| 16.7.26 | Miasma RAT | AsyncAPI Packages Compromised with Miasma RAT | MALWARE | RAT |
| 15.7.26 | CVE-2026-56164 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | VULNEREBILITY | VULNEREBILITY |
| 15.7.26 | CVE-2026-56155 | Active Directory Federation Services Elevation of Privilege Vulnerability | VULNEREBILITY | VULNEREBILITY |
| 15.7.26 | CVE-2026-15409 | (CVSS score: 10.0) - A Server-side request forgery (SSRF) vulnerability that a remote unauthenticated attacker could exploit to potentially cause the appliance to make requests to an unintended location. | VULNEREBILITY | VULNEREBILITY |
| 15.7.26 | CVE-2026-15410 | (CVSS score: 7.2) - A post-authentication code injection vulnerability rooted in the Appliance Management Console (AMC) that a remote authenticated attacker could exploit to execute arbitrary operating system commands as administrator under certain conditions. | VULNEREBILITY | VULNEREBILITY |
| 14.7.26 | CVE-2026-44747 | SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability. | VULNEREBILITY | VULNEREBILITY |
| 14.7.26 | CVE-2026-27690 | (CVSS score: 9.1) - An HTTP request/response smuggling flaw in SAP Approuter deployments in non-Cloud Foundry environments that allows an unauthenticated attacker to send a specially crafted HTTP request that leads to request-response desynchronization and results in the exposure of user responses and triggers denial-of-service (DoS) attacks. | VULNEREBILITY | VULNEREBILITY |
| 14.7.26 | CVE-2026-44761 | (CVSS score: 9.1) - A use of default credentials flaw in SAP Commerce Cloud that could retain a sample OAuth 2.0 client with publicly documented sample credentials originating from a sample configuration provided in SAP Help Portal documentation. | VULNEREBILITY | VULNEREBILITY |
| 14.7.26 | ClaudeBleed Reopened | Eight Claude for Chrome releases later, the bypass is still six lines of JavaScript. We reported it to Anthropic in May. The code is unchanged in the latest version. | HACKING | AI |
| 14.7.26 | LabubaRAT | LabubaRAT: A Rust Based Remote Access Tool Masquerading as NVIDIA Software | MALWARE | RAT |
| 14.7.26 | Forgotten UEFI shims undermining Secure Boot | ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities | VULNEREBILITY | VULNEREBILITY |
| 14.7.26 | CVE-2026-57219 | (CVSS score: 8.7) - An obsolete HTTP API endpoint ("GET /api/auth") that reveals client secret on RabbitMQ installations that had OAuth 2 configured to use the management.oauth_client_secret configuration key, allowing an attacker to exchange it for an administrator token and obtain full control of every message, queue, user, and broker setting. | VULNEREBILITY | VULNEREBILITY |
| 14.7.26 | CVE-2026-57221 | (CVSS score: 5.3) - A missing authorization that allows any authenticated user who can connect to a virtual host to enumerate all queue and exchange names in that virtual host and read queue message counts and consumer counts, regardless of their actual permissions. | VULNEREBILITY | VULNEREBILITY |
| 14.7.26 | CVE-2026-8863 | UEFI Secure Boot Security Feature Bypass Vulnerability | VULNEREBILITY | VULNEREBILITY |
| 14.7.26 | Is Your Wallet Snitching On You? An Analysis on the Privacy Implications of Web3 | With the recent hype around the Metaverse and NFTs, Web3 is getting more and more popular. The goal of Web3 is to decentralize the web via decentralized applications. Wallets play a crucial role as they act as an interface between these applications and the user. | PAPERS | PAPERS |
| 14.7.26 |
The Masks We
(Think We) Wear: Privacy Threats of Browser-ExtensionWallets in the Web3 Ecosystem |
Cryptocurrency wallets are the primary interface for managing pseudonymous blockchain addresses, viewing balances, and interacting with Web3 applications. Although users typically assume that their addresses remain independent of each other unless intentionally revealed, modern wallets routinely communicate with both blockchain infrastructure and decentralized applications (dApps), generating network-side and web-side signals that may undermine this assumption. | PAPERS | PAPERS |
| 14.7.26 | CVE-2008-4128 | Cisco IOS Cross-Site Request Forgery Vulnerability | KEV | KEV |
| 14.7.26 | Lucide Proxy | Lucide Proxy: Turning Student Web Proxies into DDoS Bots | BOTNET | BOTNET |
| 13.7.26 | CrashStealer | CrashStealer: C++ macOS infostealer posing as crash reporter | MALWARE | MacOS |
| 13.7.26 | ModHeader Malware | ModHeader Malware: Inside the Chrome Spyware Google Removed | MALWARE | Spyware |
| 13.7.26 | codemado | One Misconfigured Server, Three Active Campaigns: Full exposure of three AiTM Phishing Operators | CAMPAIGN | CAMPAIGN |
| 13.7.26 | mail-argenta | One Misconfigured Server, Three Active Campaigns: Full exposure of three AiTM Phishing Operators | CAMPAIGN | CAMPAIGN |
| 13.7.26 | saroula01 | One Misconfigured Server, Three Active Campaigns: Full exposure of three AiTM Phishing Operators | CAMPAIGN | CAMPAIGN |
| 13.7.26 |
EchoLeak: The
First Real-World Zero-Click Prompt Injection Exploit in a Production LLM System |
Large language model (LLM) assistants are increasingly integrated into enterprise workflows, raising new security concerns as they bridge internal and external data sources. This paper presents an in-depth case study of EchoLeak (CVE2025-32711), a zero-click prompt injection vulnerability in Microsoft 365 Copilot that enabled remote, unauthenticated data exfiltration via a single crafted email. | PAPERS | PAPERS |
| 13.7.26 | SpAIware | Spyware Injection Into Your ChatGPT's Long-Term Memory (SpAIware) | MALWARE | SpAIware |
| 13.7.26 | When Claws Remember but Do Not Tell: Stealthy Memory Injection in Persistent Personal Agents | Persistent personal agents combine long-term memory with access to users’ external environments, enabling personalized foreground assistance and proactive background execution. This integration also creates a new path to compromise: untrusted external content can be silently written into persistent memory and later reused as trusted state. | PAPERS | PAPERS |
| 13.7.26 | AI-Assisted Cloud Attack | Inside an AI-Assisted Cloud Attack: Familiar Techniques at Unfamiliar Speed | ATTACK | AI |
| 13.7.26 | GPPStorm | GPPStorm: Fake Google Partner Invitations Target Workspace Credentials | CAMPAIGN | CAMPAIGN |
