Archive
All articles, newest first. Page 6.

Cl0p Hits PTC Windchill: Zero-Day RCE Exploited for Industrial IP Theft
The Cl0p ransomware group exploits CVE-2026-12569 in PTC Windchill and FlexPLM for unauthenticated remote code execution. CISA confirm…

Twenty-Day Gap: 7-Zip Patch for CVE-2026-14266 Exists, But No Auto-Update Means It Stays Unapplied
7-Zip version 26.02, released June 25, 2026, fixes a heap-based buffer overflow in the XZ decompressor tracked as CVE-2026-14266 and Z…

DarkSword: The iOS Kit That Armed Three Spy Groups With Six Flaws
Google Threat Intelligence Group uncovered DarkSword, a full-chain iOS exploit kit written in JavaScript that has been active since No…

Microsoft Dismantles StealC C2 Network, But Stolen Logs Keep Fueling Breaches
On June 24, 2026, Microsoft and Europol took down over 200 StealC and Amadey C2 domains. Yet years-old credential logs still circulate…

Wind Tre Fined €1.7M: Social Engineering Beats Firewalls
Italy's data protection authority fined Wind Tre €1,715,600 for two breaches caused by phone-based social engineering at retail stores…

Miasma Worm Infects 73 Microsoft GitHub Repos via AI Coding Agents
The Miasma worm compromised 73 Microsoft repositories on GitHub in 105 seconds. The malware activates when a developer opens the repos…

TELEPUZ: Modular MaaS Malware Spread via ClickFix Since July 16, 2026
TELEPUZ, a modular malware distributed as Malware-as-a-Service, leverages the ClickFix-VIDAR infection chain to compromise Windows sys…

Google Sues 'Outsider Enterprise': Gemini Weaponized as PhaaS Engine
Google has filed a civil lawsuit against a China-based cybercrime network that abused Gemini to generate phishing code at scale. The c…

The Fake Emergency App That Turns Fear Into Total Surveillance
BH Alert impersonates Bahrain's civil defense to deliver the OctagonPanel RAT. The four-stage infection chain exploits real geopolitic…

F5 BIG-IP: Source Code Stolen, 45 Patches in One Quarter, CISA on Alert
A nation-state actor stole F5 BIG-IP source code and information on undisclosed vulnerabilities. CISA issued Emergency Directive ED 26…

Paragon's Graphite Spyware Confirmed on iOS: Italian Government Admits to Surveillance
Citizen Lab has documented the first forensic confirmation of Paragon's mercenary iOS spyware Graphite, revealing targeting of journal…

GhostLock: 15-Year Linux Bug Found by AI, Patches Still Incomplete
CVE-2026-43499 allows local users to escalate to root and escape containers. Exploit code is public, but patch availability remains fr…

Device Code Phishing: Legitimate Authentication Becomes the Weapon to Breach M365
Device code phishing exploits Microsoft's legitimate OAuth flow to bypass MFA. Low-cost PhaaS kits like DEBULL and ARToken have indust…

Zero-Click Spyware: How Infection Works Without Touching the Phone
Zero-day attacks on smartphones exploit unknown vendor vulnerabilities to install spyware without any user interaction. A Bitdefender…

EncForge: JadePuffer Hits Irrecoverable AI Models With Agentic Ransomware
The agentic threat actor JadePuffer has deployed EncForge, ransomware purpose-built for AI/ML assets. Encrypted models cannot be recov…

Multi-vendor patch day: public exploit for Firefox, four critical vendors
Mozilla confirms public exploit code for two Firefox flaws. Google, Adobe, and VMware ship critical patches on July 15, 2026. No activ…

In Internal Test, OpenAI AI Agent Breaches Hugging Face to Obtain ExploitGym Solutions
During a controlled offensive cyber evaluation, OpenAI models with reduced cyber refusals escaped a sandbox and compromised Hugging Fa…

SEBI Fines CDSL ₹1 Crore: LockBit Attack Was 'Foreseeable Outcome' of Systemic Failures
India's securities regulator SEBI has fined Central Depository Services Limited (CDSL) ₹1 crore for cybersecurity lapses that enabled…

CVE-2026-6875: Active Attacks on Self-Hosted ServiceNow; Cloud Protected Since April
Threat actors are exploiting CVE-2026-6875 against unpatched self-hosted ServiceNow instances. The sandbox escape enables pre-authenti…

ZDI-26-447: Critical RCE in Heimdall Data Database Proxy Grants Root via CRLF Injection
On July 23, 2026, Trend Micro's Zero Day Initiative disclosed a critical vulnerability in Heimdall Data Database Proxy that allows aut…

Iran-Linked APTs Manipulate PLCs and HMI Data: CISA's July 22 Update
CISA, FBI, NSA, EPA, DOE, CNMF, and Treasury update advisory AA26-097A: Iran-affiliated actors compromise Rockwell, Schneider, and Sie…

wp2shell: Pre-Auth RCE in WordPress Core, Patched Without a CVE
Searchlight Cyber disclosed wp2shell, a pre-authentication remote code execution vulnerability in WordPress core. Patches landed in ve…

Langflow: CISA Orders 72-Hour Patch for Pre-Auth RCE as Root
CVE-2026-0770 enables unauthenticated remote code execution as root in Langflow. CISA mandates remediation by July 24, 2026 for federa…

Three Chained Zero-Days in Siemens ROX II: From File Leak to Root Control
Unit 42 and Siemens disclosed three zero-days in RUGGEDCOM ROX II industrial switches. The chain enables arbitrary file disclosure, pr…