Archive
All articles, newest first. Page 4.

Samsung rlottie: RCE Bug in Lottie Animations, Patch Available Since July 3
The open-source Samsung rlottie library contains a numeric truncation vulnerability (CVE-2026-15551, CVSS 5.5) enabling remote code ex…

Dirty Frag: Post-Compromise LPE With Confirmed Active Attacks on Linux
Microsoft has detected active attacks exploiting Dirty Frag, a deterministic local privilege escalation vulnerability in the Linux ker…

WhatsApp's CVSS 5.4 Falls Short: Zero-Click Surveillance Lurks Behind the Score
WhatsApp released an emergency update on July 28, 2025, patching CVE-2025-55177, an insufficient authorization flaw in Linked Devices…

Operation STANDOFF: 44 C2 Servers Mask Traffic With GitHub Redirects
VMRay Labs has mapped a Russian-speaking criminal campaign operating at least 44 command-and-control servers hosted on TimeWeb Ltd. (A…

CVE-2026-56163: Microsoft Mitigates Critical AKS Flaw Without Customer Action
Microsoft assigned CVE-2026-56163 a maximum CVSS 10.0 score for a critical elevation-of-privilege vulnerability in Azure Kubernetes Se…

Kratos Phishing Kit Dismantled: 200 Servers Seized, but AiTM Code Remains in Circulation
German, U.S., and Indonesian authorities took down the Kratos phishing kit, seizing over 200 servers and arresting the alleged develop…

BRICKSTORM: Chinese Backdoor Targets US and Canadian Critical Infrastructure
CISA, NSA, and the Canadian Centre for Cyber Security disclosed BRICKSTORM, Chinese state-sponsored malware with 17-month persistence…

Arista VeloCloud Zero-Day: The SD-WAN Controller That Cannot Hide
CVE-2026-16812 hits on-prem Arista VeloCloud Orchestrator with a CVSS 10.0. Active exploitation requires no credentials, and no config…

The Enterprise SOC Broke on February 11: Seven Days of Zero-Day Overload
Between February 11 and 17, 2026, a relentless cluster of critical zero-day vulnerabilities hit Ivanti, BeyondTrust, Microsoft, Apple,…

Hotel Wi-Fi DNS Attacks Steal Microsoft 365 Accounts, Bypass MFA
Threat actors compromise hotel and conference center Wi-Fi captive portals to manipulate DNS and steal Microsoft 365 credentials, sess…

Spirals: New Rust Ransomware Deployed Across Enterprise Network in Under 24 Hours
The Symantec Threat Hunter Team has documented Spirals, a Rust-based ransomware using ECDH+AES hybrid encryption. An attack in South A…

Oracle Smashes the Thousand-Patch Ceiling: Enterprise Vulnerability Management Under Strain
Oracle released a record 1,449 security patches in July 2026, nearly tripling the previous high. The volume exposes the unsustainabili…

Anubis Hits Fairlife-Coca-Cola: Production Halted, 1 TB of Data Threatened
The Anubis ransomware group claims responsibility for an attack on Fairlife, a Coca-Cola subsidiary specializing in premium dairy prod…

Infostealers Overtake Phishing and Exploits as Top Enterprise Cloud Access Vector
Infostealer malware logs have surpassed phishing and vulnerability exploits as the primary initial access vector for enterprise cloud…

Commercial Spyware and Zero-Days: Smartphone Exploit Chains Are Now a Product
Zero-click exploit chains for iOS and Android have become commercial products. Bitdefender's dossier compiles confirmed cases and docu…

Certighost: Ten Days After the Patch, the Exploit Is Public and the Domain Falls
The Certighost proof-of-concept for CVE-2026-54121 lets a standard domain user impersonate a Domain Controller via AD CS. Released exa…

Heimdall Data Database Proxy: RCE Vulnerability with Root Privileges Discovered
Trend Micro's Zero Day Initiative published advisory ZDI-26-447 covering CVE-2026-12357 (CVSS 7.2). The flaw in Heimdall Data Database…

OctagonPanel Spyware Hides Behind Fake Bahrain Civil Defense Alert App
A counterfeit "BH Alert" app impersonating Bahrain's civil defense system delivers the OctagonPanel surveillance malware via a four-st…

Record Patch Tuesday: Microsoft Fixes 570 CVEs and Two Actively Exploited Zero-Days in AD FS and SharePoint
The July 14, 2026 Patch Tuesday sets a record with 570 CVEs patched, two actively exploited zero-days, and a third publicly disclosed.…

Iran APT Sabotages US PLCs: CISA Warns of Physical Risk
The US government discloses an Iranian APT compromising internet-exposed PLCs in water and energy facilities, disabling safety logic t…

CISA Mandates Three-Day Patch for Splunk Zero-Day: New BOD 26-04 Ups the Ante
CVE-2026-20253 in Splunk Enterprise carries a CVSS 9.8 and pre-authentication RCE. CISA set a three-day deadline via the new Binding O…

Apple Patches iOS 26 dyld Zero-Day: Targeted Attacks Already Underway
Apple has released iOS 26.3 to address CVE-2026-20700, a zero-day vulnerability in the dyld component exploited in sophisticated attac…

Qilin Exploits CVE-2026-0257: From VPN Bypass to Ransomware in 4 Days
Arctic Wolf confirms Qilin ransomware is exploiting CVE-2026-0257 in Palo Alto GlobalProtect. The window between patch availability an…

From Zero to Shell: The wp2shell Chain Strikes WordPress Core in Seconds
The HackerHood group has reproduced the wp2shell exploit chain against WordPress 6.9.1 in a lab setting, achieving pre-authentication…