Cybersecurity
Cybersecurity collects analysis on vulnerabilities, exploits, patch management, ransomware, supply chain, AI security and threat intelligence. These articles help IT professionals, developers and security analysts follow operational threats, vendor updates and technical trends.

CVE-2026-6071: RCE in Rockwell Arena Simulation via Malicious DOE File
Trend Micro's Zero Day Initiative disclosed CVE-2026-6071, an out-of-bounds write in Rockwell Automation Arena Simulation's DOE file p…

NVIDIAScape: Container Escape in Three Lines of Code in the NVIDIA Toolkit
CVE-2025-23266, rated CVSS 9.0, affects 37% of AI cloud environments. An old-school bug in the NVIDIA Container Toolkit enables privil…

SonicWall SMA 1000: The Unexpected Backdoor — Active Exploitation and a 72-Hour Patch Window
SonicWall disclosed CVE-2026-15409 and CVE-2026-15410 on July 14, 2026: active exploitation since June 22, public PoC, and a mandatory…

CISA Overhauls Vulnerability Management: 72-Hour Deadline for High-Risk KEVs
The new CISA directive abandons the one-size-fits-all model of BOD 22-01 and introduces four risk-based variables for prioritizing kno…

Zimbra 10.1.20 Patches Critical Command Injection Among Nine Vulnerabilities
Zimbra released version 10.1.20 of the Collaboration Suite on July 20, 2026, fixing nine security flaws. The most severe is a command…

TrapDoor: 34+ Malicious Packages Turn AI Assistants Into Insider Threats
The TrapDoor campaign has distributed over 34 packages across npm, PyPI, and Crates.io with multi-stage payloads and hidden instructio…

German Police Dismantle Kratos, the Kit That Turned AiTM Phishing Into a Franchise
German, U.S., and Indonesian authorities dismantled the Kratos phishing-as-a-service platform, seizing over 200 servers and arresting…

Microsoft Uncovers OAuth Abuse: Vishing and Supply Chain Attacks Target SaaS
Microsoft has documented ShinyHunters-linked campaigns abusing trusted OAuth relationships in Salesforce through vishing and third-par…

DarkSword and Coruna: Government-Grade Spyware Turns Mass Crime on iOS
Apple issued rare retroactive patches for legacy iOS versions to address two APT-grade spyware frameworks now weaponized in zero-click…

Landfall: Military-Grade Spyware Targeted Samsung Galaxy Devices for Months
Palo Alto Networks Unit 42 uncovered Landfall, a commercial-grade modular Android spyware that exploited the Samsung zero-day CVE-2025…

Accenture Confirms 'Isolated Matter' After Threat Actor '888' Lists 35GB of Data for Sale
Threat actor '888' claims to be selling roughly 35GB of Accenture data, including source code, Azure tokens, and SSH keys. Accenture a…

GhostApproval, 14 UniFi CVEs, and Roundcube Espionage: A Triple Threat Convergence
Three critical attack vectors converged in July 2026: the GhostApproval symlink vulnerability in six AI coding assistants, 14 new crit…