| 12.7.26 | Official jscrambler npm Package Compromised | Official jscrambler npm Package Compromised Across Multiple Releases | INCIDENT | INCIDENT |
| 12.7.26 | Helix | Helix, a New Name in the Data Extortion Ecosystem? | GROUP | Vishing |
| 12.7.26 | UNK_MassTraction | One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation | GROUP | Cluster |
| 12.7.26 | Forg365 | Inside Forg365: A Telegram-Distributed Sneaky 2FA-Style PhaaS Targeting Microsoft 365 | PHISHING | Phishing-as-a-service |
| 11.7.26 | CVE-2026-48939 | iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability | KEV | KEV |
| 11.7.26 | CVE-2026-56291 | Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability | KEV | KEV |
| 11.7.26 | GNU Wget enables SSRF via unvalidated FTP PASV IPs | GNU Wget, versions 1.25.0 and earlier, contains a server-side request forgery (SSRF) vulnerability in its implementation of FTP passive mode. Because Wget does not properly validate IP addresses obtained from PASV responses, an attacker-controlled FTP endpoint can redirect the client’s connection to arbitrary IPs, potentially exposing internal network host and service responses. | ALERT | ALERT |
| 11.7.26 | Bypassing Tangem Card Security with a Laser Attack | After uncovering a genuine check bypass on the Tangem Android application and a brute-force attack on the card's authentication protocol, the Ledger Donjon turned its attention to the card itself with more advanced tools and sophisticated techniques. What we found is a critical vulnerability that lets an attacker with physical access to a single Tangem card reset its password and steal all associated funds. | HACKING | CARD |
| 11.7.26 | Teardrop Attack | A teardrop attack is when an attacker sends deliberately crafted IP fragments with overlapped offsets and payload lengths to exploit this vulnerability. As a result, the system becomes overwhelmed and may crash or experience severe performance degradation. | ATTACK | IP |
| 11.7.26 | Card tear-off attack | A card tear-off attack (or tearing attack) is a type of fault injection that exploits how smart cards and NFC tags handle power interruptions during write operations. By pulling a card away from an RFID reader or cutting the power at a precise millisecond, an attacker can prevent the card's chip from finalizing state changes. | ATTACK | NFC |
| 11.7.26 | Injective npm Supply Chain Attack: 18 Packages Backdoored to Steal Crypto Wallet Keys | attackers used access to a trusted developer's account to slip a backdoor into a widely used software development kit for the Injective blockchain. Disguised as harmless analytics, the code quietly captured wallet recovery phrases and private keys and sent them to an attacker-controlled server the moment a wallet was created or loaded. | HACKING | CRYPTOCURRENCY |
| 11.7.26 | A Security Analysis of the OpenClaw AI Agent Framework | AI agent frameworks that connect large language model (LLM) reasoning to host execution surfaces—shell, filesystem, containers, browser automation, and messaging platforms—introduce a class of security challenges that differs structurally from those of conventional software | PAPERS | PAPERS |
| 10.7.26 | Before Fraud Transacts | Enabling Proactive Prevention for European Finance(In the Age of Al) | WHITEPAPERS | WHITEPAPERS |
| 10.7.26 | SCMBANKER - a PowerShell toolkit leveraged in a recent ClickFix campaign | Researchers from Elastic reported on a new Mexican banking fraud operation dubbed REF6045. The attack begins when victims encounter deceptive verification screens mimicking CAPTCHA checks. These fraudulent pages trick users into manually executing a system command that downloads SCMBANKER, a malicious PowerShell-based toolkit. | ALERTS | VIRUS |
| 10.7.26 | Android Malware: Redwing | Zimperium's zLabs team has published a report documenting RedWing, an Android spyware variant marketed as a subscription-based malware service through Telegram channels with apparent links to Russian threat actors. The MaaS integrates a customizable dropper constructor that generates convincing phishing sites mimicking legitimate app stores, delivering payloads that abuse Accessibility Services to achieve deep device compromise. | ALERTS | VIRUS |
| 10.7.26 | GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses | Analysis of a recent GodDamn ransomware attack indicates that this seemingly new ransomware is in fact the latest rebrand of the Beast ransomware, which in itself was a rebrand of the Monster ransomware, which was first seen in 2022. The Symantec Threat Hunter Team tracks the developer behind these ransomware families as Hyadina. | ALERTS | RANSOM |
| 10.7.26 | Recent activities attributed to the Swallowtail threat group | The 360 Advanced Threat Research Institute recently exposed a sophisticated cyberespionage campaign conducted by the notorious state-sponsored hacking group Swallowtail (aka APT-C-20, Fancy Bear, APT28). The group is known to leverage a multi-stage infection process starting with a deceptive, macro-enabled documents. To trick users, the file displays randomized characters and hides its malicious intent using visual object manipulation while presenting a fake Eastern European defense ministry decoy. | ALERTS | GROUP |
| 10.7.26 | Financially Motivated Actors Deploying Dual-Threat Vidar Stealer and XMRig Payloads | Palo Alto Networks Unit 42 has recently identified a financially motivated campaign delivering a combination of info-stealing malware and cryptocurrency miners globally. The activity targets corporate and consumer endpoints primarily located in the United States and European Union by using malicious search advertisements for pirated applications. | ALERTS | VIRUS |
| 10.7.26 | MODBEACON | Operation Phnom Penh: Silver Fox Ghost Distributor Targets Specific Victims with MODBEACON Custom Trojan | MALWARE | TROJAN |
| 10.7.26 | Operation Phnom Penh | Operation Phnom Penh: Silver Fox Ghost Distributor Targets Specific Victims with MODBEACON Custom Trojan | OPERATION | OPERATION |
| 10.7.26 | XRING | XRING: Crashing XQUIC with spec-compliant QPACK instructions | HACKING | VULNEREBILITY |
| 10.7.26 | WP-SHELLSTORM | How WP-SHELLSTORM Exposed 1.4M WordPress Sites | OPERATION | OPERATION |
