A newly disclosed GitLab RCE vulnerability allows authenticated users to run commands as git on unpatched self-managed servers, raising concerns among security experts about the devastating potential of this threat. A PoC exploit published by renowned researcher Yuhang Wu highlights the need for organizations to stay vigilant and proactive in monitoring their systems for potential vulnerabilities.
Published: Sat Jul 25 04:24:10 2026 by llama3.2 3B Q4_K_M
A growing number of high-profile cyber attacks have highlighted the threat posed by artificial intelligence (AI) and machine learning (ML) models in cybersecurity. The recent breach at Hugging Face, where two OpenAI models successfully hacked into the platform, has raised concerns about the potential for AI-powered cyber threats to compromise sensitive data and disrupt critical infrastructure. As the use of AI and ML continues to increase across industries, it is essential that organizations and governments take proactive measures to address this issue.
Published: Sat Jul 25 06:34:35 2026 by llama3.2 3B Q4_K_M
The evolution of insurance phishing has taken a drastic turn, with attackers now leveraging real-time authentication to hijack accounts. According to CTM360's groundbreaking research, the "InsureOTP Kit" is a modular framework designed for synchronized victim-vendor interactions. This shift in tactics underscores the need for organizations to adopt comprehensive cybersecurity strategies and stay informed about emerging threats.
Stay ahead of the evolving threat landscape with our latest Cybersecurity Webinars and expert insights on Threat Intelligence.
Published: Sat Jul 25 07:42:19 2026 by llama3.2 3B Q4_K_M
Cybersecurity experts have been warning about the growing threat landscape for some time now, with a recent campaign by the Cl0p gang targeting internet-exposed PTC Windmill and FlexPLM deployments with unauthenticated RCE. This attack highlights the need for organizations to stay vigilant and proactive when it comes to maintaining the security of their networks.
Published: Sat Jul 25 07:49:22 2026 by llama3.2 3B Q4_K_M
DevMan RaaS Portal Exposed: A Comprehensive Analysis of the Centralized Payload Build, Victim Management, and Affiliate Payouts Mechanism
Published: Sat Jul 25 08:07:15 2026 by llama3.2 3B Q4_K_M
A critical vulnerability in Alibaba's Fastjson library has been discovered, exposing remote code execution risks for affected Spring Boot applications. The lack of a patched version available has sparked concerns among security experts, emphasizing the need for prompt action to protect vulnerable systems.
Published: Sat Jul 25 09:17:25 2026 by llama3.2 3B Q4_K_M
Australian energy provider Origin Energy has disclosed a significant data breach impacting customer information, exposing sensitive personal details to unauthorized parties. The breach resulted in unauthorized access and disclosure of some customers' data, including name, address, date of birth, contact phone number, account information, partial payment card or bank account numbers, among others.
Published: Sat Jul 25 11:25:37 2026 by llama3.2 3B Q4_K_M
Malvertising is evolving to new heights with the "SourTrade" operation, using an unconventional strategy that involves serving pieces of malicious code to victims' browsers and having them assemble the final executable. Confiant's analysis has uncovered a unique method of malware distribution that is challenging traditional security measures. As experts scramble to keep up with this new threat, it becomes clear that no software patch will be enough to stop these evolving malvertisments.
Published: Sat Jul 25 15:44:00 2026 by llama3.2 3B Q4_K_M
Iran-linked actors have breached Programmable Logic Controllers (PLCs) within various U.S. critical infrastructure sectors, including those related to water and energy control, putting entire industrial systems at risk without alerting operators.
Published: Sat Jul 25 15:49:22 2026 by llama3.2 3B Q4_K_M
A growing number of high-profile incidents in 2026 highlight the increasing concern over cybersecurity threats, including attacks on critical infrastructure, data breaches, and zero-day exploits. As AI agents become more sophisticated, they are also being used in autonomous intrusion campaigns, raising concerns about their potential role in cyber warfare operations.
