Cybersecurity
Cybersecurity collects analysis on vulnerabilities, exploits, patch management, ransomware, supply chain, AI security and threat intelligence. These articles help IT professionals, developers and security analysts follow operational threats, vendor updates and technical trends.

Head Mare APT Turns TrueConf Servers into Supply-Chain Attack Vehicles
The Head Mare APT group exploited two zero-day vulnerabilities in TrueConf Server to distribute the PhantomCore and PhantomGraph backd…

Intellexa: Leaked Documents Expose 14 Zero-Days and Vendor Remote Access to Government Clients
Internal documents stolen from mercenary spyware vendor Intellexa reveal a systematic inventory of at least 14 zero-days for Android,…

Local Malware Bypasses Google Passkeys: The Flaw Is in Chrome, Not FIDO2
Palo Alto Networks Unit 42 research demonstrates that local malware can bypass FIDO2 passkeys in Chrome on Windows using three techniq…

Greatness PhaaS: Device Code Phishing and MFA Bypass in a Single Platform
The Greatness PhaaS platform has added device code phishing to its arsenal alongside AiTM and OAuth consent abuse, enabling Microsoft…

Kimsuky Builds Offline AI Stack to Automate Phishing and Malware
North Korean APT group Kimsuky has deployed a fully offline AI pipeline on its own C2 servers. Genians researchers documented the stac…

WatchGuard FireWare OS: Stack Buffer Overflow Enables Root RCE, Patch Available
A stack-based buffer overflow in the WatchGuard FireWare OS networkd daemon allows remote code execution with root privileges. Tracked…

Apple Patches CVE-2026-20700: Zero-Day in dyld Survived Two Decades in iOS
Apple has fixed CVE-2026-20700, a zero-day memory corruption vulnerability in the dyld dynamic linker that existed in iOS for over a d…

APT29 Hits Hotel Wi-Fi: Steals M365 Credentials with Malware
Microsoft attributes the CaptiveCrunch campaign to Storm-2945, a Midnight Blizzard sub-group, which compromises hotel captive portals…

TONTOU: The AMD Attack Exposing the Gap Between Linux Patches and Vendor Disclosure
The TONTOU attack bypasses Spectre-v2 mitigations on AMD Zen 1–4 processors. The Linux kernel received a fix on June 2, 2026, but AMD'…

Cisco FMC Under Attack: Static Credentials Exploited, No Workaround Available
CVE-2026-20316 in Cisco Secure Firewall Management Center involves hard-coded static credentials, confirmed active exploitation, and n…

Battering RAM: $50 Physical Attack Bypasses SGX and SEV-SNP on DDR4 Systems
A sub-$50 DDR4 interposer compromises confidential computing. Vendors classify physical attacks as out of scope. Article based on a si…

Microsoft Uses AI to Find Windows Flaws Before Attackers Could Exploit Them
In the May 2026 Patch Tuesday, Microsoft fixed 138 vulnerabilities. Sixteen were discovered by the MDASH AI system before they could b…