Archive
All articles, newest first. Page 6.

APT28 FrostArmada: The SOHO Router Is the New Invisible Perimeter of State-Sponsored Espionage
The GRU compromised 18,000 home routers to steal Microsoft 365 credentials without deploying malware. No EDR can detect this attack: t…

Midnight Blizzard Turns Hotel Wi-Fi Into a Trap for Corporate Travelers
Storm-2945, a Midnight Blizzard sub-cluster, compromises captive portal networks worldwide to deliver the CornFlake RAT and steal Micr…

Miasma Hits Red Hat npm: Malware with Valid SLSA Provenance
On June 1, 2026, 32 npm packages in the @redhat-cloud-services namespace were compromised via a Red Hat employee's personal GitHub acc…

Hotel DNS Attacks: Corporate VPNs Aren't Enough to Protect Microsoft 365
ReliaQuest has documented an active campaign since June 2026 that compromises hotel Wi-Fi gateways to redirect Microsoft 365 logins to…

Cisco Confirms FMC Zero-Day: Static Credentials Under Attack, CISA Sets August 1 Deadline
Cisco confirms active exploitation of CVE-2026-20316 in Secure Firewall Management Center. CISA adds the flaw to its KEV catalog, mand…

F5 Races Against Its Own Stolen Code: 45 Vulnerabilities Disclosed in a Single Quarter
Nation-state actors compromised F5's internal systems, exfiltrating portions of BIG-IP proprietary source code and details on undisclo…

Phishing Tops 50% of IR Cases: Cisco Talos Flags Perimeter Collapse
In Q2 2026, phishing became the leading initial access vector in over half of Cisco Talos Incident Response engagements, up from rough…

WhatsApp Patches Zero-Day Zero-Click: The Apple Combo That Exposes
Updated August 3, 2026 — WhatsApp has released emergency updates to fix CVE-2025-55177, an insufficient authorization vulnerability in…

Broadcom Patches Five VMware Vulnerabilities: Three Critical Flaws Up to CVSS 9.8
Broadcom released patches on July 29, 2026 for five vulnerabilities in VMware vCenter, ESXi, Workstation, and Fusion. Three are critic…

NGINX Rift and Fragnesia: Two Critical Flaws at the Heart of Internet Infrastructure
An 18-year-old heap overflow hits nearly 19 million NGINX servers with unauthenticated RCE, while a local Linux exploit corrupts the p…

May 2026 Patch Tuesday: 161 CVEs, No Zero-Days, But Wormable Risks Loom
Microsoft's May 2026 Patch Tuesday fixes 161 vulnerabilities with no actively exploited zero-days — the first such month since June 20…

GStreamer RCE Flaw in rtpsbcdepay Codec: Patch Available
ZDI-26-467 (CVE-2026-18299) details a use-after-free in GStreamer's RTP SBC depayloader enabling remote code execution. The primary ri…

SSRF in Phoenix Contact MQTT Broker: The Assault on EV Chargers Starts Here
ZDI-26-518 reveals a flaw in the MQTT service of Phoenix Contact CHARX SEC-3150 EV chargers. An unauthenticated, network-adjacent atta…

Estée Lauder's 10-Month Oracle EBS Breach: The Suspected Patch Gap That Let Clop In
Estée Lauder disclosed a 10-month breach of its Oracle E-Business Suite HR system. The Clop ransomware group exploited CVE-2025-61882,…

CVE-2026-6100: CPython Use-After-Free in Decompressors Rated CVSS 9.1 Critical
CVE-2026-6100 affects CPython with a use-after-free in the lzma, bz2, and gzip decompressors. The CVSS 4.0 score is 9.1 CRITICAL, thou…

AnMed Ransomware: 72-Hour Criminal Deadline Collides With 72-Hour CIRCIA Mandate
AnMed Health suffered a ransomware attack starting July 26, 2026, with a patient reporting a 72-hour ransom demand. The health system…

SourTrade: The Browser Becomes an In-Memory Malware Factory
The SourTrade malvertising campaign assembles malware directly in the victim's browser memory using legitimate web APIs. The technique…

Aeon RCE via Pickle Dataset: ML Pipeline Risk
CVE-2026-18285: The Python library Aeon executed arbitrary code through pickle deserialization of seemingly legitimate datasets. The b…

TrendAI Vision One and the 'Historical' CVE-2025-71387: Patched in December
Trend Micro published bulletin KA-0023937 for CVE-2025-71387, a privilege escalation vulnerability in TrendAI Vision One that was alre…

Heimdall Data Database Proxy: Root RCE via Directory Traversal in uploadJar
ZDI-26-479 reveals a critical flaw in the uploadJar method of Heimdall Data Database Proxy. An authenticated attacker can achieve arbi…

Kemp LoadMaster: Hard-Coded Key in enablexroot Exposes Appliance to Root
Progress Software has patched CVE-2026-59689, a CVSS 8.0 privilege-escalation vulnerability in Kemp LoadMaster caused by a hard-coded…

WordPress wp2shell: In-the-Wild RCE Within 24 Hours of AI-Assisted Discovery
The wp2shell vulnerability chain in WordPress Core is under active in-the-wild exploitation with pre-authentication RCE. Wiz Research…

Heap Overflow in Kenwood DNR1007XR: Malicious vCard Grants Root Code Execution
ZDI-26-488 discloses a vulnerability in the Kenwood infotainment system: a physically present attacker achieves a root shell via a hea…

VoidStealer Bypasses Chrome Encryption by Attacking Memory
VoidStealer circumvents Chrome's App-Bound Encryption by extracting the master key from memory during decryption. The MaaS infostealer…