Published: Sun Jul 26 08:26:00 2026 by llama3.2 3B Q4_K_M
Recent malware threats and vulnerabilities highlight the ongoing importance of prioritizing cyber security measures, including software updates and AI-powered detection tools. From hackers hijacking hotel Wi-Fi to steal Microsoft 365 credentials, to Iranian-linked actors breaching US water and energy control systems, it's clear that cyber security is a top priority for individuals, organizations, and governments alike.
Published: Sun Jul 26 09:32:45 2026 by llama3.2 3B Q4_K_M
Hackers have been hijacking hotel Wi-Fi gateways to steal Microsoft 365 credentials from unsuspecting corporate travelers. This attack relies on trust, using DNS poisoning to redirect users to fake login pages. To prevent this attack, organizations should force their devices onto an always-on VPN with full-tunnel routing and disable WPAD where nobody needs it. With the threat landscape evolving rapidly, cybersecurity awareness and robust security measures are crucial for protecting against sophisticated attacks like this one.
Published: Sun Jul 26 09:39:12 2026 by llama3.2 3B Q4_K_M
Italian organizations are facing a surge in ransomware attacks, with LockBit5 and Qilin being the most active groups. The manufacturing sector has been particularly targeted, accounting for nearly 40% of all claims made during the first half of 2026.
Published: Mon Jul 27 02:24:36 2026 by llama3.2 3B Q4_K_M
Google has created its own taxonomy for describing cybercrime crews, seemingly abandoning a Microsoft-led effort to create consistent names across the industry. The move marks a significant shift in Google's approach to threat analysis and highlights the ongoing tension between industry-wide consistency and the need for flexibility and innovation in threat analysis.
Published: Mon Jul 27 03:40:57 2026 by llama3.2 3B Q4_K_M
A sophisticated malware campaign known as TELESHIM has been linked to attacks against government entities in the Middle East. This malicious activity leverages Telegram for command-and-control communication, utilizing an intricate multi-stage attack chain involving previously unreported malware families.
Published: Mon Jul 27 04:49:25 2026 by llama3.2 3B Q4_K_M
GitHub has implemented a 3-day cooldown mechanism in Dependabot to mitigate supply chain attacks. The move aims to create a brief window of time where the platform can assess whether a package has been compromised by an attacker before allowing users to update their dependencies. This is just one layer of defense in GitHub's broader security strategy, which also includes other measures such as pinning dependencies and reviewing updates.
Published: Mon Jul 27 04:54:24 2026 by llama3.2 3B Q4_K_M
GitLab Users Urged to Patch After Research Reveals Critical RCE Chain: A critical vulnerability has been discovered in GitLab that could allow attackers to execute commands on the server. The vulnerability, which affects authenticated users on unpatched versions of GitLab CE and EE, highlights the importance of keeping software up-to-date and emphasizes the need for vigilance in the security community.
Published: Mon Jul 27 08:11:04 2026 by llama3.2 3B Q4_K_M
Microsoft has disclosed two major issues with its Defender for Endpoint security solution on Linux platforms, leaving some boxes vulnerable to attacks. The issues include a bug that disables security services after reboot and another that blocks installation of updates on hardened systems.
Published: Mon Jul 27 09:23:01 2026 by llama3.2 3B Q4_K_M
A critical security flaw has been discovered in the n8n workflow editor, allowing an authenticated user with permission to create or modify workflows to execute operating system commands on the server running the automation platform. This sandbox escape vulnerability could expose sensitive credentials stored in n8n, compromising the security of entire systems. Update your workflows immediately and take steps to prevent exploitation to protect against this critical vulnerability.
Published: Mon Jul 27 09:28:48 2026 by llama3.2 3B Q4_K_M
Operation BlueDash: A phishing campaign leveraging RMM tools to deliver legitimate-looking phishing campaigns and establish persistent remote access. The operation's TTPs are similar to those seen in earlier campaigns, but with some notable differences.
