Archive
All articles, newest first. Page 12.

Chrome 152 Patches 327 Vulnerabilities, Including Sandbox-Escape RCE
Google released Chrome 152.0.7977.64/.65 on August 26, 2026, with a record 327 security fixes — 10 rated critical. CVE-2026-79282, a u…

Hugging Face Kubernetes AI Agent Intrusion
Qualys mapped the stages of an autonomous AI agent's multi-day intrusion against Hugging Face's Kubernetes environment on July 9, 2026…

CareCloud Breach Balloons to 3.7 Million Victims: A Lesson in Regulatory Reporting Gaps
The CareCloud breach has surged from 350,000 to 3.75 million victims in five months, exposing how healthcare regulatory reporting can…

Kaltura Unpatched: RCE and File Read in mwEmbed, No Fix for Five Months
CERT/CC disclosed two critical unpatched vulnerabilities in Kaltura's mwEmbed library enabling remote code execution and arbitrary fil…

Satanic Exposes 1,033 Stripe API Keys: The Vector Isn't an Infostealer
Threat actor Satanic released data from 669 Stripe vendors with live API keys. Analysis rules out infostealer infections and points to…

Mirage2FA: AiTM Phishing Kit Hits 3,500 Organizations, Bypasses MFA on Microsoft 365
The Mirage2FA phishing-as-a-service kit, operated by LinX Coders, has targeted over 3,500 organizations using Adversary-in-the-Middle…

Active Attacks on miniOrange: When Vendor Silence Becomes a Weapon
Threat actors are actively exploiting two vulnerabilities in the miniOrange SAML 2.0 SSO plugin for WordPress to bypass authentication…

Gitea CVE-2026-60004: Real-World Victim Reports CPU Spike and Dropper
A Russian sysadmin documented an attack on their self-hosted Gitea instance via CVE-2026-60004. Hosting provider HOSTKEY flagged susta…

First Car Head Unit Malware Discovered: Vehicles Recruited into Proxy Botnet
Kaspersky has identified the first malware with a dedicated infection chain for Android automotive head units. It exploits the privile…

LiteSpeed cPanel Plugin: CVSS 10.0 Flaw Patched in Three Rounds
CISA added CVE-2026-48172 to its Known Exploited Vulnerabilities catalog on May 26, 2026, giving federal agencies a three-day remediat…

Citrix NetScaler: CVE-2026-19490, Critical Authentication Bypass with CVSS 9.3
Citrix has released patches for CVE-2026-19490, a critical authentication bypass in NetScaler ADC/Gateway carrying a CVSS 9.3 score. T…

NSA and CISA Issue First Alert on AI-Driven Attacks Against Critical Siemens PLCs
Five U.S. federal agencies have released joint advisory AA26-231A confirming threat actors are using AI-generated scripts to target in…

Unisoc VoLTE Exploit Chain Opens Android Kernel via Modem — No Patch, No CVE
A two-stage exploit chain in Unisoc VoLTE modems lets an attacker with a rogue 4G network achieve full Android kernel access when the…

Lazarus Exploits Windows AFD.sys Zero-Day for SYSTEM: Third Time in Two Years
The North Korean group used CVE-2026-68820 for local privilege escalation to SYSTEM, deploying the FudModule 3.1 rootkit and Troy back…

French Cyber-Spies Used GitHub Code to Hack EncroChat
A reverse-engineering report reveals French malware targeting EncroChat was copied from GitHub. Thousands of convictions across Europe…

iOS: Coruna and DarkSword Proliferation Exposes 17,000 Domains to Risk
iVerify VP of Research Matthias Frielingsdorf revealed at Black Hat USA 2026 the unprecedented scale of a proliferation: roughly 17,00…

Shell in Cl0p's Crosshairs: Investigation Into Alleged 89GB Theft From PTC Systems
Shell confirms an investigation after the Cl0p ransomware group claimed theft of 89GB of technical data. The campaign targeting PTC Wi…

CVE-2026-55040: Active SharePoint Exploitation Within 48 Hours of PoC Release
Attackers are already exploiting CVE-2026-55040, a critical JWT authentication bypass in Microsoft SharePoint Server. The window betwe…

CVE-2026-32475: Elementor Pro ≤4.2.1 Exposed to Unauthenticated RCE
A critical CVSS 9.0 vulnerability in Elementor Pro allows unauthenticated PHP file upload. The fix sat ready for 34 days before releas…

DOUBLECUP: The Fake Steganography That Exposes Criminal Payloads to a Simple grep
The DOUBLECUP loader promises advanced steganography but hides PowerShell code in plaintext after the PNG file. Extractable with FINDS…

Windows: Localized Filename Bug Steals NTLM Credentials with a Single Click
CVE-2026-50508: A flaw in Windows localized filenames enables NTLM hash theft simply by opening a file or visiting a web page. Microso…

Fabric.js JSON Parsing Turns Attack Vector: SSRF Bug Discovered
CVE-2026-19504 in Fabric.js' loadFromJSON method enables SSRF attacks for sensitive data disclosure. The fix requires implementing a U…

Foxit PDF Reader: UAF Bug in Annotation Parser Enables Remote Code Execution
ZDI-26-604 (CVE-2026-13126) is a Use-After-Free in Foxit PDF Reader's Annotation object parsing. Opening a malicious PDF allows arbitr…

Safari UAF in JavaScriptCore: Apple Patches Already Available
CVE-2026-64715 in Safari's JavaScript engine enables remote code execution simply by visiting a malicious page. Patches were released…