Archive
All articles, newest first. Page 8.

DarkSword and Coruna: Government-Grade Spyware Turns Mass Crime on iOS
Apple issued rare retroactive patches for legacy iOS versions to address two APT-grade spyware frameworks now weaponized in zero-click…

Landfall: Military-Grade Spyware Targeted Samsung Galaxy Devices for Months
Palo Alto Networks Unit 42 uncovered Landfall, a commercial-grade modular Android spyware that exploited the Samsung zero-day CVE-2025…

Oracle Patches PeopleSoft Flaw That Emptied 300 Servers in Six Weeks
The July 2026 Critical Patch Update fixes CVE-2026-35278 and CVE-2026-35273, the pre-auth RCE and privilege-escalation chain exploited…

CVE-2026-31431 "Copy Fail": 732 Bytes of Code Breaks the Linux Kernel Since 2017
A vulnerability in the algif_aead module enables root privilege escalation via a 732-byte exploit. CISA has added CVE-2026-31431 to th…

Accenture Confirms 'Isolated Matter' After Threat Actor '888' Lists 35GB of Data for Sale
Threat actor '888' claims to be selling roughly 35GB of Accenture data, including source code, Azure tokens, and SSH keys. Accenture a…

GhostApproval, 14 UniFi CVEs, and Roundcube Espionage: A Triple Threat Convergence
Three critical attack vectors converged in July 2026: the GhostApproval symlink vulnerability in six AI coding assistants, 14 new crit…

Fairlife Halts All U.S. Milk Production: The Ransomware the SEC Didn't Classify as Material
On July 16, 2026, Fairlife, a ~$4 billion Coca-Cola subsidiary, suspended every U.S. plant after ransomware hit 'production-related sy…

ViteVenom: Seven npm Packages Use Blockchain as Unstoppable C2
The ViteVenom campaign distributes malware via npm using Tron, Aptos, and Binance Smart Chain as command-and-control infrastructure. A…

Dell RecoverPoint: CVSS 10 Zero-Day Exploited for 18 Months by China-Nexus APT
A maximum-severity vulnerability in Dell RecoverPoint for Virtual Machines allowed a suspected China-linked APT cluster to operate und…

Telepuz: The Modular Malware Turning VIDAR into a Criminal Platform
Elastic Security Labs analyzes Telepuz, a modular malware under active development and distributed as Malware-as-a-Service via a Click…

From VPN Bypass to Encrypted Domain: How CVE-2026-0257 Fuels Qilin Ransomware
Arctic Wolf Labs confirms active exploitation of CVE-2026-0257 to deploy Qilin ransomware. Specific TTPs reveal shared infrastructure…

RabbitMQ CVE-2026-5721: Obsolete Endpoint Exposed OAuth Secret, Went Undetected
An obsolete endpoint in RabbitMQ's management panel exposed the OAuth client secret. CVE-2026-5721 carries a CVSS 8.7 score.

Atomic Arch: 1,500 AUR Packages Hijacked, Targeting Developers and CI
The Atomic Arch operation hijacked over 1,500 Arch User Repository packages via orphaned-package ownership transfers to deliver a Rust…

Apple Patches Zero-Day in dyld: A Flaw Hidden for Over a Decade
CVE-2026-20700 carries a CVSS 7.8 rating and is actively exploited against targeted individuals. Apple released patches on February 11…

NFCShare: The Campaign Turning GitHub Into a Distribution Pipeline for Fake Banking Apps
NFCShare steals payment-card data via NFC and captures PINs through spoofed banking apps hosted on GitHub. The European campaign produ…

WordPress: wp2shell Chain Exploited in the Wild 24 Hours After AI-Assisted Discovery
The wp2shell vulnerability chain in WordPress Core was discovered using AI for roughly $25, published July 17, and actively exploited…

IngressNightmare: The Design Flaw That Breaches the Kubernetes Perimeter
CVE-2025-1974 in the Ingress NGINX Controller enables unauthenticated RCE and full cluster takeover. Over 6,500 clusters are publicly…

Misconfigured Server Exposes Three Evilginx Phishing Campaigns
A server with directory listing enabled revealed the full arsenal of three phishing operators targeting Microsoft 365 accounts using d…

DarkSword: JavaScript iOS Exploit Kit Strikes via Compromised Legitimate Sites
DarkSword chains six CVEs to compromise iPhones through compromised legitimate websites. The fileless, in-memory chain self-erases aft…

Vietnam's Ransomware Dip Masks an Underestimated Threat
In Q1 2026, 2.56% of Vietnamese SMEs were hit by ransomware, a slight decline from 2.91% in Q1 2025. The figure, published July 16 by…

CISA Adds CVE-2008-4128 to KEV: An 18-Year-Old Cisco IOS Bug Resurfaces
CISA's Known Exploited Vulnerabilities catalog now includes CVE-2008-4128, an 18-year-old CSRF flaw in Cisco IOS 12.4. Federal agencie…

Italy as Both Client and Target: The Graphite Case Exposes the Limits of Spyware
On July 18, 2026, forensic investigator Luca Cadonici presented a comprehensive reconstruction of the Graphite case at the Cyber Crime…

AsyncAPI: The Supply Chain That Trusted Its Own Signatures
On July 14, 2026, an attacker compromised the AsyncAPI release pipeline. Five malicious versions of four npm packages, with over two m…

Patch Day: Mozilla Confirms Public Exploits for Firefox as Adobe and VMware Ship CVSS 9+ Fixes
On July 15, 2026, four vendors released critical updates simultaneously. Mozilla broke with standard practice by explicitly confirming…