| 10.7.26 | Hidden Links: Analyzing Secret Families of VPN Apps | Ownership transparency in the VPN ecosystem allows users to make informed decisions about who they trust with their data. Researchers have recently begun investigating the relationships between seemingly distinct providers and who operates them, but such analysis is currently limited to a small sample of providers in the VPN ecosystem. | PAPERS | PAPERS |
| 10.7.26 | CVE-2016-2183 | The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack. | VULNEREBILITY | VULNEREBILITY |
| 10.7.26 | CVE-2016-6329 | OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTP-over-OpenVPN session using Blowfish in CBC mode, aka a "Sweet32" attack. | VULNEREBILITY | VULNEREBILITY |
| 10.7.26 |
MVPNalyzer: An Investigative Framework for Auditing the Security & Privacy of Mobile VPNs |
Mobile users increasingly rely on Virtual Private Networks (VPNs) to protect themselves from tracking, surveillance, and censorship. VPN apps operate from a privileged position by requiring interception of user traffic. While this safeguards end user traffic from malicious network intermediaries (e.g. surveilling ISPs), it leads to a critical “transfer of trust” from such network intermediaries to VPN providers. | PAPERS | PAPERS |
| 10.7.26 | O-UNC-066 | Vishing actors target Entra passkey enrollment | GROUP | GROUP |
| 10.7.26 |
Beware of
Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting |
The growing adoption of agentic LLM applicationshas introduced a new threat previously named as promptware. While prior work has established that adversaries can exploit direct channels to LLM applications to apply promptware (push adversarial prompts) under weak threat models (e.g., by sending emails or calendar invitations to a target), many applications do not provide any direct channels that could be exploited for prompt injection beyond the Internet. This raises a fundamental question: | PAPERS | PAPERS |
| 10.7.26 | PayRange Android app version 7.0.7 contains multiple vulnerabilities | PayRange is a mobile payment app that allows users to pay for vending machines, laundromats, and other unattended machines using a smartphone with Bluetooth. Two vulnerabilities were discovered in version 7.0.7 of the PayRange app that is available in the Google Play store. | ALERT | ALERT |
| 10.7.26 | Xerte Online Toolkit contains an authentication bypass that allows for RCE | Two vulnerabilities have been discovered in Xerte Online Toolkits, an open-source e-learning authoring toolsuite intended for the creation of learning materials within a web browser. | ALERT | ALERT |
| 10.7.26 | Adalo Database API Enables Cross-App User Data Extraction via Over-Fetching and Missing Authorization Controls | Adalo’s no‑code application platform exposes complete user records through its database API for all applications built on both V1 and V2. Due to a platform-level flaw, authenticated users can retrieve full user data belonging to any Adalo application, regardless of configuration. This issue affects more than one million applications and placing developers and their end users at risk of data exposure that they cannot prevent or remediate. | ALERT | ALERT |
| 10.7.26 | BLUERABBIT | BLUERABBIT: A Golang-Based Backdoor with Ransomware and Destructive Capabilities | MALWARE | BACKDOOR |
| 10.7.26 | GigaWiper | GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware | MALWARE | WIPPER |
| 9.7.26 | Beast Ransomware | The Nature of the Beast Ransomware | RANSOM | RANSOM |
| 9.7.26 | GodDamn Ransomware | GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses | RANSOM | RANSOM |
| 9.7.26 | CVE-2026-50656 | Microsoft Defender Elevation of Privilege Vulnerability | VULNEREBILITY | VULNEREBILITY |
| 9.7.26 | LapDogs Campaign | Unmasking A New China-Linked Covert ORB Network: Inside the LapDogs Campaign | CAMPAIGN | CAMPAIGN |
| 9.7.26 | SymJack | SymJack: the approval prompt is lying to you. A symlink-hijack RCE in six AI coding agents | AI | AI |
| 9.7.26 | TrustFall | TrustFall: coding agent security flaw enables one-click RCE in Claude, Cursor, Gemini CLI and GitHub Copilot | AI | AI |
| 9.7.26 | CVE-2026-39861 | Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processes from creating symlinks pointing to locations outside the workspace. | VULNEREBILITY | VULNEREBILITY |
| 8.7.26 | The Promptware Kill Chain: How Prompt Injections Gradually Evolved Into a Multistep Malware Delivery Mechanism | Prompt injection was initially framed as the largelanguage model (LLM) analogue of SQL injection. However, over the past three years, attacks labeled as prompt injection have evolved from isolated input-manipulation exploits into multistep attack mechanisms that resemble malware. In this paper, we argue that prompt injections evolved into promptware, a new class of malware execution mechanism triggered through prompts engineered to exploit an application’s LLM. | PAPERS | PAPERS |
| 8.7.26 | Git Hash Chain Malleability | Git commit signing is widely entrusted to serve as evidence that a commit hash uniquely and immutably identifies a specific piece of signed content. We show this invariant does not hold. Given any signed commit, an attacker without access to the signing key, and without breaking SHA2 can produce a second, distinct commit with an identical tree, identical metadata, a valid signature, and a “Verified” badge from a Git Forge such as Github, differing only in its commit hash. | PAPERS | PAPERS |
| 8.7.26 |
Great, Now Write
an Article About That: The Crescendo Multi-Turn LLM Jailbreak Attack |
Large Language Models (LLMs) have risen significantly in popularity and are increasingly being adopted across multiple applications. These LLMs are heavily aligned to resist engaging in illegal or unethical topics as a means to avoid contributing to responsible AI harms. However, arecent line of attacks, known as “jailbreaks”, seek to overcome this alignment. Intuitively, jailbreak attacks aim to narrow the gap between what the model can do and what it is willing to do. In this paper, we introduce a novel jailbreak attack called Crescendo | PAPERS | PAPERS |
| 8.7.26 | Smoke and Mirrors: Jailbreaking LLM-based Code Generation via Implicit Malicious Prompts |
The proliferation of Large Language Models (LLMs) has
revolutionized natural language processing and significantly impactedcode
generation tasks, enhancing software development efficiency and productivity.
