Vulnerabilities
Curated coverage and analysis in this editorial area.

Arch Linux Halts AUR Package Adoptions: Third Supply-Chain Attack in Two Months
On July 30, 2026, Arch Linux suspended package adoptions in the Arch User Repository to stop an active supply-chain campaign. It is th…

Exploitarium Turns Zero-Day Disclosure into Permanent Infrastructure
The Exploitarium repository has published 204 zero-day exploits for open-source projects without vendor notification. CVE-2026-55200 a…

Fortinet CVE-2026-24858: Active Exploitation, SSO Bypass, CVSS 9.8
Fortinet has patched CVE-2026-24858, a critical authentication bypass with a CVSS 9.8 score that is under active exploitation. CISA ha…

AI Agent Prompt Injection: SOCs Are Blind to Language as a Weapon
Gartner and OWASP confirm prompt injection as the top AI threat for 2026. Traditional SOCs cannot detect attacks that weaponize natura…

GhostLock: The Exploit That Unlocks Linux in 5 Seconds — 15 Years in the Shadows
On July 7, 2026, Nebula Security disclosed GhostLock, a working exploit for CVE-2026-43499, a use-after-free in the Linux kernel's fut…

7-Zip XZ Decoder RCE: Silent Patch Leaves Users Exposed
CVE-2026-14266 enables code execution via a crafted XZ archive. The fix landed in 7-Zip 26.02 on June 25, but the lack of automatic up…

Intel and AMD Patch 70 Flaws: Two Critical CVSS 9.3 and 9.2 Bugs in GPU Drivers
On May 13, 2026, Intel and AMD released 28 advisories covering 69 vulnerabilities. Two critical flaws hit chip software drivers, not t…

PNLD Data Breach: UK Police Contacts Published on Dark Web July 26
The Police National Legal Database confirms the exfiltration of names, organizations, and work emails of officers, government staff, a…

Pass-ta-key Exposes the Gap Between FIDO2 Cryptography and Windows Implementation
Unit 42 reveals three post-compromise techniques that bypass PIN and biometrics on Chrome for Windows. Passkeys resist phishing, not m…

Data-Theft Campaign Targets Windchill and FlexPLM via CVE-2026-12569 RCE
A data-theft extortion campaign is exploiting CVE-2026-12569, a critical unauthenticated RCE in PTC Windchill and FlexPLM, to deploy h…

Iranian APTs Hit Rockwell PLCs: Over 30 Minnesota Water Systems Compromised
Iran-affiliated APT actors are exploiting CVE-2021-22681 in Rockwell, Schneider, and Siemens PLCs. The joint CISA-FBI advisory updated…

Cisco Confirms FMC Zero-Day: Static Credentials Under Attack, CISA Sets August 1 Deadline
Cisco confirms active exploitation of CVE-2026-20316 in Secure Firewall Management Center. CISA adds the flaw to its KEV catalog, mand…