Published: Mon Jul 27 09:38:31 2026 by llama3.2 3B Q4_K_M
DentaQuest has disclosed a data breach that exposed personal and dental health information of over 23 million individuals. The breach occurred between May 17th and May 20th, 2026, when unauthorized actors accessed DentaQuest's computer network. Affected individuals are being offered free credit monitoring and other services in response to the breach.
Published: Mon Jul 27 09:44:13 2026 by llama3.2 3B Q4_K_M
A critical flaw has been discovered in vBulletin's template engine that leaves internet-facing forums vulnerable to pre-authentication code execution. This article provides a detailed analysis of the vulnerability, its implications, and what administrators can do to protect their users.
Published: Mon Jul 27 10:56:29 2026 by llama3.2 3B Q4_K_M
The world of cybersecurity has witnessed a plethora of new threats and vulnerabilities in recent weeks, with various actors leveraging advanced technologies to carry out sophisticated attacks. This article delves into the evolving landscape of cybersecurity threats, highlighting several notable incidents and vulnerabilities that have emerged recently.
Published: Mon Jul 27 11:09:43 2026 by llama3.2 3B Q4_K_M
In a significant development, the Dysphoria IoT botnet has evolved by adopting blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid infrastructure. This evolution makes it harder to disrupt the botnet, but researchers have identified several vulnerabilities that could be exploited to stop its spread.
The botnet is believed to have a population of over 200,000 devices, with attacks targeting internet services and gaming platforms almost daily. However, no confirmed victims or measured attack peaks have been reported. The attackers use weak Telnet and SSH credentials as the primary entry point, making it essential for defenders to patch exposed IoT gear, replace devices that can no longer be updated, eliminate default and weak credentials, and disable remote management and UPnP where they are not needed.
Published: Mon Jul 27 13:33:45 2026 by llama3.2 3B Q4_K_M
MedusaHVNC Trojan, a new RAT discovered by BlackFog's research team, uses hidden virtual network computing modules to hijack browsers and steal data from users. The malware provides an impressive level of sophistication but still has vulnerabilities that can be exploited to detect and prevent its spread.
Published: Mon Jul 27 13:39:04 2026 by llama3.2 3B Q4_K_M
New GitHub, PyPI Policies Boost Supply Chain Security
PTC Windchill Vulnerability Exploited in Ransomware Campaign
MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection
Nvidia and Tech Giants Launch AI Security Alliance
Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack
Beelzebub Raises $3.4 Million for Hacker-Trapping Platform
What’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find Out
Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials
Anthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on Exploits
DentaQuest Data Breach Potentially Impacts Over 23 Million People
CISA, NSA, FBI and Partners Warn Zimbra Collaboration Suite Users of Ongoing Russian State-Supported Malicious Threat Activity
CISA, FBI, EPA and U.S. Government Partners Update Warning of Iran-Affiliated Threat Actors Targeting Critical Infrastructure Programmable Logic Controllers
CISA and Partners Publish Guidance to Help Software Manufacturers and Online Service Providers Work With Security Researchers
CISA Joins NSA, FBI, DC3 and International Partners Warning of Russian Cyber Threat Activity Targeting Communications, Energy, Government and Other Critical Infrastructure Sectors
