News
Curated coverage and analysis in this editorial area.

Vietnam's Ransomware Dip Masks an Underestimated Threat
In Q1 2026, 2.56% of Vietnamese SMEs were hit by ransomware, a slight decline from 2.91% in Q1 2025. The figure, published July 16 by…

CVE-2026-42533: Heap Buffer Overflow in NGINX Spans 15 Years of Versions
A heap buffer overflow in NGINX's two-pass scripting engine puts 15 years of releases at risk. The patch landed July 15, 2026; F5 cond…

Progress Orders ShareFile Shutdown: Third Critical Incident in Three Years
Progress Software confirmed a high-severity zero-day in the ShareFile Storage Zone Controller that forced an emergency shutdown order…

CrashStealer: The macOS Malware That Fooled Apple Itself
CrashStealer, a native C++ macOS infostealer, was distributed via a dropper signed and notarized by Apple, bypassing Gatekeeper checks…

AnyDesk 0Day ZDI-26-401: No Patch After 15 Months, DoS Remains Active
Trend Micro's Zero Day Initiative disclosed ZDI-26-401, a zero-day vulnerability in AnyDesk enabling local denial-of-service via NTFS…

BeyondTrust Patches Four Critical Flaws: The AI That Finds Bugs Risks Becoming the Weapon That Exploits Them
BeyondTrust released patches on July 7, 2026 for four vulnerabilities in Remote Support and Privileged Remote Access. Two carry CVSS 9…

Security AI Agents Turned Into Attack Vectors: The Report That Stops You Cold
The Friendly Fire report published by the AI Now Institute on July 8, 2026 proves that Anthropic's Claude Code and OpenAI's Codex CLI…

Ex-DigitalMint Negotiator Gets 70 Months for Feeding Clients to BlackCat
Angelo Martino was sentenced to 70 months in prison for acting as an insider for the BlackCat/ALPHV ransomware gang against five U.S.…

ATEN Unizon Exposes System Files Without Authentication: Directory Traversal
The ZDI-26-380 vulnerability in ATEN Unizon allows a remote attacker to read arbitrary files in the SYSTEM context. A patch is availab…

BeyondTrust Patches Four Critical Remote Support Flaws — Self-Hosted Servers Left Exposed for Months
July 7, 2026. BeyondTrust released fixes for four vulnerabilities in Remote Support and Privileged Remote Access, two rated CVSS 9.2.…

DeepSeek Generates Browser-Only Ransomware From a Prompt: Proof-of-Concept
Check Point Research analyzed a ransomware sample generated by DeepSeek that encrypts local files via the browser on Android, requirin…

Gitea Under Attack: The Docker Template That Opens the Door to Anyone
It took just 13 days from the advisory's publication for the first in-the-wild exploitation attempts against CVE-2026-20896, a critica…