Cyber Security
Qilin Affiliates Exploit PAN-OS CVE-2026-0257 GlobalProtect Bypass
JetBrains Patches TeamCity CVE-2026-63077 CVSS 9.8 RCE Flaw
AI-Assisted Linux Kernel CVE-2026-53264 Root Exploit Released
Arista VeloCloud CVE-2026-16812 Exploited, CISA Orders Patch
Dysphoria IoT Botnet Hits 200K Devices With Blockchain C2
Public Exploit Released for vBulletin CVE-2026-61511 RCE
n8n Sandbox Escape GHSA-gv7g-jm28-cr3m Exposes Host OS Commands
Operation BlueDash Delivers RMM Tools via Fake Teams Lures
Cruciferra Crypter Combines BYOVD and Process Ghosting to Kill EDR
Victims Sue Apple Over $1.8M Bitcoin Theft Via Fake Sparrow App
ShinyHunters Claims Ernst & Young Breach via Third-Party System
Origin Energy Breach Exposes Data on 900,000 Australian Customers
MedusaHVNC Hides Covert Browser Sessions in Windows Desktops
Fastjson CVE-2026-16723 Under Active Attack With No Patch
TELESHIM Backdoor Hits Middle East Governments via Telegram C2
DentaQuest Breach Affects 23.4 Million, PHI and SSNs Exposed
PEAR Ransomware Breach at MCBS Hits 1.26 Million Patients
SourTrade Malvertising Assembles Malware in Browser Memory
ShinyHunters Breach Data Fuels $2,000 Bitcoin Sextortion Wave
Steam ClickFix Campaign Installs SYSTEM-Level XMRig Miner
GitHub and PyPI Add Time-Based Defenses Against Supply Chain Poisoning
Rockwell Patches Four Arena Code Execution Flaws Across Sectors
Scattered Spider TfL Hackers Sentenced to Five and a Half Years
ClickLock macOS Stealer Uses App-Kill Loop to Coerce Passwords
Elastic Exposes TELEPUZ: C Malware Sold as MaaS via ClickFix Chain
Russian Threat Actor Uses Gemini CLI to Run Dental Clinic Botnet
DragonForce Posts Eighteen Victims Across Eight Countries in 48 Hours
Coca-Cola Files SEC 8-K After Ransomware Hits Fairlife Dairy
CISA Adds SharePoint CVE-2026-58644 to KEV After Zero-Day Confirmed
CISA Issues Sunday Patch Deadline for Fortinet FortiSandbox RCE Flaws
Cybersecurity
ENCFORGE Ransomware Targets PyTorch, SafeTensors Model Files
Sysdig documented ENCFORGE, a Go ransomware targeting 180 AI file formats including PyTorch, SafeTensors, and GGUF, deployed by the JADEPUFFER threat operator.
Application Security
Fastjson 1.x Zero-Day CVE-2026-16723 Under Active Exploit, No Patch
CVE-2026-16723, a CVSS 9.0 zero-day in Fastjson 1.x with no available patch, is actively exploited targeting financial services and healthcare backends.
Application Security
CISA Orders Patch for Langflow and WordPress wp2shell RCEs
CISA added Langflow CVE-2026-0770 and WordPress wp2shell CVE-2026-63030 to its KEV catalog, setting a July 24 Langflow deadline and August 4 WordPress deadline as mass ...
CVE Vulnerability Alerts
Qilin Affiliates Exploit PAN-OS CVE-2026-0257 GlobalProtect Bypass
Arctic Wolf documented Qilin affiliates exploiting CVE-2026-0257, a PAN-OS GlobalProtect auth bypass, to gain trusted VPN access for double-extortion attacks.
Application Security
JetBrains Patches TeamCity CVE-2026-63077 CVSS 9.8 RCE Flaw
JetBrains patched CVE-2026-63077, a CVSS 9.8 unauthenticated RCE in TeamCity CI/CD servers exploitable via the agent polling protocol without any credentials.