Notably, LLMs like GPT-4 have demonstrated remarkable proficiency in
text-to-code generation tasks. However, the growing reliance on LLMs for
code generation necessitates a critical examination of the safety
implications associated with their outputs. Existing research efforts have
primarily focused on verifying the functional correctness of LLMs,
overlooking their safety in code generation. |
PAPERS | PAPERS |
| 8.7.26 |
RedCode: Risky
Code Execution and Generation Benchmark for Code Agents |
With the rapidly increasing capabilities and adoption of code agents for AI-assistedcoding and software development, safety and security concerns, such as generating or executing malicious code, have become significant barriers to the real-world deployment of these agents. To provide comprehensive and practical evaluations on the safety of code agents, we propose RedCode, an evaluation platform with benchmarks grounded in four key principles: real interaction with systems, holistic evaluation of unsafe code generation and execution, diverse input formats, and highquality safety scenarios and tests. | PAPERS | PAPERS |
| 8.7.26 |
Refusal-Trained
LLMs Are Easily Jailbroken As Browser Agents |
For safety reasons, large language models (LLMs) are trained to refuse harmful user instructions, such as assisting dangerous activities. We study an openquestion in this work: does the desired safety refusal, typically enforced in chat contexts, generalize to non-chat and agentic use cases? Unlike chatbots, LLM agents equipped with general-purpose tools, such as web browsers and mobile devices, can directly influence the real world, making it even more crucial to refuse harmful instructions. In this work, we primarily focus on red-teaming browser agents – LLMs that manipulate information via web browsers | PAPERS | PAPERS |
| 8.7.26 |
Refused in Chat,
Written in Code: Workflow-Level Jailbreak Construction in IDE Coding Agents. |
Large language models are increasingly deployed as IDE-integrated coding agents that decompose tasks, generate and edit files, run code, and refine outputs over many turns. Yet their safety is still often evaluated as if they were chatbots: one harmful prompt, one response, judged in isolation. We introduce workflowlevel jailbreak construction, a failure mode in which a harmful objective is assembled across ordinary stages of a softwaredevelopment workflow rather than generated through a single direct prompt. | PAPERS | PAPERS |
| 8.7.26 | CVE-2026-55116 | A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices. | VULNEREBILITY | VULNEREBILITY |
| 8.7.26 | CVE-2026-54402 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device. | VULNEREBILITY | VULNEREBILITY |
| 8.7.26 | CVE-2026-55115 | A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device. | VULNEREBILITY | VULNEREBILITY |
| 8.7.26 | CVE-2026-54400 | A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device. | VULNEREBILITY | VULNEREBILITY |
| 8.7.26 | CVE-2026-50748 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. | VULNEREBILITY | VULNEREBILITY |
| 8.7.26 | CVE-2026-50747 | A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to escalate privileges on the host device. | VULNEREBILITY | VULNEREBILITY |
| 8.7.26 | CVE-2026-50746 | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device. | VULNEREBILITY | VULNEREBILITY |
| 8.7.26 | SCMBANKER | ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit | VULNEREBILITY | VULNEREBILITY |
| 8.7.26 | UAT-7810 | UAT-7810 continues building ORB networks using new malware | MALWARE | BANKING |
| 8.7.26 | CVE-2025-2492 | An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted request, potentially leading to unauthorized execution of functions. Refer to the 'ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information. | VULNEREBILITY | VULNEREBILITY |
| 8.7.26 | CVE-2023-25717 | Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$(curl substring. | VULNEREBILITY | VULNEREBILITY |
| 8.7.26 | CVE-2020-22658 | In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300) before 3.6.2.0.795, Virtual SmartZone (vSZ) before 3.6.2.0.795, ZoneDirector 1100 9.10.2.0.130, ZoneDirector 1200 10.2.1.0.218, ZoneDirector 3000 10.2.1.0.218, ZoneDirector 5000 10.0.1.0.151, a vulnerability allows attackers to switch completely to unauthorized image to be Boot as primary verified image. | VULNEREBILITY | VULNEREBILITY |
| 8.7.26 | CVE-2020-22653 | In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300) before 3.6.2.0.795, Virtual SmartZone (vSZ) before 3.6.2.0.795, ZoneDirector 1100 9.10.2.0.130, ZoneDirector 1200 10.2.1.0.218, ZoneDirector 3000 10.2.1.0.218, ZoneDirector 5000 10.0.1.0.151, a vulnerability allows attackers to exploit the official image signature to force injection unauthorized image signature. | VULNEREBILITY | VULNEREBILITY |
| 8.7.26 | Newly Unveiled Cavern C2 Toolset Targets Israeli Government and IT Sectors | A sophisticated Iran-nexus threat actor dubbed Cavern Manticore has deployed a new post-exploitation framework targeting Israeli networks. Known as "Cavern," this highly modular toolset stands out because it deliberately splits its components across three distinct .NET compilation formats. By blending pure .NET, Mixed-Mode C++/CLI, and NativeAOT binaries, the malware forces defenders to switch between entirely different reverse-engineering workflows, serving as an effective anti-analysis barrier. | ALERTS | APT |
| 8.7.26 | FBI Warns of TeamPCP Cybercrime Group Compromising CI/CD Pipelines | An FBI flash alert warns of extensive software supply chain breaches conducted by the cybercriminal organization TeamPCP. Security teams should monitor for specific custom malware deployed during these operations. This includes CanisterWorm, which is built to harvest cloud access tokens and API keys across AWS, Azure, and GCP infrastructure. | ALERTS | GROUP |
| 8.7.26 | Fake VPN and Media Tools Deliver MarkiRAT | According to Insikt Group, an Iran-linked surveillance campaign is distributing MarkiRAT through fraudulent VPN, media-player and utility applications. The activity primarily targets Farsi-speaking users in Iran, as well as Iranian dissidents and anti-government communities in Europe and North America. | ALERTS | VIRUS |
| 8.7.26 | WriteOut | WriteOut: Abusing the Sandbox for a Critical Cross-Tenant Vulnerability in Writer AI | VULNEREBILITY | VULNEREBILITY |
