// 2 CVE · 1 EXPLOIT IN THE LAST 24H
news

Gitea Under Attack: The Docker Template That Opens the Door to Anyone

It took just 13 days from the advisory's publication for the first in-the-wild exploitation attempts against CVE-2026-20896, a critica…

Jul 06, 2026views - 1.4k

CYBERSEC

Armored Likho Targets Governments and Power Operators with BusySnake Stealer

The Armored Likho APT group, uncovered by Kaspersky, is conducting cyber-espionage and financially motivated attacks against governmen…

Jul 06, 2026views - 1.3k

news

QuimaRAT: A Modular Java RAT Challenges Defensive Segmentation on Windows

LevelBlue has identified QuimaRAT, a remote access trojan written in Java and sold as malware-as-a-service starting at $150 per month.…

Jul 06, 2026views - 1.3k

CYBERSECEXPLOIT

Adobe ColdFusion: July 1 Patch, Active Exploit Within Hours

Adobe released security updates for ColdFusion on July 1, 2026, fixing 11 vulnerabilities, six rated CVSS 10.0. Within hours, the Cana…

Jul 06, 2026views - 1.3k

news

Zscaler: 4 of 26 LLMs Tricked Into Making Crypto Payments via Prompt Injection

Zscaler ThreatLabz demonstrated that four out of 26 tested large language models can be induced to execute cryptocurrency transactions…

Jul 06, 2026views - 1.3k

ai

SkillCloak: 90% of AI Agent Skill Scanners Fail Against Obfuscated Skills

HKUST researchers demonstrate that static scanners on AI skill marketplaces systematically fail against active evasion techniques. The…

Jul 06, 2026views - 1.4k

CYBERSEC

Kaseya: 69% of SaaS Accounts in Small Businesses Are Guest Access, MFA Disabled for 56%

Kaseya's 2026 SaaS Security Report reveals that guest accounts make up 69% of monitored SaaS identities across 50,000+ SMBs, while MFA…

Jul 06, 2026views - 1.5k

CYBERSEC

Cisco Talos Releases ClamAV 1.5.3 and 1.4.5: Seven Legacy Vulnerabilities Patched

ClamAV 1.5.3 and 1.4.5 address vulnerabilities in PE file, archive, and disk image parsers. Two bugs survived roughly 20 years in crit…

Jul 05, 2026views - 1.4k

ransomware

The Gentlemen: Go Backdoor and BYOVD in New RaaS That Spies on EDR

Kaspersky analyzes The Gentlemen, a ransomware-as-a-service group active since early 2026. Custom Go backdoor with persistent C2, five…

Jul 05, 2026views - 1.6k

CYBERSECCVE

CVE-2026-9787: RCE in Quest NetVault Backup with SYSTEM Execution

A vulnerability in the NVBULogDaemon component of Quest NetVault Backup enables remote code execution with authentication bypass. The…

Jul 05, 2026views - 1.4k

CYBERSEC

FortiBleed Fuels INC and Lynx: One Operator Serving Two Ransomware Clients

SOCRadar has documented the link between FortiBleed and the INC and Lynx ransomware groups. A single operator accessed the negotiation…

Jul 05, 2026views - 1.4k

newsCRITICAL

FlowiseAI: RCE in CSV Agent, Authentication Bypassable

The ZDI-26-365 vulnerability in FlowiseAI's CSV Agent component allows remote execution of arbitrary Python code. The patch introduces…

Jul 04, 2026views - 1.5k

news

JadePuffer: The First Agentic Ransomware — AI Automates the Entire Kill Chain

Sysdig Threat Research Team documented the first end-to-end ransomware attack conducted by an AI agent on July 1, 2026. Dubbed JadePuf…

Jul 04, 2026views - 1.4k

ransomware

A U.S. Local Government Paid $1 Million for an Illusion of Control

A U.S. government entity paid roughly $1 million in bitcoin to the Kairos ransomware group on June 13, 2025, to prevent the release of…

Jul 04, 2026views - 1.6k

CYBERSEC

Researcher Documents Real-Time Shared Access Between FortiBleed Operator and INC Ransom, Lynx Panels for First Time

SOCRadar documented that an operator with access to the FortiBleed infrastructure was simultaneously logged into the negotiation panel…

Jul 04, 2026views - 1.4k

apple

Apple Compresses Patch Cycle After AI Uncovers Four WebKit Flaws

On June 29, 2026, Apple released iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, and Safari 26.5.2, addressing over 30 vulnerabilities.…

Jul 04, 2026views - 1.5k

CYBERSECZERO-DAY

Bad Epoll: Linux Kernel Bug Roots Android, Escapes Chrome Sandbox

CVE-2026-46242 is a race condition in the Linux kernel's epoll subsystem that allows an unprivileged user to gain root privileges. The…

Jul 03, 2026views - 1.4k

malware

Avalon: The Malware Framework Merging AI and Multi-Evasion to Strike

The Avalon framework combines credential harvesting, multi-EDR evasion, and the CrownX ransomware into a single attack chain. Blackpoi…

Jul 03, 2026views - 1.6k

malware

BusySnake Stealer: The APT That Generates Malware With AI

Armored Likho uses LLMs to write first-stage payloads and PyArmor Pro to obfuscate them. Kaspersky's report reveals an infostealer tar…

Jul 03, 2026views - 1.6k

ransomware

Interpol Ransomware: Small Businesses Targeted via Social Engineering

Threat actors are impersonating Interpol in a ransomware campaign hitting small businesses across pharmaceutical, food, agriculture, t…

Jul 02, 2026views - 1.4k

news

Apple Shifts Patching Model: First Step Toward Faster Security Updates

Apple has decoupled security updates from major OS release cycles, citing the acceleration of AI-driven attacks as the catalyst. The f…

Jul 02, 2026views - 1.6k

CYBERSEC

Medtronic Begins Breach Notifications: 369,200+ Confirmed Victims vs. 9 Million Claimed by ShinyHunters

Medtronic has started notifying individuals affected by an April 2026 corporate IT breach. State regulator filings confirm over 369,20…

Jul 02, 2026views - 1.6k

malware

ToddyCat's Umbrij Malware Steals Gmail OAuth Tokens by Abusing Enterprise Browsers

The Umbrij malware automates OAuth 2.0 token theft via the Chrome DevTools Protocol, bypassing passwords and MFA on corporate Gmail ac…

Jul 02, 2026views - 1.3k

CYBERSECEXPLOIT

Cisco Confirms: Unified CM SSRF Exploited, 48-Hour Window from PoC to Attacks

Cisco confirmed on July 1, 2026, that CVE-2026-20230, an SSRF vulnerability in Unified Communications Manager, is under active in-the-…

Jul 02, 2026views - 1.4k