Archive
All articles, newest first. Page 8.

AsyncAPI: Five npm Packages Compromised with Valid Provenance
Attackers hijacked the AsyncAPI project's CI/CD pipeline on July 14, 2026, stealing the asyncapi-bot service account token and publish…

npm/PyPI Supply Chain: When Sigstore Provenance Signs the Malware
Four attacks in seven weeks compromised npm and PyPI. Sigstore and SLSA provenance proved useless: the attacker stole the CI identity,…

Prinz Eugen: The Ransomware That Encrypts Recent Files and Vanishes Without a Trace
Prinz Eugen sorts files by modification date, verifies decryptability, then wipes its key and binary. A model targeting the data least…

AI-Assisted Kernel Exploit: Researcher Publishes Root Escalation Code for Linux
STAR Labs researcher Lee Jia Jie has released exploit code for CVE-2026-53264, a use-after-free vulnerability in the Linux kernel's ne…

Microsoft Patches RoguePlanet, the Defender Black Hole That Handed SYSTEM to Anyone
CVE-2026-50656: a race condition in the Windows 10 and 11 antivirus engine let a standard user gain SYSTEM privileges. The silent engi…

Iran: APTs Modify Internet-Exposed PLCs, CISA Alerts Seven Agencies
CISA and six U.S. government agencies have updated a joint advisory on Iranian attacks against programmable logic controllers (PLCs) d…

OWAReaper: The Malware That Survives Device Reimaging
Russia-aligned APT Laundry Bear (TA488) exploited CVE-2026-42897, an XSS flaw in Outlook Web Access, to deploy OWAReaper — a browser-b…

Aeon RCE Flaw in Benchmark Loading: The Risk Lies in the Datasets
Trend Micro's Zero Day Initiative published advisory ZDI-26-470 assigning CVE-2026-18287 to a code injection vulnerability in the Pyth…

GIMP: APNG Integer Overflow Enables Code Execution, Patch Released
An integer overflow in GIMP's APNG parser allows remote arbitrary code execution when a user opens a malicious file. Tracked as CVE-20…

GStreamer RCE Bug in MRF Parsing: Urgent Update Required
An out-of-bounds write vulnerability in GStreamer's MRF file parser enables remote code execution. User interaction is required, but t…

Cisco FMC CVE-2026-20316: Actively Exploited Zero-Day, CISA Sets August 1 Deadline
Cisco disclosed CVE-2026-20316, a zero-day static-credential vulnerability in FMC Software. CISA has ordered federal agencies to remed…

Sony XAV-9500ES: Bluetooth Turns Weapon — From Pwn2Own to the Parking Lot
ZDI advisory ZDI-26-475 details a heap-based buffer overflow in the AVRCP parser of the Sony XAV-9500ES head unit, enabling remote cod…

Adminer: A 2021 Patch Bug Returns as RCE — The CVE-2026-15686 Case
Vulnerability ZDI-26-478 shows how a fix for CVE-2021-43008 introduced a new RCE vector via catastrophic backtracking in preg_match().

NoMachine getstat Command Injection Opens Door to RCE, CVSS 8.8
ZDI-26-483 details a command injection flaw in NoMachine's getstat function that allows authenticated remote code execution. A patch i…

WatchGuard FireWare OS Buffer Overflow Turns Firewall Into a Backdoor
A vulnerability in the networkd process of WatchGuard FireWare OS allows an authenticated remote attacker to execute arbitrary code wi…

macOS USD Library Buffer Overflow Enables RCE via Malicious 3D Files
CVE-2026-43729 is a heap-based buffer overflow in Apple's USD library that allows arbitrary code execution through crafted 3D scene fi…

QuantaStor RCE in Kapacitor Exposes Storage Supply-Chain Risks
CVE-2026-18265 hits OSNEXUS QuantaStor with a CVSS 9.8. The flaw lies in Kapacitor, an InfluxData component, configured without authen…

CVE-2026-16723: FastJson 1.x Under Active RCE Zero-Day Attack, Patch Unlikely
An unpatched RCE vulnerability affects FastJson 1.2.68 through 1.2.83 in Spring Boot fat-JAR deployments. The library, with 25,600 Git…

Rails Active Storage Exposes Arbitrary Files: The 'EOL Window' That Forces the Issue
A critical flaw in Ruby on Rails Active Storage lets unauthenticated attackers read arbitrary server files via crafted image uploads.…

RufRoot: The AI Vulnerability That Survives the Patch — 233 Tools Exposed and Persistent Memory Poisoning
CVE-2026-59726 in Ruflo exposes 233 MCP tools without authentication, enabling RCE, LLM API key theft, and persistent memory poisoning…

Broadcom Patches Five VMware Flaws: Full vCenter Bypass and VM Escape
Three critical vulnerabilities hit vCenter and ESXi. Two allow credential-less access; one enables escape from a virtual machine to th…

Tengu: The Botnet That Turns Reboot Into a Forensic Trap
Discovered by Nozomi Networks Labs, the Mirai variant Tengu abuses the hardware watchdog timer on embedded Linux devices to force an a…

CVE-2026-10702: One Click Is All It Takes to Compromise Tor Browser
A JIT compiler bug in Firefox propagates to Tor Browser, enabling arbitrary code execution on a single page visit. Mozilla patched it…

Russian Zero-Clicks Empty Zimbra Webmail Without a Single Click
An XSS bug in Zimbra Classic UI let a Russian espionage group steal 90 days of email and 2FA codes just by viewing a message