Cybersecurity
Cybersecurity collects analysis on vulnerabilities, exploits, patch management, ransomware, supply chain, AI security and threat intelligence. These articles help IT professionals, developers and security analysts follow operational threats, vendor updates and technical trends.

SleeperGem: The Day RubyGems Became an npm-Style Target
Three malicious RubyGems packages compromised developer workstations through require-time execution and CI evasion. The campaign marks…

dYdX Hit by Third Supply-Chain Attack: Compromised npm and PyPI Packages Deliver Wallet Stealer and RAT
DeFi protocol with $1.5T cumulative volume compromised on npm and PyPI. Wallet stealer and remote access trojan distributed via mainta…

CVE-2026-3888: LPE to Root in snapd Hits Ubuntu LTS Since 2016
Qualys discovered a local privilege escalation vulnerability in snapd that lets a local attacker gain root on Ubuntu 16.04 through 24.…

Public Scanner Released for NGINX Map Regex Flaw; Full RCE Exploit Expected Around August 5
Researcher Stan Shaw (cyberstan) has published an open-source static scanner for CVE-2026-42533, a heap buffer overflow in the NGINX s…

Russia Exploits Zimbra Zero-Day: Patching Alone Won't Evict the Spies
A zero-click XSS flaw in Zimbra Collaboration Suite let a Russian espionage group harvest emails, 2FA codes, and persistent app passwo…

Autel Wallbox Exposed to Pre-Auth RCE: The Pwn2Own Bug Hitting Home EV Chargers
Trend Micro's Zero Day Initiative published advisory ZDI-26-437 on July 15, 2026, detailing a pre-authentication remote code execution…

Cl0p Hits PTC Windchill: Zero-Day RCE Exploited for Industrial IP Theft
The Cl0p ransomware group exploits CVE-2026-12569 in PTC Windchill and FlexPLM for unauthenticated remote code execution. CISA confirm…

DarkSword: The iOS Kit That Armed Three Spy Groups With Six Flaws
Google Threat Intelligence Group uncovered DarkSword, a full-chain iOS exploit kit written in JavaScript that has been active since No…

Wind Tre Fined €1.7M: Social Engineering Beats Firewalls
Italy's data protection authority fined Wind Tre €1,715,600 for two breaches caused by phone-based social engineering at retail stores…

Miasma Worm Infects 73 Microsoft GitHub Repos via AI Coding Agents
The Miasma worm compromised 73 Microsoft repositories on GitHub in 105 seconds. The malware activates when a developer opens the repos…

F5 BIG-IP: Source Code Stolen, 45 Patches in One Quarter, CISA on Alert
A nation-state actor stole F5 BIG-IP source code and information on undisclosed vulnerabilities. CISA issued Emergency Directive ED 26…

Paragon's Graphite Spyware Confirmed on iOS: Italian Government Admits to Surveillance
Citizen Lab has documented the first forensic confirmation of Paragon's mercenary iOS spyware Graphite, revealing targeting of journal…