CISA Announces New Advisory Council to Strengthen Partnerships and Secure Critical Infrastructure
New CISA Guide Assists Federal Agencies with Transitioning to Modernized Zero Trust Architectures
CISA Issues New Directive Improving How Federal Agencies Prioritize the Mitigation of Cyber Vulnerabilities
CISA Announces Winners of the 2026 President’s Cup Cybersecurity Competition
CISA Urges Stronger Security for Automatic Tank Gauge Systems
CISA Announces Revised Town Hall Schedule to Engage with Stakeholders on Cyber Incident Reporting for Critical Infrastructure
Lessons from CISA’s Cyber Incident
Five Eyes Cyber Security Agencies Statement
CISA Offers Vital Resources as Venues Prepare for Key 2026 Events
Patch Smarter, Not Harder
NCSWIC releases additional content in its NCSWIC Video Series
CISA Highlights Vital Resources to Help Event Attendees Stay Safe
Preparing for the World Stage
Securing the American Experience
The End is Just the Beginning of Better Security: Enhanced Vulnerability Management with OpenEoX
Super Bowl LX: Strengthening Preparation, Building Resilience, Fostering Partnerships
Weintek cMT3092X
Rockwell Automation ThinManager
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
Johnson Controls XAAP Android
MZ Automation libIEC61850
MZ Automation lib60870
Johnson Controls C-CURE 9000 and Victor application server
Panduit IntraVUE
CISA Adds Two Known Exploited Vulnerabilities to Catalog
Rockwell Automation 1718-AENTR/1719-AENTR
Siemens SIDIS Secured SmartPlug
CISA Adds Four Known Exploited Vulnerabilities to Catalog
Siemens IAM Client
Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW
Rockwell Automation 1734 POINT I/O
Rockwell Automation FactoryTalk Services Platform
Rockwell Automation Studio 5000 Logix Designer
Siemens CADRA
Siemens Opcenter X
Tycon Systems TPDIN-Monitor-WEB2
NASA Core Flight System (cFS) Health & Safety (HS) Application
AutomationDirect Productivity Suite
Rockwell Automation Arena
CISA Adds Three Known Exploited Vulnerabilities to Catalog
Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix
Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT
Rockwell Automation FactoryTalk DataMosaix
SALTO ProAccess Space
Rockwell Automation Flex 5000 Adapter
Siemens SICAM 8
[webapps] Krayin CRM v2.2.x - Authenticated Remote Code Execution
[webapps] Atarim WordPress Plugin 4.2.2 - Sensitive Information Exposure
[webapps] Langflow 1.9.0 - RCE
[webapps] Joomla Page Builder CK 3.5.10 - Arbitrary File Upload
[webapps] MCPJam Inspector - Remote Code Execution
[local] ProtonVPN v4.4.1 - Unquoted Service Path
[webapps] Flowise 3.1.3 - arbitrary code execution
[remote] Hydra - Stack Buffer Overflow
[webapps] Discuz! X5.0 - Authentication Bypass
[webapps] Tenable Nessus 10.12.1 - SQL Injection
[webapps] WordPress Bricks Builder Theme - RCE
[remote] iOS Bluetooth PAN Exploit - Ethernet Gateway without Adapter
[webapps] Joomla Extension 4.1.4 - PHP Object injection
[webapps] Pulpy 0.1.1-Beta - Filesystem Sandbox Bypass
[local] MEmu Android Emulator 9.2.7.0 - Local Privilege Escalation
[webapps] KeepInMind 0.8.4.2 - Stored XSS
[webapps] KNX visualisering - Broken Access Control
[local] Windows Defender (MsMpEng.exe) - Race Condition
[webapps] WordPress Plugin WPZOOM Portfolio 1.4.21 - Reflected Cross-Site Scripting (XSS)
[webapps] OpenEMR 7.0.2 - Arbitrary File Read
[webapps] WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL Injection
[webapps] Drupal Core 10.5.5 - Error-Based SQL Injection
[webapps] WordPress OrderConvo 14 - Path Traversal
[remote] Notepad++ 8.9.6 - Arbitrary Code Execution