| 8.7.26 | GitLost | GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos | VULNEREBILITY | VULNEREBILITY |
| 8.7.26 | CVE-2026-26030 | Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within the `InMemoryVectorStore` filter functionality. | VULNEREBILITY | VULNEREBILITY |
| 8.7.26 | CVE-2026-25592 | Semantic Kernel is an SDK used to build, orchestrate, and deploy AI agents and multi-agent systems. Prior to 1.71.0, an Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the SessionsPythonPlugin. | VULNEREBILITY | VULNEREBILITY |
| 8.7.26 | CVE-2026-48282 | (CVSS score: 10.0) - A path traversal vulnerability in Adobe ColdFusion that could lead to arbitrary code execution in the context of the current user. | VULNEREBILITY | VULNEREBILITY |
| 8.7.26 | CVE-2026-56290 | (CVSS score: 10.0) - An improper access control vulnerability in Joomlack Page Builder that could allow for remote code execution via unauthenticated arbitrary file upload. | VULNEREBILITY | VULNEREBILITY |
| 8.7.26 | CVE-2026-55255 | (CVSS score: 6.1) - An authorization bypass through a user-controlled key vulnerability in Langflow that could allow an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. | VULNEREBILITY | VULNEREBILITY |
| 8.7.26 | CVE-2026-48908 | (CVSS score: 10.0) - An unrestricted upload of a file with a dangerous type vulnerability in JoomShaper SP Page Builder that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code. | VULNEREBILITY | VULNEREBILITY |
| 8.7.26 | GhostLock | 15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros | VULNEREBILITY | VULNEREBILITY |
| 8.7.26 | CVE-2026-43499 | In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from futex_requeue(). | VULNEREBILITY | VULNEREBILITY |
| 8.7.26 | Oblivion | Oblivion: The New $300 Android RAT That Beats Every Major Phone Manufacturer’s Security | MALWARE | RAT |
| 8.7.26 | RedWing | RedWing: A Mobile Malware-as-a-Service Operation | MALWARE | ANDROID |
| 8.7.26 | Rogue Agent | Rogue Agent: How a Single Code Block Could Hijack Your AI Conversations in Google’s DialogFlow | CAMPAIGN | CAMPAIGN |
| 7.7.26 | DEBULL | DEBULL: Storm-2372-Style Microsoft Device-Code Phishing With GraphSpy Post-Exploitation | MALWARE | TOOL |
| 7.7.26 | Vshell | Vshell: A Chinese-Language Alternative to Cobalt Strike | MALWARE | TOOL |
| 7.7.26 | CVE-2026-11405 | The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8. - The function contains a normal authentication path using MD5/hash-based password verification (prod_encode64/PasswordToMd5/check_rand_key). | VULNEREBILITY | VULNEREBILITY |
| 7.7.26 | Tenda firmware (multiple versions) contains hidden authentication backdoor | Several versions of Tenda firmware contain an undocumented authentication backdoor that grants administrative access to the devices' web management interfaces. An attacker can expoit this vulnerability, tracked as CVE-2026-11405, to bypass the password verification process and obtain full administrative control without valid credentials. | ALERT | ALERT |
| 7.7.26 | HP Deskjet 2800 Printer Series Webservers contain Missing Authorization Vulnerability | HP Printers in the Deskjet 2800 Series running firmware version <=TBP1CN2612AR contain a missing authorization vulnerability tracked as CVE-2026-13753. This vulnerability allows unauthenticated access to the printer's webserver API endpoints, exposing Wi-Fi credentials, management configuration details, and sensitive security data normally restricted to administrative users. | ALERT | ALERT |
| 7.7.26 | CVE-2026-40138 | A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. | VULNEREBILITY | VULNEREBILITY |
| 7.7.26 | CVE-2026-40139 | A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. | VULNEREBILITY | VULNEREBILITY |
| 7.7.26 | CVE-2026-40140 | BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the network communication subsystem. | VULNEREBILITY | VULNEREBILITY |
| 7.7.26 | CVE-2026-40141 | A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. | VULNEREBILITY | VULNEREBILITY |
| 7.7.26 | Cavern Manticore | Cavern Manticore: Exposing Iran-Linked Modular C2 Framework | GROUP | GROUP |
| 7.7.26 | CVE-2025-52691 | SmarterMail remote code execution vulnerability | VULNEREBILITY | VULNEREBILITY |
| 7.7.26 | CVE-2025-68613 | n8n remote code execution vulnerability | VULNEREBILITY | VULNEREBILITY |
| 7.7.26 | CVE-2025-9316 | N-Central unauthenticated sessionID generation vulnerability | VULNEREBILITY | VULNEREBILITY |
| 7.7.26 | CVE-2025-34291 | Langflow remote code execution vulnerability | VULNEREBILITY | VULNEREBILITY |
| 7.7.26 | CVE-2025-54068 | Laravel Livewire remote code execution vulnerability | VULNEREBILITY | VULNEREBILITY |
| 6.7.26 | Januscape | Januscape: Guest-to-Host Escape in KVM/x86 | VULNEREBILITY | VULNEREBILITY |
| 6.7.26 | CVE-2026-53359 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected role Commit 0cb2af2ea66ad ("KVM: x86: Fix shadow paging use-after-free due to unexpected GFN") fixed a shadow paging mismatch between stored and computed GFNs; the bug could be triggered by changing a PDE mapping from outside the guest, and then deleting a memslot. | VULNEREBILITY | VULNEREBILITY |
| 6.7.26 | CVE-2026-20896 | Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` | VULNEREBILITY | VULNEREBILITY |
| 6.7.26 | Reflecthernet: Exfiltrating 100BASE-TX Ethernet Traffic Using a Retroreflector Hardware Trojan | This work has been submitted to the IEEE for possible publication. Copyright may be transferred without notice, after which this version may no longer be accessible. Electromagnetic eavesdropping is a well-established attack vector for remotely monitoring a target activity, most notably displays, over considerable ranges. | PAPERS | PAPERS |
| 6.7.26 | TEMPEST-LoRa: Cross-Technology Covert Communication | Electromagnetic (EM) covert channels pose significant threats to computer and communications security in air-gapped networks. Previous works exploit EM radiation from various components (e.g., video cables, memory buses, CPUs) to secretly send sensitive information. | PAPERS | PAPERS |
