Cloud & Enterprise
Cloud and enterprise IT covers identity, access, SaaS, hybrid infrastructure and corporate attack surfaces. The analysis helps readers follow risks, incidents and architectural decisions relevant to complex environments.

CVE-2026-63077: Critical RCE in JetBrains TeamCity, CVSS 9.8
JetBrains has patched a deserialization vulnerability in TeamCity On-Premises with a CVSS 9.8 score. The unauthenticated RCE via the a…

Three Decades of Forensic DNA Evidence Left Without Digital Signatures
A CVSS 8.2 vulnerability in Thermo Fisher Applied Biosystems software allows tampering with forensic DNA files. The patch adds digital…

AI Agent Prompt Injection: SOCs Are Blind to Language as a Weapon
Gartner and OWASP confirm prompt injection as the top AI threat for 2026. Traditional SOCs cannot detect attacks that weaponize natura…

Intel and AMD Patch 70 Flaws: Two Critical CVSS 9.3 and 9.2 Bugs in GPU Drivers
On May 13, 2026, Intel and AMD released 28 advisories covering 69 vulnerabilities. Two critical flaws hit chip software drivers, not t…

Notepad++ Compromised: Lotus Blossom Hijacked Updates for Months
Chinese threat actors compromised Notepad++'s shared hosting infrastructure to selectively deliver malware to telecom and financial or…

TokenLover and YaksaLover: The PhaaS Kits That Measure Persistence With a 'Password Change Survival Rate'
Italy's ACN details two Phishing-as-a-Service toolkits that abuse the Device Code Flow and NGC keys to achieve persistence that surviv…

Cisco Confirms FMC Zero-Day: Static Credentials Under Attack, CISA Sets August 1 Deadline
Cisco confirms active exploitation of CVE-2026-20316 in Secure Firewall Management Center. CISA adds the flaw to its KEV catalog, mand…

F5 Races Against Its Own Stolen Code: 45 Vulnerabilities Disclosed in a Single Quarter
Nation-state actors compromised F5's internal systems, exfiltrating portions of BIG-IP proprietary source code and details on undisclo…

Broadcom Patches Five VMware Vulnerabilities: Three Critical Flaws Up to CVSS 9.8
Broadcom released patches on July 29, 2026 for five vulnerabilities in VMware vCenter, ESXi, Workstation, and Fusion. Three are critic…

Estée Lauder's 10-Month Oracle EBS Breach: The Suspected Patch Gap That Let Clop In
Estée Lauder disclosed a 10-month breach of its Oracle E-Business Suite HR system. The Clop ransomware group exploited CVE-2025-61882,…

TrendAI Vision One and the 'Historical' CVE-2025-71387: Patched in December
Trend Micro published bulletin KA-0023937 for CVE-2025-71387, a privilege escalation vulnerability in TrendAI Vision One that was alre…

Kemp LoadMaster: Hard-Coded Key in enablexroot Exposes Appliance to Root
Progress Software has patched CVE-2026-59689, a CVSS 8.0 privilege-escalation vulnerability in Kemp LoadMaster caused by a hard-coded…