Cybersecurity
Curated coverage and analysis in this editorial area.

Zimbra Patches Critical Stored XSS in Classic Web Client, Reported by Google TAG
Zimbra released ZCS 10.1.19 on July 7, 2026 to fix a stored cross-site scripting vulnerability in the Classic Web Client reported by G…

LVM: Weeks of Blackout After Ransomware Hits System Unpatched for Two Years
Latvia's state-owned forestry company Latvijas valsts meži (LVM) remains paralyzed weeks after a June 22 ransomware attack. Roughly tw…

Microsoft Patches RoguePlanet: When the Antivirus Becomes the Attack Surface
CVE-2026-50656 enables privilege escalation to SYSTEM via the Microsoft Defender engine. The fix arrives through an automatic engine u…

AssuranceAmerica: 7 Million Driver's Licenses Exposed, No Credit Monitoring Offered
A single compromised employee account opened access to nearly 7 million driver's license numbers. AssuranceAmerica is not offering cre…

Hyadina Strikes with GodDamn: Microsoft-Signed Driver Disables EDR in 24 Hours
The Hyadina ransomware-as-a-service group deploys a new locker, GodDamn, using the Microsoft-signed PoisonX kernel driver to neutraliz…

Ollama Zero-Day DoS: downloadBlob Bug Puts Local AI Servers at Risk
ZDI has disclosed a zero-day vulnerability in Ollama enabling unauthenticated remote denial-of-service attacks via the downloadBlob fu…

FortiBleed: 74,000 FortiGates Exposed — Patching Alone Won't Fix It
CISA estimates 74,000 Fortinet devices have compromised credentials. The FortiBleed campaign exploits credential reuse and brute-force…

Qualys Unveils Risk Operations Center for the 'Day Minus Seven' Era
Qualys published a product-tech blog post on July 8, 2026 introducing the Risk Operations Center (ROC) as an operational response to w…

IRIS C2: Convicted Fraudsters Run Zero-Day Exploit Startup
IRIS C2, a McLean, Virginia startup offering up to $7 million for zero-day vulnerabilities, is operated by Jacob Wohl and Jack Burkman…

Ubiquiti Patches CVE-2026-50746, Maximum-Severity Flaw in UniFi OS
Ubiquiti released security updates on July 8, 2026 for seven critical vulnerabilities in UniFi OS. The most severe, CVE-2026-50746, ca…

Accenture Confirms Data Breach: 35 GB of Data Up for Sale by Threat Actor '888'
Accenture has confirmed a security breach after threat actor '888' listed 35 GB of allegedly stolen data for sale on a cybercrime foru…

UAT-7810 Expands ORB Network: New LONGLEASH, DOGLEASH, and JARLEASH Backdoors
Cisco Talos reveals the China-nexus APT UAT-7810 is actively expanding its LapDogs Operational Relay Box (ORB) network with new malwar…