Archive
All articles, newest first. Page 37.

Malicious AI Skills: 3,000 Evade Scanning, Enterprises Exposed
ESET detected over 3,000 malicious skills among nearly 900,000 analyzed. The SkillCloak technique bypasses static scanners in more tha…

IRIS C2: Convicted Fraudsters Run Zero-Day Exploit Startup
IRIS C2, a McLean, Virginia startup offering up to $7 million for zero-day vulnerabilities, is operated by Jacob Wohl and Jack Burkman…

KDDI: Zero-Day in Third-Party Software Exposes 12,233,087 Email Addresses
KDDI confirmed a zero-day attack in third-party software compromised the shared email platform of five Japanese ISPs, exposing over 12…

Ubiquiti Patches CVE-2026-50746, Maximum-Severity Flaw in UniFi OS
Ubiquiti released security updates on July 8, 2026 for seven critical vulnerabilities in UniFi OS. The most severe, CVE-2026-50746, ca…

GhostLock: 15-Year Linux Kernel Bug Now Publicly Exploitable, Guarantees Root
CVE-2026-43499 enables root escalation and container escape on nearly every Linux distribution since 2011. Nebula Security published t…

Gartner: By 2028, 60% of Enterprises Will Drop Annual Pentesting for Continuous Validation
Gartner formalizes the COST framework for continuous vulnerability validation. Exploit time has compressed to under 10 hours, and 53%…

RedWing: Android Banking Malware Turns into a Telegram Rental Service
Zimperium zLabs uncovered RedWing, a Malware-as-a-Service platform that commercializes Android banking fraud with Telegram bots and su…

Accenture Confirms Data Breach: 35 GB of Data Up for Sale by Threat Actor '888'
Accenture has confirmed a security breach after threat actor '888' listed 35 GB of allegedly stolen data for sale on a cybercrime foru…

CAI Worm Kills Rival Cloud Malware, Steals Credentials
The CAI cloud-native worm eliminates TeamPCP and PCPJack processes to monopolize compromised hosts, marking an escalation in criminal…

ATEN Unizon Exposes System Files Without Authentication: Directory Traversal
The ZDI-26-380 vulnerability in ATEN Unizon allows a remote attacker to read arbitrary files in the SYSTEM context. A patch is availab…

X.Org Server: A Forgotten Bug Returns as Privilege Escalation — The ZDI-26-395 Case
A use-after-free flaw in SyncChangeCounter enables local privilege escalation to root on X.Org Server. The bug mirrors a pattern alrea…

UAT-7810 Expands ORB Network: New LONGLEASH, DOGLEASH, and JARLEASH Backdoors
Cisco Talos reveals the China-nexus APT UAT-7810 is actively expanding its LapDogs Operational Relay Box (ORB) network with new malwar…

China-Linked Exploit Chain Targets US and Canadian Universities via Roundcube
A suspected Chinese espionage cluster has compromised fewer than ten US and Canadian universities using a two-vulnerability chain in R…

BeyondTrust Patches Four Critical Remote Support Flaws — Self-Hosted Servers Left Exposed for Months
July 7, 2026. BeyondTrust released fixes for four vulnerabilities in Remote Support and Privileged Remote Access, two rated CVSS 9.2.…

Nissan Employees in Four Countries Exposed by Oracle PeopleSoft Zero-Day
Nissan Americas confirmed that attackers exploited CVE-2026-35273, a zero-day vulnerability in Oracle PeopleSoft PeopleTools, to steal…

Exploitarium: The Speed Paradox — Public Exploits for Already-Patched Flaws
Pseudonymous researcher 'bikini' dumped 30+ zero-day PoCs on GitHub without coordinated disclosure. CVE-2026-55200 in libssh2 had a fi…

DeepSeek Generates Browser-Only Ransomware From a Prompt: Proof-of-Concept
Check Point Research analyzed a ransomware sample generated by DeepSeek that encrypts local files via the browser on Android, requirin…

CSE Discloses Three Offensive Cyber Operations in Rare 2025 Report
Canada's Communications Security Establishment (CSE) revealed in its 2025 annual report that it conducted three authorized offensive c…

Vishing 2.0 Hits Teams: Fake IT Support Calls Deploy EtherRAT
Palo Alto Networks Unit 42 uncovered a campaign that abuses Microsoft Teams voice calls to impersonate corporate IT support and trick…

Cavern: The .NET Framework That Challenges Analysts With Three Distinct Compilation Formats
Check Point Research has unveiled Cavern, a modular .NET C2 framework used by the Iranian threat actor Cavern Manticore. The framework…

Januscape: 16-Year-Old KVM Bug Enables Guest-to-Host Escape on Intel and AMD
CVE-2026-53359 strikes the shared shadow MMU code in Linux KVM used by both Intel and AMD. The flaw has existed since 2010 and require…

Elastic Automates CVE Advisory Writing with RAG on MITRE Data
Elastic Security Labs has put into production an AI pipeline that generates complete CVE advisory drafts with CWE, CAPEC, and CVSS, gr…

Gitea Under Attack: The Docker Template That Opens the Door to Anyone
It took just 13 days from the advisory's publication for the first in-the-wild exploitation attempts against CVE-2026-20896, a critica…

Armored Likho Targets Governments and Power Operators with BusySnake Stealer
The Armored Likho APT group, uncovered by Kaspersky, is conducting cyber-espionage and financially motivated attacks against governmen…