Archive
All articles, newest first. Page 3.

Heimdall Data: Root RCE in Database Proxy Poses Infrastructure-Wide Risk
ZDI-26-479 reveals a directory traversal flaw in the uploadJar method of Heimdall Data Database Proxy. Authentication is required, but…

TrueConf Becomes Strategic Chokepoint: Compromised Servers Infect Clients
At least three distinct attack campaigns — attributed to Ukrainian hacktivists and Chinese threat actors — have compromised on-premise…

7-Zip 26.00: Any .zip File Can Trigger the Most Severe Heap Overflow Yet
CVE-2026-48095 is a heap overflow in 7-Zip's NTFS parser caused by undefined behavior in a 32-bit shift. An apparently harmless archiv…

CISA Adds CVE-2026-8037 to KEV: 792 Exploit Attempts Against LoadMaster
CISA added CVE-2026-8037 to the Known Exploited Vulnerabilities catalog on August 7, 2026, after KEVIntel telemetry recorded 792 explo…

NoMachine: Command Injection in getstat Exposes TCP 4000 Service to RCE
ZDI-26-483 reveals a command injection flaw in the NoMachine web service on port 4000. Authentication is required, but the vendor ship…

VoidLink: The Cloud-Native Malware Turning Linux into an Attack SaaS
Check Point Research discovered VoidLink in December 2025, a cloud-native Linux malware framework written in Zig with 30-plus plugins,…

Guangdong Chanming: The Ghost Vendor Behind PLA Botnets
Chinese firm Guangdong Chanming, which has no website or known commercial clients, sold anonymized relay infrastructure to the PLA and…

Iranian APTs Target U.S. PLCs: Unpatchable CVE-2021-22681 Exploited
Seven U.S. federal agencies confirmed an active Iranian APT campaign against Rockwell, Schneider, and Siemens PLCs. The critical CVE-2…

Dell RecoverPoint Zero-Day Exploited by UNC6201 Since 2024 for Root Access
CVE-2026-22769: Hardcoded credentials in Dell RecoverPoint for Virtual Machines gave UNC6201 root persistence, ghost NICs, and GrimBol…

June 2026 Patch Tuesday: Microsoft's Largest Ever, With Three Publicly Disclosed Zero-Days
Microsoft fixed nearly 200 vulnerabilities in the June 2026 Patch Tuesday, the most voluminous monthly cycle in the company's history.…

Cisco Confirms Active Exploitation of Hard-Coded Credentials in Secure Firewall Management Center
Cisco has confirmed active in-the-wild exploitation of CVE-2026-20316, a static credential vulnerability in Secure Firewall Management…

Chrome's Fifth 2026 Zero-Day: Google Issues Emergency Patch for Actively Exploited V8 Flaw
Google released an emergency update on June 8, 2026, for CVE-2026-11645, an out-of-bounds vulnerability in the V8 JavaScript engine al…

Swiss Federal SharePoint Breach Compromises 200 Accounts
The Federal Office for Information Technology and Telecommunication (BIT/FOITT) confirms exploitation of already-patched SharePoint fl…

Minnesota Cyberattack Hits Over 30 Water Systems; Cellular Modems Exposed PLCs
A coordinated cyberattack struck more than 30 Minnesota municipal water systems on July 26–27, 2026, forcing manual operations and tri…

Copy Fail CVE-2026-31431: Root Escalation in 732 Bytes on Linux
CVE-2026-31431 lets a local user gain root on Linux in seconds with a 732-byte script. CISA confirms active exploitation.

DarkSword Exposes the Hidden iOS Exploit Market: Zero-Days in the Wild
DarkSword exploits six Apple vulnerabilities — three zero-days — to achieve full iPhone takeover. Three threat groups of differing geo…

WordPress: Backdoors in Essential Plugins, Supply Chain Collapses on Flippa
A buyer purchased 31 WordPress plugins on Flippa, injected PHP backdoors, and activated cloaked SEO spam for Googlebot after eight mon…

UAC-0099: The Fake Notepad++ Plugin That Weaponizes a Legitimate Feature
On July 24, 2026, CERT-UA disclosed a campaign by the UAC-0099 threat cluster: a counterfeit Notepad++ plugin serves as an initial-acc…

Zapscape: Hyunwoo Kim's Third KVM Escape Raises Systemic Security Questions
CVE-2026-64561 is a use-after-free in the KVM/x86 shadow MMU discovered by Hyunwoo Kim. It allows a kernel-privileged L1 guest to brea…

Amazon Attributes Four NPM Supply-Chain Attacks to North Korean Hackers
Amazon Threat Intelligence links the compromise of axios, debug, chalk, and typo-crypto to a North Korean group tracked as SAPPHIRE SL…

Lazarus Shares Zero-Day and C2 With Gunra: South Korea Raises Alarm
Four South Korean agencies confirm the Lazarus Group shared tools, infrastructure, and a zero-day vulnerability with the Gunra ransomw…

SharePoint Zero-Day: Patches Aren't Enough — The Real Danger Is the Keys
Attackers are actively exploiting zero-day vulnerabilities in Microsoft SharePoint Server on-premises to gain administrative privilege…

CaptiveCrunch: Midnight Blizzard Turns Hotel Wi-Fi into an APT Delivery Vector
Microsoft Threat Intelligence has exposed CaptiveCrunch, a Storm-2945 campaign that weaponizes hotel captive portals to deliver the Co…

ExfilSquad Exfiltrates Data on 100,000 UK Police Officers: Debut Without Encryption
The emerging ransomware group ExfilSquad has exfiltrated contact data for over 100,000 officers from the UK Police National Legal Data…