| 6.7.26 | TrojPix: Electromagnetic Covert Channels via Imperceptible Pixel Modulation | Air-gapped networks rely on physical isolation to prevent external connectivity. Prior electromagnetic (EM) covert channels have exploited emissions from video cables, memory buses, and CPUs, yet they rarely achieve high throughput, long range, and visual imperceptibility simultaneously, limiting practical utility in air-gapped settings. | PAPERS | PAPERS |
| 6.7.26 | QuimaRAT | Novel Java-Based QuimaRAT Targets Windows, macOS, and Linux | MALWARE | RAT |
| 6.7.26 | Cyber Criminal Group TeamPCP |
The Federal Bureau of Investigation (FBI) is releasing this
FLASH to highlight the tactics, techniques, and procedures (TTPs) and
indicators of compromise (IOCs) associated with the cyber criminal group
TeamPCP. TeamPCP actors have conducted large-scale software supply chain
compromises by targeting widely used developers and security tools, gaining access to victim environments and extracting sensitive data, including but not limited to cloud access tokens, SSH keys, and Kubernetes secrets. |
IC3 | IC3 INDUSTRY |
| 6.7.26 | Cloak and Detonate: Scanner Evasion and Dynamic Detection of Agent Skill Malware | LLM coding agents increasingly rely on third-party agent skills from public marketplaces, which execute with the agent's privileges and create a software supply-chain attack surface: a malicious skill can steal credentials, exfiltrate source code, or install backdoors. Existing defenses use static skill scanners based on pattern matching or LLM-as-judge analysis, but it remains unclear whether they withstand adaptive evasions that preserve malicious behavior while changing payload appearance. | PAPERS | PAPERS |
| 6.7.26 | Cloak and Detonate: Scanner Evasion and Dynamic Detection of Agent Skill Malware | LLM coding agents increasingly rely on third-party agent skills from public marketplaces, which execute with the agent's privileges and create a software supply-chain attack surface: a malicious skill can steal credentials, exfiltrate source code, or install backdoors. Existing defenses use static skill scanners based on pattern matching or LLM-as-judge analysis, but it remains unclear whether they withstand adaptive evasions that preserve malicious behavior while changing payload appearance. | MALWARE | AI MALWARE |
| 5.7.26 | ChocoPoC | This article details a campaign targeting vulnerability researchers with "ChocoPoC" malware embedded inside trojanised Python dependencies. Exploiting the pressure to quickly test new vulnerabilities, threat actors distribute a persistent Remote Access Trojan (RAT) that exfiltrates data and harvests credentials from compromised developer environments. | MALWARE | RAT |
| 5.7.26 | CVE-2026-20230 | A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. | VULNEREBILITY | VULNEREBILITY |
| 5.7.26 | CVE-2026-46817 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. | VULNEREBILITY | VULNEREBILITY |
| 5.7.26 | Operation Navy Ghost | Operation Navy Ghost: How Attackers Planted a Telegram-Powered Backdoor Across Fake pyrogram Packages on PyPI | OPERATION | OPERATION |
| 5.7.26 | CVE-2026-33825 | Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally. | VULNEREBILITY | VULNEREBILITY |
| 5.7.26 | Operation Contagious Interview | The most effective social engineering campaigns don’t rely on obvious red flags or technical exploits. They move through familiar business interactions, like hiring conversations, project discussions, and routine follow-ups that are designed to feel legitimate from the start. | OPERATION | OPERATION |
| 5.7.26 | PolinRider | PolinRider: North Korea-Linked Supply Chain Campaign Expands Across Open Source Ecosystems | CAMPAIGN | CAMPAIGN |
| 4.7.26 | PureLog Stealer distributed via Veil#Drop framework | Veil#Drop is a sophisticated, multi-phase malware delivery framework designed to deploy PureLog Stealer directly into a system's memory. As reported by researchers from Securonix, the infection chain begins with social engineering, tricking victims into opening a malicious JavaScript file disguised as a legitimate PDF. | ALERTS | VIRUS |
| 4.7.26 | Silent Swap Campaign Deploys Malicious Notes Extension to Intercept Crypto Transactions | In a recent write-up, McAfee Advanced Threat Research details an active campaign, dubbed Silent Swap, that distributes a cryptocurrency-stealing browser extension via sideloading. Delivered via unsigned .NET and Golang installers, the malware targets Chromium-based browsers on Windows endpoints, opportunistically scanning for active browser profiles. | ALERTS | VIRUS |
| 4.7.26 | QuimaRAT: Cross-Platform Remote Access Trojan | LevelBlue has published a report on QuimaRAT, a subscription-based Java remote access trojan designed for Windows, Linux, and macOS. Per their analysis, QuimaRAT decrypts its embedded configuration, validates the host environment, installs platform-specific persistence, and connects to operator infrastructure. | ALERTS | VIRUS |
| 4.7.26 | CVE-2026-55255 - LangFlow vulnerability | CVE-2026-55255 is a recently disclosed critical (CVSS score 9.9) Authentication Bypass vulnerability affecting Langflow (pip), which is an open-source tool for building and deploying AI-powered agents and workflows. If successfully exploited the flaw might allow an authenticated attacker to execute any flow belonging to another user leading to cross-tenant access and potential data exposure. The vulnerability has been fixed in 1.9.2 version of the product. | ALERTS | VULNEREBILITY |
| 4.7.26 | Multiple local privilege escalation vulnerabilities in Little Orbits GameFirst Anti-Cheat | The GamersFirst Anti-Cheat (GFAC) driver GFAC.sys contains multiple local privilege escalations and denial-of-service vulnerabilities stemming from insecure handling of user-controlled input through a minifilter communication port. A local attacker can abuse these flaws to perform arbitrary kernel memory writes, obtain privilege escalation to SYSTEM, or trigger a system crash. | ALERT | ALERT |
| 4.7.26 | Bad Epoll | In the Linux kernel, the following vulnerability has been resolved: eventpoll: fix ep_remove struct eventpoll / struct file UAF ep_remove() (via ep_remove_file()) cleared file->f_ep under file->f_lock but then kept using @file inside the critical section (is_file_epoll(), hlist_del_rcu() through the head, spin_unlock). A concurrent __fput() taking the eventpoll_release() fastpath in that window observed the transient NULL, skipped eventpoll_release_file() and ran to f_op->release / file_free(). | VULNEREBILITY | VULNEREBILITY |
