Cybersecurity
Cybersecurity collects analysis on vulnerabilities, exploits, patch management, ransomware, supply chain, AI security and threat intelligence. These articles help IT professionals, developers and security analysts follow operational threats, vendor updates and technical trends.

Ex-Huntress Analyst Accuses Company of Covering Up Insider Who Allegedly Fed FBI Data to DevMan Ransomware Gang
A former SOC analyst claims Huntress concealed an insider who passed U.S. law enforcement communications to the DevMan ransomware grou…

Beyond IOCs: Talos Unveils Vision for LLMs in Threat Intelligence
Cisco Talos explores how large language models transcend traditional indicators of compromise by indexing strategic reports in natural…

'Snoopy' Sentenced: 18 Months for the Massive DraftKings Hack
Nathan Austad, known as 'Snoopy,' received an 18-month federal prison sentence for orchestrating the November 2022 credential-stuffing…

ThreatsDay June 2026: Miasma Toolkit Leaked, Claude Code Patched, AI Agent Phishing
The June 2026 ThreatsDay Bulletin, published June 11 by Rescana, is an aggregated cyber threat digest. This analysis relies primarily…

Adobe Reader: Patch Now for CVE-2026-27278, RCE via PDF
Adobe has released APSB26-26 for CVE-2026-27278, a Use-After-Free vulnerability in Acrobat Reader DC that enables remote code executio…

FlowiseAI CSV Agent RCE: Arbitrary Python Code Execution with Authentication Bypass
ZDI-26-365 discloses a remote code execution vulnerability in FlowiseAI's CSV Agent: Python code injection via customReadCSV with auth…

Docker MCP Plugin: RCE via OCI Label, Urgent Patch
ZDI-26-363: The YAML label io.docker.server.metadata in the Docker MCP Gateway enables remote code execution as root. The fix isolates…

ZDI-26-376: RCE in Quest NetVault Backup with Authentication Bypass
Command injection in NVBULogDaemon enables remote code execution as SYSTEM. Patch available but no CVE or CVSS assigned.

Fuji Electric Tellus: Kernel Driver Bug Enables SYSTEM Privilege Escalation
CVE-2026-8108 in the Fuji Electric Tellus pcid64 driver allows local privilege escalation to SYSTEM via Registry APIs with excessive p…

Unraid: Command Injection in ToggleState.php Enables RCE
CVE-2026-9773 in the Unraid web server: command injection in ToggleState.php allows authenticated remote code execution. CVSS 8.8, fix…

StrikeShark: New Loader Targets Governments and Diplomats Across 10 Countries
Kaspersky documents the StrikeShark campaign: SharkLoader delivers Cobalt Strike by exploiting known vulnerabilities with public PoCs,…

Railway Cybersecurity: The IT/OT Boundary Has Collapsed
Rail systems are abandoning isolated SCADA for IP networks and AI. DNV's Jorge Aldegunde explains why security is now an active interf…