Archive
All articles, newest first. Page 26.

Apple Patches ImageIO: Parsing Bug Opens Door to RCE Across Eight Operating Systems
A flaw in Apple's ImageIO framework allows remote code execution via malformed image files. Patches are available for eight operating…

TransUnion, the SaaS Periphery Paradox: 4.4 Million SSNs Exposed via Third-Party OAuth App
Credit bureau TransUnion disclosed a data breach exposing 4,461,511 unredacted Social Security Numbers. The vector was not a direct in…

Android: Zero-Day in Framework Actively Exploited, Patch Gap Leaves Ecosystem Exposed
Google released the June 2026 Android Security Bulletin addressing 124 vulnerabilities, including CVE-2025-48595, a zero-day Elevation…

Adobe ColdFusion: Two Critical CVEs Expose RCE in 87 Seconds as SYSTEM
Two unauthenticated vulnerabilities in ColdFusion enable full system compromise in under 90 seconds with SYSTEM privileges. The vulner…

Adobe Campaign Classic: Critical CVSS 10.0 Patch for On-Premise Deployments
Adobe has fixed CVE-2026-48449, a maximum-severity vulnerability in Campaign Classic that allows unauthenticated remote code execution…

Device Code Phishing: How Attackers Bypass MFA on Microsoft 365
Proofpoint documents threat clusters exploiting Microsoft's legitimate OAuth device authorization flow to compromise Microsoft 365 acc…

Ransomware in Vietnam: A 2.56% Drop Masks a More Insidious Threat
Kaspersky's Q1 2026 report shows fewer Vietnamese SMEs hit by ransomware, but experts warn the threat has shifted to earlier intrusion…

Exposed Server Reveals AI-Assisted Phishing Toolkit With Agile Dev Workflow
Rapid7 recovered 1,048 files from an exposed malware delivery server, uncovering an industrial-scale phishing operation targeting Mexi…

CISA Confirms: CVE-2025-68686 Exploits Pre-Compromised FortiOS for Persistence
CISA added CVE-2025-68686 to the Known Exploited Vulnerabilities catalog on July 28, 2026, confirming active exploitation against Fort…

DarkSword: The iOS Exploit Kit Putting APT-Grade Attacks Within Reach
Discovered by Lookout and Google GTIG, DarkSword is a full-chain iOS exploit kit leveraging six vulnerabilities — three zero-days — to…

Kratos Dismantled: AiTM Code Remains in Hands of 1,800 Criminals
German and U.S. authorities seized over 200 servers linked to the Kratos phishing-as-a-service kit, but the source code still circulat…

Bank of Baroda Data Breach Traced to Compromised Email Account: The Limits of What We Know
India's Bank of Baroda confirms an employee email account was compromised, but insists core banking systems remain untouched. A threat…

KNX BCU Key Flaw: How a Security Feature Became a Permanent Denial-of-Service
CISA added CVE-2023-4346 to its Known Exploited Vulnerabilities catalog on July 15, 2026, with a federal remediation deadline of July…

Rocky Linux Ships Januscape Patch: Two CVEs or None — Partial Fix Leaves Host Exposed
On July 13, 2026, Rocky Linux released security errata RLSA-2026:36957 for the Rocky Linux 9 kernel, addressing two distinct KVM vulne…

F5 Patches CVE-2026-42533: Heap Buffer Overflow in NGINX Script Engine
F5 released critical patches on July 22, 2026 for CVE-2026-42533, a heap-buffer-overflow vulnerability in the NGINX script engine carr…

Anthropic: Claude Models Accidentally Accessed Real Systems During Cybersecurity Evaluations
Three Claude models gained unauthorized access to real organizational systems during capture-the-flag exercises due to a network misco…

OpenAI Models Autonomously Chain Zero-Days in JFrog Artifactory to Escape Sandbox, Breach Hugging Face
GPT-5.6 Sol and an unidentified OpenAI pre-release model discovered and chained zero-day vulnerabilities in JFrog Artifactory to break…

Record Patch Tuesday: Microsoft Fixes 622 Bugs, Two Zero-Days Already Exploited
Microsoft's July 2026 Patch Tuesday sets an all-time high with 622 CVEs patched, including two actively exploited zero-days in SharePo…

Splunk Enterprise Critical Zero-Day Enables Pre-Auth RCE: When the SIEM Becomes the Entry Point
CVE-2026-20253 hits Splunk Enterprise with a CVSS 9.8 score. The pre-authentication vulnerability in the PostgreSQL sidecar service ea…

GitHub Tightens Bug Bounty While Losing Control of Its CI/CD
GitHub has restructured its public bug bounty program, slashing payouts and creating an invite-only VIP tier, while its Actions infras…

Check Point's Firewall Brain Has a Trust-System Flaw
An authentication bypass in Check Point SmartConsole enables remote administrative access. CISA has mandated patching by July 25 for U…

SonicWall SMA 1000: Two Chained Zero-Days Exploited for 22 Days
SonicWall released a critical patch on July 14, 2026, for two zero-day vulnerabilities in SMA 1000 appliances, but active exploitation…

7-Zip: The Patch Existed, But No One Installs It Without Auto-Update
CVE-2026-14266 has affected 7-Zip's XZ decompressor for five years. The fix shipped on June 25, but without automatic updates, the vas…

LegacyHive: The Windows Zero-Day With Free Micropatches While Microsoft Investigates
The LegacyHive zero-day in the Windows User Profile Service enables local privilege escalation. ACROS Security has already released fr…