| 4.7.26 | CVE-2026-46242 | In the Linux kernel, the following vulnerability has been resolved: eventpoll: fix ep_remove struct eventpoll / struct file UAF ep_remove() (via ep_remove_file()) cleared file->f_ep under file->f_lock but then kept using @file inside the critical section (is_file_epoll(), hlist_del_rcu() through the head, spin_unlock). A concurrent __fput() taking the eventpoll_release() fastpath in that window observed the transient NULL, skipped eventpoll_release_file() and ran to f_op->release / file_free(). | VULNEREBILITY | VULNEREBILITY |
| 4.7.26 | CVE-2026-31694 | In the Linux kernel, the following vulnerability has been resolved: fuse: reject oversized dirents in page cache fuse_add_dirent_to_cache() computes a serialized dirent size from the server-controlled namelen field and copies the dirent into a single page-cache page. | VULNEREBILITY | VULNEREBILITY |
| 4.7.26 | Avalon | New Avalon Malware Framework | MALWARE | FRAMEWORK |
| 4.7.26 | CVE-2026-6684 | (CVSS 4.6, Medium) – CVE-2026-6684 covers a GPT entry-count abuse case that can trigger effectively unbounded scanning in older trees. That creates a severe mount-time DoS in affected pre-R0.16 implementations, especially painful in boot paths, but it is ranked last here because upstream R0.16 added protective GPT validation. Now, it's up to implementers to upgrade. | VULNEREBILITY | VULNEREBILITY |
| 4.7.26 | CVE-2026-6686 | (CVSS 4.6, Medium) – CVE-2026-6686 describes an uninitialized-cluster exposure path where extending files beyond EOF can leak stale data from previously deleted content. It is an information-disclosure bug with real consequences in multi-stage boot/update and shared-media environments. | VULNEREBILITY | VULNEREBILITY |
| 4.7.26 | CVE-2026-6683 | (CVSS 4.6, Medium) – CVE-2026-6683 documents a divide-by-zero condition in exFAT sync/write flows that can be triggered by crafted media and produce reliable crash behavior. In update contexts, this can become a practical bricking vector. While generally more "DoS than RCE," it still offers meaningful attacker value against availability, especially given the OTA implications. | VULNEREBILITY | VULNEREBILITY |
| 4.7.26 | CVE-2026-6685 | (CVSS 6.1, Medium) – CVE-2026-6685 describes a condition where on fragmented volumes, arithmetic wrap can drive stale dirty-cache behavior and out-of-bounds memory effects in read/write paths. This can manifest as silent corruption, which is exactly the kind of bug operators hate most: hard to detect, easy to misdiagnose, and dangerous in control/data-logging workloads. | VULNEREBILITY | VULNEREBILITY |
| 4.7.26 | CVE-2026-6688 | (CVSS 7.6, High) – With LFN enabled, fno.fname can be much larger than many caller buffers expect, as described by CVE-2026-6688. The bug class appears repeatedly in integrations (strcpy, sprintf, fixed-size name/path fields). This one is tricky to fix entirely in FatFs directly (since exploitation depends on wrappers copying long filenames into undersized local buffers), but it could be mitigated by FatFs changes that make filename lengths and truncation/validation outcomes more explicit to callers. | VULNEREBILITY | VULNEREBILITY |
| 4.7.26 | CVE-2026-6687 | (CVSS 7.6, High) – CVE-2026-6687 describes a condition where the exFAT label length field is not adequately capped, enabling oversized writes into caller-provided label buffers. This is especially painful where canonical examples and generated code use small stack buffers. It is a clean memory-corruption primitive in a path many firmware projects expose, at least where exFAT has been enabled. | VULNEREBILITY | VULNEREBILITY |
| 4.7.26 | CVE-2026-6682 | In FatFS R0.16 and earlier contains a FAT32 integer overflow bug in mount_volume() where fasize *= fs->n_fats can wrap, leading to attacker-controlled file-size metadata and unsafe read lengths in downstream callers. | VULNEREBILITY | VULNEREBILITY |
| 4.7.26 | Glitch SPY | CRIL analyzes Glitch SPY, an Android RAT with 70+ commands, crypto-clipping, and a silent remote browser, giving attackers full device control. | MALWARE | RAT |
| 4.7.26 | Banana RAT | In this blog entry, researchers from the TrendAI™ MDR team discuss how they mapped the full end-to-end operation of SHADOW-WATER-063’s Banana RAT banking malware by analyzing server-side artifacts and victim-side data. | MALWARE | RAT |
| 4.7.26 | Void Dokkaebi’s | Void Dokkaebi, a North Korea-aligned intrusion set, has updated its information-stealing malware, InvisibleFerret, shifting its delivery format to evade script-based detections. | MALWARE | STEALER |
| 4.7.26 | TONResolver RAT | In this blog entry, TrendAI™ Research examines a wave of phishing emails observed in May 2026 that targeted Japanese accommodation facilities using Booking.com, detailing the victims, attack techniques used, and characteristics of the malware involved. | MALWARE | ANDROID |
| 4.7.26 | Arsink RAT | The SonicWall Capture Labs threat research team identified an ongoing Android Remote Access Trojan (RAT) campaign that employs multiple techniques to harvest sensitive user information through phishing and data exfiltration activities by impersonating the actual app icons and using similar names. | MALWARE | ANDROID |
| 4.7.26 | Operation DragonReturn | Authors: Dixit Panchal & Soumen Burma Table of Contents: Introduction: Key Targets: Infection Chain: Initial Findings about Campaign: Initial Mail: Email Attachment: Lure: Official GoI, Income Tax Document: Technical Analysis: Infrastructural Artefacts & Threat actor Attributions. Campaign Timeline. | OPERATION | OPERATION |
| 3.7.26 | BusySnake | Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign | MALWARE | STEALER |
| 3.7.26 | PamStealer | PamStealer: a Rust-based macOS infostealer that validates credentials through PAM | MALWARE | STEALER |
| 3.7.26 | Vect Analysis | Vect is a newly observed RaaS operation that emerged in December of 2025, with affiliate recruitment and victim postings following shortly after in January 2026. Following the 19th of March 2026 Trivy/LiteLLM supply chain attack conducted by TeamPCP, in which ~340 GB uncompressed data was stolen, Vect announced on the dark web forum “Breached” that they would be partnering with TeamPCP. | ANALÝZA | ANALÝZA |
