Archive
All articles, newest first. Page 1.

FortiBleed: 75,000 Firewalls at Risk from Stolen Credentials, Not a Zero-Day
FortiBleed hits already-patched FortiGate devices: credentials stolen in prior incidents enable administrative access without exploiti…

Security Vendor Jscrambler Becomes Supply-Chain Vector: 5 Malicious npm Versions
Threat actors compromised Jscrambler's npm publishing credentials and released five malicious versions of the jscrambler package conta…

CrashStealer: The macOS Malware That Fooled Apple Itself
CrashStealer, a native C++ macOS infostealer, was distributed via a dropper signed and notarized by Apple, bypassing Gatekeeper checks…

CISA Adds Two Joomla Zero-Days to KEV Catalog: Deadline July 13
On July 10, 2026, CISA added two actively exploited zero-day vulnerabilities in Joomla extensions to its Known Exploited Vulnerabiliti…

RedHook RAT: Android Malware Gains Shell Access Without Root or PC
The RedHook trojan upgrades its arsenal by abusing Wireless ADB, Shizuku, and Accessibility Service to obtain shell privileges on non-…

AnyDesk 0Day ZDI-26-401: No Patch After 15 Months, DoS Remains Active
Trend Micro's Zero Day Initiative disclosed ZDI-26-401, a zero-day vulnerability in AnyDesk enabling local denial-of-service via NTFS…

ZDI Publishes 0-Day in Glary Utilities: LPE via Junction, No Patch
Trend Micro's Zero Day Initiative has disclosed ZDI-26-402, a local privilege escalation vulnerability in Glarysoft Glary Utilities. T…

BeyondTrust Patches Four Critical Flaws: The AI That Finds Bugs Risks Becoming the Weapon That Exploits Them
BeyondTrust released patches on July 7, 2026 for four vulnerabilities in Remote Support and Privileged Remote Access. Two carry CVSS 9…

Metasploit Arms FlowiseAI and macOS: Two Exploits Land in the Framework
Metasploit has merged exploit modules for CVE-2026-41264, an unauthenticated RCE in FlowiseAI's CSV Agent, and CVE-2024-27822, a local…

Adobe ColdFusion: 10 Critical CVEs With In-the-Wild RCE, Forced Update
Adobe patched 10 ColdFusion vulnerabilities, including CVE-2026-48282 with a CVSS 10.0 score and confirmed exploitation. The legacy RD…

The Gentlemen Climbs RaaS Rankings: 90% Payout and 580 Victims in One Year
The Gentlemen, tracked as Storm-2697, has become the second most active RaaS operation of 2026 with over 6x growth and a 90% affiliate…

GodDamn Ransomware Uses Microsoft-Signed Driver to Disable EDR
The GodDamn ransomware, a rebrand of the Hyadina family, leverages the PoisonX driver — signed with a valid Microsoft Windows Hardware…

Friendly Fire: Defensive AI Agents Turn into RCE Attack Vectors
The AI Now Institute's Friendly Fire report, published July 8, 2026, demonstrates that Anthropic's Claude Code and OpenAI's Codex — to…

Security AI Agents Turned Into Attack Vectors: The Report That Stops You Cold
The Friendly Fire report published by the AI Now Institute on July 8, 2026 proves that Anthropic's Claude Code and OpenAI's Codex CLI…

Zimbra Patches Critical Stored XSS in Classic Web Client, Reported by Google TAG
Zimbra released ZCS 10.1.19 on July 7, 2026 to fix a stored cross-site scripting vulnerability in the Classic Web Client reported by G…

Ill Bloom: 431 Wallets Drained for $3.1M via Insecure PRNG
The Ill Bloom vulnerability exposed 2,114 crypto addresses due to weak pseudorandom number generators. No patch exists: the only defen…

Chinese-Linked Cluster Exploits Roundcube to Spy on Strategic Research in North America
Proofpoint has identified UNK_MassTraction, a suspected Chinese cluster, exploiting two Roundcube N-day vulnerabilities to compromise…

Operation Muck and Load: 222 GitHub Repositories Weaponized to Distribute Windows Malware
A threat actor built a network of 222 GitHub repositories across 190 accounts to distribute Windows malware via malicious Go modules.…

Microsoft: AI Will Make Patch Tuesday Permanently More Demanding
Microsoft EVP Pavan Davuluri confirmed on July 9, 2026 that AI will permanently increase the volume of security updates in each Patch…

Ex-DigitalMint Negotiator Gets 70 Months for Feeding Clients to BlackCat
Angelo Martino was sentenced to 70 months in prison for acting as an insider for the BlackCat/ALPHV ransomware gang against five U.S.…

GigaWiper: The Post-Compromise Malware Masking Three Destructive Intents
GigaWiper is a modular Go backdoor that unifies wiper, fake ransomware, and spyware capabilities. Linked to BLUERABBIT, the platform c…

LVM: Weeks of Blackout After Ransomware Hits System Unpatched for Two Years
Latvia's state-owned forestry company Latvijas valsts meži (LVM) remains paralyzed weeks after a June 22 ransomware attack. Roughly tw…

AI-Generated Malware Maps Active Directory: How It Was Caught
On June 3, 2026, Huntress detected an attack using an AI-generated PowerShell script created via vibe coding. Behavioral detection suc…

Microsoft Patches RoguePlanet: When the Antivirus Becomes the Attack Surface
CVE-2026-50656 enables privilege escalation to SYSTEM via the Microsoft Defender engine. The fix arrives through an automatic engine u…