Cybersecurity
Cybersecurity collects analysis on vulnerabilities, exploits, patch management, ransomware, supply chain, AI security and threat intelligence. These articles help IT professionals, developers and security analysts follow operational threats, vendor updates and technical trends.

GhostLock: 15-Year Linux Bug Found by AI, Patches Still Incomplete
CVE-2026-43499 allows local users to escalate to root and escape containers. Exploit code is public, but patch availability remains fr…

Device Code Phishing: Legitimate Authentication Becomes the Weapon to Breach M365
Device code phishing exploits Microsoft's legitimate OAuth flow to bypass MFA. Low-cost PhaaS kits like DEBULL and ARToken have indust…

Zero-Click Spyware: How Infection Works Without Touching the Phone
Zero-day attacks on smartphones exploit unknown vendor vulnerabilities to install spyware without any user interaction. A Bitdefender…

SEBI Fines CDSL ₹1 Crore: LockBit Attack Was 'Foreseeable Outcome' of Systemic Failures
India's securities regulator SEBI has fined Central Depository Services Limited (CDSL) ₹1 crore for cybersecurity lapses that enabled…

Langflow: CISA Orders 72-Hour Patch for Pre-Auth RCE as Root
CVE-2026-0770 enables unauthenticated remote code execution as root in Langflow. CISA mandates remediation by July 24, 2026 for federa…

Three Chained Zero-Days in Siemens ROX II: From File Leak to Root Control
Unit 42 and Siemens disclosed three zero-days in RUGGEDCOM ROX II industrial switches. The chain enables arbitrary file disclosure, pr…

LastPass Suffers New Breach via Klue: Vaults Safe, Personal Data Exposed
LastPass disclosed an indirect data breach through vendor Klue. Password vaults remain secure, but personal data including names, emai…

Microsoft Patch Tuesday July 2026: Two Zero-Days, and the CVSS 5.3 Is More Dangerous Than the 7.8
Microsoft's July 2026 Patch Tuesday addressed 570 CVEs, including two actively exploited zero-days: CVE-2026-56164 in SharePoint Serve…

AsyncAPI: 5 Malicious npm Packages with Valid SLSA Attestations Distributed for Hours
Attackers compromised two AsyncAPI GitHub repositories via a misconfigured pull_request_target workflow, then used legitimate CI/CD pi…

CVE-2026-16232: Check Point SmartConsole Zero-Day Actively Exploited in the Wild
Check Point confirms active exploitation of CVE-2026-16232, an authentication bypass with a CVSS 9.3 score in SmartConsole. CISA has a…

BIN Project Files as Weapons: The Delta Electronics DTM Soft Flaw That Turns Engineering Data into Code Execution
A deserialization vulnerability in Delta Electronics DTM Soft allows remote code execution via malicious BIN project files. With a CVS…

Synology DS925+: Root RCE via Redis MailPlus, Patch Available
ZDI-26-423 reveals a cryptographic flaw in the Synology DS925+ MailPlus Redis component. Network-adjacent attackers achieve unauthenti…