| 3.7.26 | ‘Popa’ Botnet | For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. | BOTNET | BOTNET |
| 2.7.26 | ToddyCat | ToddyCat: your hidden email assistant. Part 2 | APT | APT |
| 2.7.26 | JADEPUFFER | JADEPUFFER: Agentic ransomware for automated database extortion | RANSOM | RANSOM |
| 2.7.26 | CVE-2026-45659 | Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability | VULNEREBILITY | VULNEREBILITY |
| 2.7.26 | CVE-2026-42880 | Kubernetes Secret Extraction via ArgoCD ServerSideDiff | VULNEREBILITY | VULNEREBILITY |
| 2.7.26 | CVE-2025-55190 | Project API Token Exposes Repository Credentials | VULNEREBILITY | VULNEREBILITY |
| 2.7.26 | CVE-2024-31989 | Use of Risky or Missing Cryptographic Algorithms in Redis Cache | VULNEREBILITY | VULNEREBILITY |
| 2.7.26 | AsyncRAT Reloaded | AsyncRAT Reloaded: Using Python and TryCloudflare for Malware Delivery Again | MALWARE | RAT |
| 2.7.26 | Veil#Drop | Veil#Drop: Blogspot-Hosted PowerShell Loader Delivers PureLog Stealer Through XOR-Encoded In-Memory .NET Payloads | MALWARE | LOADER |
| 1.7.26 | CVE-2026-50548 | abuses a setting. The sandbox permits writes into a command's working folder, and that folder is an optional parameter, working_directory, on Cursor's run_terminal_cmd tool. When the agent sets it to a non-default path, Cursor adds that path to the allowed-write list without question. Injected instructions point it at a system file instead of the project. Overwrite the sandbox helper itself (on macOS, /Applications/Cursor.app/Contents/Resources/app/resources/helpers/cursorsandbox), and later commands run with no sandbox at all. Startup files like ~/.zshrc work as targets too. | VULNEREBILITY | VULNEREBILITY |
| 1.7.26 | CVE-2026-50549 | abuses a safety check. Before writing, Cursor resolves shortcuts (symlinks) to confirm the real destination sits inside your project. The bug is the fallback: when that check fails, because the target does not exist or the attacker removes read access from a folder in the path, Cursor gives up and trusts the shortcut's in-project path instead. An attacker creates a shortcut that points outside the project, forces the check to fail, and Cursor writes straight through it to the same sandbox helper. Same escape, different door. | VULNEREBILITY | VULNEREBILITY |
| 1.7.26 | DuneSlide | DuneSlide: Two Critical RCE vulnerabilities via Zero-Click Prompt Injection in Cursor IDE | VULNEREBILITY | VULNEREBILITY |
| 1.7.26 | LSHIY CAMPAIGN | No (Bad) CAP: Inside an Ongoing LSHIY Password Spray Attack | CAMPAIGN | CAMPAIGN |
| 1.7.26 | Global Incident Response Report 2026 | While these four trends each present a challenge, attacker success is rarely determined by a single attack vector. In more than 750 incident response (IR) engagements, 87% of intrusions involved activity across multiple attack surfaces. This means defenders must protect endpoints, networks, cloud infrastructure, SaaS applications and identity together. | REPORT | REPORT |
| 1.7.26 | Phantom Squatting | Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector | HACKING | AI |
| 1.7.26 | ClickFix: The Gift That Keeps On Giving | In the beginning of June I presented the session ClickFix: The Gift That Keeps On Giving at OrangeCon. ClickFix emerged around 2024 and saw a 517% increase in 2025 as described by SANS, the effectiveness of this technique is something we will have to deal with for the upcoming years. | HACKING | ClickFix |
| 1.7.26 | Microsoft Digital Defense Report 2025 | Lighting the path to a secure future | REPORT | REPORT |
| 1.7.26 | Espionage Group Abuses Legitimate Cloud Platform in Campaigns Against India | In a recent write-up, Acronis TRU Security details two cyber espionage campaigns orchestrated by the China-aligned threat actor Fireant (aka Mustang Panda) against the government and hydropower sectors in India. The threat group compromised public networks, including workstations used by senior administrative personnel, using spear-phishing emails containing malicious ZIP archives. | ALERTS | CAMPAIGN |
| 1.7.26 | TinyRCT backdoor delivered in CL-STA-1062 campaign | Active since early 2022, a Chinese-speaking cyberespionage collective tracked as CL-STA-1062 (aka UAT-7237) has maintained a persistent focus on strategic entities across East and Southeast Asia. As reported by Palo Alto researchers, lately the group targeted state-owned energy and governmental organizations in Southeast Asia. To execute their operations, these threat actors employ a blended toolkit. | ALERTS | CAMPAIGN |
| 1.7.26 | CVE-2026-8451 | (CVSS score: 8.8) - An insufficient input validation vulnerability leading to memory overread when NetScaler ADC or NetScaler Gateway is configured as a SAML IDP | VULNEREBILITY | VULNEREBILITY |
| 1.7.26 | CVE-2026-8452 | (CVSS score: 8.8) - A memory overflow vulnerability leading to unpredictable or erroneous behavior and denial-of-service when the appliance is configured as a Gateway or an AAA virtual server | VULNEREBILITY | VULNEREBILITY |
| 1.7.26 | CVE-2026-8655 | (CVSS score: 8.8) - Multiple memory overflow vulnerabilities leading to unpredictable or erroneous behavior and denial-of-service when NetScaler ADC is configured as an LB of type Oracle, a DNS Proxy, or a DNS recursive resolver deployment | VULNEREBILITY | VULNEREBILITY |
| 1.7.26 | CVE-2026-10816 | (CVSS score: 7.7) - An external control of the file name of the path vulnerability leading to unauthenticated, arbitrary file read when access to NSIP, Cluster Management IP, or SNIP with management access is enabled | VULNEREBILITY | VULNEREBILITY |
| 1.7.26 | CVE-2026-10817 | (CVSS score: 6.9) - An insufficient input validation vulnerability leading to memory overread when TCP TimeStamp is enabled in TCP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler | VULNEREBILITY | VULNEREBILITY |
| 1.7.26 | CVE-2026-13474 | (CVSS score: 8.7) - A missing release of memory after effective lifetime vulnerability leading to denial-of-service via malformed HTTP/2 requests when HTTP/2 is enabled in the HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler | VULNEREBILITY | VULNEREBILITY |
| 1.7.26 | Securing AI agents | Securing AI agents: When AI tools move from reading to acting | AI | AI |
| 1.7.26 | RustDuck | RustDuck: An In-Depth Analysis of a Two-Stage Botnet | BOTNET | BOTNET |
|
|
|
|
|
|