Cybersecurity
Cybersecurity collects analysis on vulnerabilities, exploits, patch management, ransomware, supply chain, AI security and threat intelligence. These articles help IT professionals, developers and security analysts follow operational threats, vendor updates and technical trends.

ViteVenom: Seven npm Packages Use Blockchain as Unstoppable C2
The ViteVenom campaign distributes malware via npm using Tron, Aptos, and Binance Smart Chain as command-and-control infrastructure. A…

From VPN Bypass to Encrypted Domain: How CVE-2026-0257 Fuels Qilin Ransomware
Arctic Wolf Labs confirms active exploitation of CVE-2026-0257 to deploy Qilin ransomware. Specific TTPs reveal shared infrastructure…

Atomic Arch: 1,500 AUR Packages Hijacked, Targeting Developers and CI
The Atomic Arch operation hijacked over 1,500 Arch User Repository packages via orphaned-package ownership transfers to deliver a Rust…

Apple Patches Zero-Day in dyld: A Flaw Hidden for Over a Decade
CVE-2026-20700 carries a CVSS 7.8 rating and is actively exploited against targeted individuals. Apple released patches on February 11…

WordPress: wp2shell Chain Exploited in the Wild 24 Hours After AI-Assisted Discovery
The wp2shell vulnerability chain in WordPress Core was discovered using AI for roughly $25, published July 17, and actively exploited…

IngressNightmare: The Design Flaw That Breaches the Kubernetes Perimeter
CVE-2025-1974 in the Ingress NGINX Controller enables unauthenticated RCE and full cluster takeover. Over 6,500 clusters are publicly…

DarkSword: JavaScript iOS Exploit Kit Strikes via Compromised Legitimate Sites
DarkSword chains six CVEs to compromise iPhones through compromised legitimate websites. The fileless, in-memory chain self-erases aft…

CISA Adds CVE-2008-4128 to KEV: An 18-Year-Old Cisco IOS Bug Resurfaces
CISA's Known Exploited Vulnerabilities catalog now includes CVE-2008-4128, an 18-year-old CSRF flaw in Cisco IOS 12.4. Federal agencie…

Italy as Both Client and Target: The Graphite Case Exposes the Limits of Spyware
On July 18, 2026, forensic investigator Luca Cadonici presented a comprehensive reconstruction of the Graphite case at the Cyber Crime…

AsyncAPI: The Supply Chain That Trusted Its Own Signatures
On July 14, 2026, an attacker compromised the AsyncAPI release pipeline. Five malicious versions of four npm packages, with over two m…

Patch Day: Mozilla Confirms Public Exploits for Firefox as Adobe and VMware Ship CVSS 9+ Fixes
On July 15, 2026, four vendors released critical updates simultaneously. Mozilla broke with standard practice by explicitly confirming…

Three Chained Zero-Days in Siemens Switches: From xz Utility to Root Access
Three zero-day vulnerabilities in Siemens RUGGEDCOM ROX II switches enable full privilege escalation and persistent root access. Firmw…