Archive
All articles, newest first. Page 5.

Delta Electronics DTM Soft Exposed to User-Interaction RCE via Project Files
The industrial configuration software DTM Soft contains a deserialization flaw in project files that enables remote code execution wit…

SCADA DAQFactory: RCE via Engineered .ctl File, Patch Available
ZDI-26-450 (CVE-2026-12921) exposes AzeoTech DAQFactory 21.1 and earlier to remote code execution through a use-after-free in the .ctl…

Docker Desktop macOS: Sandbox Escape in Inference Server, Patch Available
A vulnerability in the sandbox profile of Docker Desktop for macOS's inference server allows local sandbox escape and privilege escala…

X.Org Server: Critical Glamor Font Bug Allows Root Privilege Escalation
CVE-2026-55999 in the Glamor Font component of X.Org Server and Xwayland lets any local user with an X connection escalate to root. Pa…

LiteLLM Open-Source LLM Gateway Distributes Credential-Stealing Malware
Two PyPI versions of the litellm package were compromised by malware that abuses Python .pth files to exfiltrate credentials to an att…

GitHub Actions Unwittingly Became an ISP for Criminals
Threat actors turned GitHub Actions runners into botnet nodes for large-scale cPanel/WHM scanning and exploitation. The campaign gener…

Stadler Rejects $12.3M Ransom: Everest Fails to Leak Data
Swiss rail manufacturer Stadler Rail publicly refused a 10 million Swiss franc ($12.3 million) ransom demand from the Everest ransomwa…

LegacyHive: Zero-Day Windows Flaw Patched by 0Patch Before Microsoft
The LegacyHive vulnerability in the Windows User Profile Service enables local privilege escalation. ACROS Security has released free…

Autonomous AI vs. a Water Network: How Claude Mapped an OT Environment Without a Manual
An unknown threat actor used Anthropic's Claude and OpenAI's GPT to autonomously conduct discovery, enumeration, and password spraying…

SleeperGem: The Day RubyGems Became an npm-Style Target
Three malicious RubyGems packages compromised developer workstations through require-time execution and CI evasion. The campaign marks…

dYdX Hit by Third Supply-Chain Attack: Compromised npm and PyPI Packages Deliver Wallet Stealer and RAT
DeFi protocol with $1.5T cumulative volume compromised on npm and PyPI. Wallet stealer and remote access trojan distributed via mainta…

CVE-2026-3888: LPE to Root in snapd Hits Ubuntu LTS Since 2016
Qualys discovered a local privilege escalation vulnerability in snapd that lets a local attacker gain root on Ubuntu 16.04 through 24.…

NVIDIA NVTabular: RCE via Pickle, CVE-2026-24237 Rated CVSS 7.8
A deserialization flaw in NVIDIA NVTabular enables remote code execution through malicious pickle files. User interaction is required;…

ZDI-26-419: AdobeUpdateService Bug Allows Local Privilege Escalation to SYSTEM
The ZDI-26-419 vulnerability (CVE-2026-48272) in Adobe Creative Cloud Desktop enables local privilege escalation to SYSTEM via CWE-427…

MSI Center's Ghost Driver: Local Escalation to SYSTEM in One Command
ZDI-26-430 discloses an origin validation flaw in the MSI Center kernel driver NTIOLib_X64.sys, tracked as CVE-2026-6102 (CVSS 7.8). A…

ZDI-26-443: Linux Kernel vmwgfx Integer Overflow Enables Local Privilege Escalation at CVSS 8.8
An integer overflow in the Linux kernel's vmwgfx graphics driver allows local privilege escalation to kernel context. Published July 1…

Public Scanner Released for NGINX Map Regex Flaw; Full RCE Exploit Expected Around August 5
Researcher Stan Shaw (cyberstan) has published an open-source static scanner for CVE-2026-42533, a heap buffer overflow in the NGINX s…

Russia Exploits Zimbra Zero-Day: Patching Alone Won't Evict the Spies
A zero-click XSS flaw in Zimbra Collaboration Suite let a Russian espionage group harvest emails, 2FA codes, and persistent app passwo…

Fastjson 1.x Has No Exit: When Standard Mitigations Aren't Enough
CVE-2026-16723 hits Fastjson 1.2.68–1.2.83 with a CVSS 9.0. The exploit works with default settings, requires no AutoType or gadgets,…

Autel Wallbox Exposed to Pre-Auth RCE: The Pwn2Own Bug Hitting Home EV Chargers
Trend Micro's Zero Day Initiative published advisory ZDI-26-437 on July 15, 2026, detailing a pre-authentication remote code execution…

Misconfigured Server Exposes Three Evilginx Operations Targeting Microsoft 365
A phishing server with directory listing enabled exposed complete M365 phishing toolkits, two distinct MFA bypass techniques, and evid…

Oracle Simphony: Four Critical CVEs Expose Hospitality POS to RCE
Four vulnerabilities in Oracle Hospitality Simphony enable unauthenticated remote code execution and NTLM hash theft. Patches released…

Joint Operation Dismantles Kratos: The AiTM Phishing Kit That Bypasses MFA
German, U.S., and Indonesian authorities have taken down over 200 servers powering the Kratos phishing kit. The code survives among ro…

Iran Weaponizes Its Asymmetric Playbook With Commercial AI
Recorded Future documents how generative AI has become a force multiplier across Iranian cyber and influence operations — compressing…