Archive
All articles, newest first. Page 12.

Accenture Confirms Data Breach: 35 GB of Data Up for Sale by Threat Actor '888'
Accenture has confirmed a security breach after threat actor '888' listed 35 GB of allegedly stolen data for sale on a cybercrime foru…

CAI Worm Kills Rival Cloud Malware, Steals Credentials
The CAI cloud-native worm eliminates TeamPCP and PCPJack processes to monopolize compromised hosts, marking an escalation in criminal…

ATEN Unizon Exposes System Files Without Authentication: Directory Traversal
The ZDI-26-380 vulnerability in ATEN Unizon allows a remote attacker to read arbitrary files in the SYSTEM context. A patch is availab…

X.Org Server: A Forgotten Bug Returns as Privilege Escalation — The ZDI-26-395 Case
A use-after-free flaw in SyncChangeCounter enables local privilege escalation to root on X.Org Server. The bug mirrors a pattern alrea…

UAT-7810 Expands ORB Network: New LONGLEASH, DOGLEASH, and JARLEASH Backdoors
Cisco Talos reveals the China-nexus APT UAT-7810 is actively expanding its LapDogs Operational Relay Box (ORB) network with new malwar…

China-Linked Exploit Chain Targets US and Canadian Universities via Roundcube
A suspected Chinese espionage cluster has compromised fewer than ten US and Canadian universities using a two-vulnerability chain in R…

BeyondTrust Patches Four Critical Remote Support Flaws — Self-Hosted Servers Left Exposed for Months
July 7, 2026. BeyondTrust released fixes for four vulnerabilities in Remote Support and Privileged Remote Access, two rated CVSS 9.2.…

Nissan Employees in Four Countries Exposed by Oracle PeopleSoft Zero-Day
Nissan Americas confirmed that attackers exploited CVE-2026-35273, a zero-day vulnerability in Oracle PeopleSoft PeopleTools, to steal…

Exploitarium: The Speed Paradox — Public Exploits for Already-Patched Flaws
Pseudonymous researcher 'bikini' dumped 30+ zero-day PoCs on GitHub without coordinated disclosure. CVE-2026-55200 in libssh2 had a fi…

DeepSeek Generates Browser-Only Ransomware From a Prompt: Proof-of-Concept
Check Point Research analyzed a ransomware sample generated by DeepSeek that encrypts local files via the browser on Android, requirin…

CSE Discloses Three Offensive Cyber Operations in Rare 2025 Report
Canada's Communications Security Establishment (CSE) revealed in its 2025 annual report that it conducted three authorized offensive c…

Vishing 2.0 Hits Teams: Fake IT Support Calls Deploy EtherRAT
Palo Alto Networks Unit 42 uncovered a campaign that abuses Microsoft Teams voice calls to impersonate corporate IT support and trick…

Cavern: The .NET Framework That Challenges Analysts With Three Distinct Compilation Formats
Check Point Research has unveiled Cavern, a modular .NET C2 framework used by the Iranian threat actor Cavern Manticore. The framework…

Januscape: 16-Year-Old KVM Bug Enables Guest-to-Host Escape on Intel and AMD
CVE-2026-53359 strikes the shared shadow MMU code in Linux KVM used by both Intel and AMD. The flaw has existed since 2010 and require…

Elastic Automates CVE Advisory Writing with RAG on MITRE Data
Elastic Security Labs has put into production an AI pipeline that generates complete CVE advisory drafts with CWE, CAPEC, and CVSS, gr…

Gitea Under Attack: The Docker Template That Opens the Door to Anyone
It took just 13 days from the advisory's publication for the first in-the-wild exploitation attempts against CVE-2026-20896, a critica…

Armored Likho Targets Governments and Power Operators with BusySnake Stealer
The Armored Likho APT group, uncovered by Kaspersky, is conducting cyber-espionage and financially motivated attacks against governmen…

QuimaRAT: A Modular Java RAT Challenges Defensive Segmentation on Windows
LevelBlue has identified QuimaRAT, a remote access trojan written in Java and sold as malware-as-a-service starting at $150 per month.…

Adobe ColdFusion: July 1 Patch, Active Exploit Within Hours
Adobe released security updates for ColdFusion on July 1, 2026, fixing 11 vulnerabilities, six rated CVSS 10.0. Within hours, the Cana…

Zscaler: 4 of 26 LLMs Tricked Into Making Crypto Payments via Prompt Injection
Zscaler ThreatLabz demonstrated that four out of 26 tested large language models can be induced to execute cryptocurrency transactions…

SkillCloak: 90% of AI Agent Skill Scanners Fail Against Obfuscated Skills
HKUST researchers demonstrate that static scanners on AI skill marketplaces systematically fail against active evasion techniques. The…

Kaseya: 69% of SaaS Accounts in Small Businesses Are Guest Access, MFA Disabled for 56%
Kaseya's 2026 SaaS Security Report reveals that guest accounts make up 69% of monitored SaaS identities across 50,000+ SMBs, while MFA…

Cisco Talos Releases ClamAV 1.5.3 and 1.4.5: Seven Legacy Vulnerabilities Patched
ClamAV 1.5.3 and 1.4.5 address vulnerabilities in PE file, archive, and disk image parsers. Two bugs survived roughly 20 years in crit…

The Gentlemen: Go Backdoor and BYOVD in New RaaS That Spies on EDR
Kaspersky analyzes The Gentlemen, a ransomware-as-a-service group active since early 2026. Custom Go backdoor with persistent C2, five…