Archive
All articles, newest first. Page 7.

LastPass Suffers New Breach via Klue: Vaults Safe, Personal Data Exposed
LastPass disclosed an indirect data breach through vendor Klue. Password vaults remain secure, but personal data including names, emai…

Microsoft Patch Tuesday July 2026: Two Zero-Days, and the CVSS 5.3 Is More Dangerous Than the 7.8
Microsoft's July 2026 Patch Tuesday addressed 570 CVEs, including two actively exploited zero-days: CVE-2026-56164 in SharePoint Serve…

FakeGit: 800 AI Repositories on GitHub Turn Agents Into Malware Vectors
Island uncovered 800 malicious GitHub repositories masquerading as AI Skills and MCP servers. AI agents autonomously recommended the m…

AsyncAPI: 5 Malicious npm Packages with Valid SLSA Attestations Distributed for Hours
Attackers compromised two AsyncAPI GitHub repositories via a misconfigured pull_request_target workflow, then used legitimate CI/CD pi…

CVE-2026-16232: Check Point SmartConsole Zero-Day Actively Exploited in the Wild
Check Point confirms active exploitation of CVE-2026-16232, an authentication bypass with a CVSS 9.3 score in SmartConsole. CISA has a…

BIN Project Files as Weapons: The Delta Electronics DTM Soft Flaw That Turns Engineering Data into Code Execution
A deserialization vulnerability in Delta Electronics DTM Soft allows remote code execution via malicious BIN project files. With a CVS…

AnyDesk 0-Day ZDI-26-400: Vendor Ignored 16 Months of Coordinated Disclosure
ZDI published advisory ZDI-26-400 for CVE-2026-15681, a local denial-of-service vulnerability in AnyDesk rated CVSS 4.7. The vendor re…

Windmill Under Attack: Active Path Traversal on 170 Exposed Servers
CVE-2026-29059 hits the Windmill automation platform with an unauthenticated path traversal. A patch has existed since January, yet th…

Metasploit Drops Two Modules: FlowiseAI RCE and macOS Privilege Escalation
The Metasploit Framework adds exploit modules for CVE-2026-41264 in FlowiseAI and CVE-2024-27822 in macOS PackageKit. Both are product…

RansomHouse Hits Nichirei: 140 Cold-Storage Hubs Frozen, KFC Japan Runs Out of Chicken
RansomHouse claimed responsibility for a cyberattack on Nichirei, Japan's frozen-food logistics giant. The company's defensive network…

OpenSSL's Unsettling Discrepancy: An X.509 Flaw Caught Between Information Disclosure and DoS
CVE-2026-42771 hits OpenSSL with a CVSS 6.5. ZDI calls it information disclosure; CVE.org points to likely DoS. The split complicates…

Synology DS925+: Root RCE via Redis MailPlus, Patch Available
ZDI-26-423 reveals a cryptographic flaw in the Synology DS925+ MailPlus Redis component. Network-adjacent attackers achieve unauthenti…

WatchGuard FireWare OS: IKEv2 Bug Enables Remote DoS with a Single Packet
A null pointer dereference in WatchGuard FireWare OS exposes firewalls with active IKEv2 VPN to remote denial-of-service. CVE-2026-130…

Samsung rlottie: RCE Bug in Lottie Files Masked by a "Medium" CVSS
A numeric truncation flaw in Samsung rlottie enables remote code execution via malicious Lottie animations. The CVSS 5.5 rating unders…

Autel EV Charger: Remote RCE via OCPP WebSocket, Discovered at Pwn2Own
The ZDI-26-437 vulnerability in the Autel MaxiCharger AC Elite Home enables pre-authentication remote code execution via an integer un…

CVE-2026-6071: RCE in Rockwell Arena Simulation via Malicious DOE File
Trend Micro's Zero Day Initiative disclosed CVE-2026-6071, an out-of-bounds write in Rockwell Automation Arena Simulation's DOE file p…

NVIDIAScape: Container Escape in Three Lines of Code in the NVIDIA Toolkit
CVE-2025-23266, rated CVSS 9.0, affects 37% of AI cloud environments. An old-school bug in the NVIDIA Container Toolkit enables privil…

SonicWall SMA 1000: The Unexpected Backdoor — Active Exploitation and a 72-Hour Patch Window
SonicWall disclosed CVE-2026-15409 and CVE-2026-15410 on July 14, 2026: active exploitation since June 22, public PoC, and a mandatory…

CISA Overhauls Vulnerability Management: 72-Hour Deadline for High-Risk KEVs
The new CISA directive abandons the one-size-fits-all model of BOD 22-01 and introduces four risk-based variables for prioritizing kno…

Zimbra 10.1.20 Patches Critical Command Injection Among Nine Vulnerabilities
Zimbra released version 10.1.20 of the Collaboration Suite on July 20, 2026, fixing nine security flaws. The most severe is a command…

TrapDoor: 34+ Malicious Packages Turn AI Assistants Into Insider Threats
The TrapDoor campaign has distributed over 34 packages across npm, PyPI, and Crates.io with multi-stage payloads and hidden instructio…

German Police Dismantle Kratos, the Kit That Turned AiTM Phishing Into a Franchise
German, U.S., and Indonesian authorities dismantled the Kratos phishing-as-a-service platform, seizing over 200 servers and arresting…

Handala and the MOIS Behind the Cal Water Breach: 5 GB of Customer Data Exfiltrated via an RTKBase NTRIP Caster
The Iranian APT group Handala, a front for the Ministry of Intelligence and Security (MOIS), claimed responsibility on June 11, 2026,…

Microsoft Uncovers OAuth Abuse: Vishing and Supply Chain Attacks Target SaaS
Microsoft has documented ShinyHunters-linked campaigns abusing trusted OAuth relationships in Salesforce through vishing and third-par…