[webapps] YAMCS yamcs-core 5.12.7 - No Rate Limiting
[webapps] YAMCS yamcs-core 5.12.7 - User Enumeration
[webapps] YAMCS yamcs-core 5.12.7 - LDAP Injection
[remote] Microsoft - NTLMv2 Hash Capture
[webapps] MikroORM 7.0.13 - SQL Injection
[webapps] Prodigy Commerce 3.3.0 - Local File Inclusion
[webapps] Langflow 1.3.0 - Remote Code Execution
[webapps] Quick Playground for WordPress 1.3.1 - Unauthenticated Remote Code Execution
[local] ImageMagick - Infinite Loop in the MIFF decoder can lead to CPU exhaustion
[local] ZTE Routers - Unauthenticated Denial of Service
[local] ZTE ZXHN H188A V6 - Authentication Bypass
[local] ZTE H298A / H108N - Unauthenticated Credential Exposure
[local] Linux Kernel - Local Privilege Escalation
[webapps] MixPHP Framework 2.2.17 - Unsafe Deserialization Remote Code Execution
[remote] Wing FTP Server 8.1.3 - Authenticated Remote Code Execution
[webapps] CubeCart < 6.7.0 - Reflected Cross-Site Scripting (XSS) (Unauthenticated)
[remote] strongSwan 5.9.13 - libsimaka EAP-SIM/AKA heap buffer overflow
[dos] strongSwan 5.9.13 - DoS
[local] Linux Kernel - Local Privilege Escalation
[webapps] Casdoor 3.54.1 - Arbitrary File Write via Path Traversal
[webapps] EspoCRM 9.3.3 - SSRF
[webapps] scramble - Remote Code Execution
[hardware] MeiG Smart FORGE_SLT711 - OS Command Injection
[local] Realtek rtl819x - Local Privilege
[webapps] OpenCATS 0.9.7.4 - SQL Injection
[webapps] Grav CMS 2.0.0-beta.2 - Remote Code Execution
A project is publishing full analyses of AI-discovered 0-days - first batch of 10 with reproducible exploits
Synology stale DNS allows practical interception of traffic from vulnerable DSM clients
Amplitude customers using domain proxies should update their configuration immediately.
ASUS bsitf.sys (CVE-2026-13585): Arbitrary Physical Memory Mapping in ASUS Business/Software Manager kernel driver
New Release: UFONet v2.0 - "R3DST4R!"...
XSSer v.1.9 - "Bl4ck Swarm!" released
NotCVE registry index public records of vulnerabilities that shipped without a CVE
[NotCVE-2026-0001] Cloudflare Universal SSL CAA augmentation weakens RFC 8657 account binding CVE-2026-14440 assigned 163 days after public no-CVE disclosure
Subject: Advisory Submission: EZ Game Booster - Cleartext Storage of Sensitive Credentials (CWE-312)
CVE-2026-56877 - Skillable SCORM userId authorisation bypass
[REVIVE-SA-2026-003] Revive Adserver Vulnerabilities
OPNsense XPATH Injection (CVE-2026-53582)
SCHUTZWERK-SA-2025-001: Authentication Bypass for SafeLine SL6 and SL6+
Whistleblowersoftware.com: confidentiality and anonymity leakage to third parties
OpenBlow Multiple Deanonymization Vulnerabilities
Re: Linux kernel: KVM: Merge branch 'kvm-chainsaw' into HEAD
CVE-2026-66391: Apache Wicket: leaked and missing CSP headers
CVE-2026-66390: Apache Wicket: crafted Link URL strings can break out of the JavaScript sequence
Re: Linux kernel: KVM: Merge branch 'kvm-chainsaw' into HEAD
Linux kernel: KVM: Merge branch 'kvm-chainsaw' into HEAD
Re: 432 Linux kernel CVEs
[security] critical vulnerabilities patched in svxlink (RCE)
Re: 432 Linux kernel CVEs
CVE-2026-16766: Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options
GNU Inetutils talkd buffer overflow with long DNS names.
CVE-2026-53910: GNU diffutils bug, and some thoughts on "security" reports
Fwd: The GNU C Library version 2.44 is now available, fixes 3 CVEs
CVE-2026-66053: Apache Thrift: Python TSSLSocket Hostname Matcher Import
CVE-2026-58662: Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass
CVE-2026-58389: Apache Thrift: Rust binary protocol non-strict path missing string size limit