CVE Vulnerability Alerts
AI-Assisted Linux Kernel CVE-2026-53264 Root Exploit Released
Lee Jia Jie used AI assistance to discover CVE-2026-53264, a Linux kernel use-after-free enabling local root escalation. A public exploit is now available.
CVE Vulnerability Alerts
Arista VeloCloud CVE-2026-16812 Exploited, CISA Orders Patch
Arista confirmed CVE-2026-16812, a CVSS 10.0 OS command injection in VeloCloud Orchestrator, is actively exploited. CISA ordered federal patches by July 30.
Cybersecurity
Dysphoria IoT Botnet Hits 200K Devices With Blockchain C2
Dysphoria, successor to the disrupted JackSkid botnet, infected 200,000 IoT devices worldwide and adopted Ethereum and Solana Name Service to anchor its C2.
Application Security
Public Exploit Released for vBulletin CVE-2026-61511 RCE
SSD Secure Disclosure released a weaponized unauthenticated RCE exploit for CVE-2026-61511 in vBulletin 6.x, exposing forum sites not yet on version 6.2.2.
Application Security
n8n Sandbox Escape GHSA-gv7g-jm28-cr3m Exposes Host OS Commands
n8n versions before 2.31.5 let authenticated users escape the expression sandbox via arrow functions and Reflect.get(), executing OS commands on the host.
Cybersecurity
Operation BlueDash Delivers RMM Tools via Fake Teams Lures
Operation BlueDash deploys Level RMM and ScreenConnect against enterprises through fake Microsoft Teams and Zoom pages linked to a Nigerian threat actor.
Cybersecurity
Cruciferra Crypter Combines BYOVD and Process Ghosting to Kill EDR
Cruciferra, a MaaS crypter active since fall 2025, bypasses EDR via BYOVD and Process Ghosting. TA4922, Silver Fox, and 11 malware families are linked to ...
Cybersecurity
Victims Sue Apple Over $1.8M Bitcoin Theft Via Fake Sparrow App
Three individuals sued Apple over a fake iOS Sparrow Wallet app that stole $1.8 million in Bitcoin by harvesting seed phrases. Apple was warned in ...
Cybersecurity
ShinyHunters Claims Ernst & Young Breach via Third-Party System
ShinyHunters posted Ernst & Young to its leak site, claiming a supply-chain attack on a third-party ticket system that exposed client tax and financial data.
Cybersecurity
Origin Energy Breach Exposes Data on 900,000 Australian Customers
Origin Energy disclosed a breach affecting 900,000 Australian customers, exposing names, bank account fragments, and addresses amid unconfirmed ransom claims.
Cybersecurity
MedusaHVNC Hides Covert Browser Sessions in Windows Desktops
BlackFog exposed MedusaHVNC, a MaaS RAT that runs browsers on a hidden Windows virtual desktop to commit banking fraud without the victim's awareness.
Application Security
Fastjson CVE-2026-16723 Under Active Attack With No Patch
Fastjson CVE-2026-16723, a CVSS 9.0 Java RCE flaw with no patch, is under active attack against financial services, healthcare, computing, and retail targets.
Cybersecurity
TELESHIM Backdoor Hits Middle East Governments via Telegram C2
Zscaler ThreatLabz uncovered TELESHIM, MIXEDKEY, and BINDCLOAK — three new malware families an East Asia-linked APT used against Middle Eastern governments.
Cybersecurity
DentaQuest Breach Affects 23.4 Million, PHI and SSNs Exposed
DentaQuest's breach notification confirms up to 23.4 million Medicaid dental enrollees potentially affected, with SSNs and dental PHI stolen in a network hack.
Cybersecurity
PEAR Ransomware Breach at MCBS Hits 1.26 Million Patients
PEAR ransomware group claimed 3 TB stolen from MCBS, a medical billing firm whose breach exposed 1.26 million patients at seven healthcare organizations.
Cybersecurity
ENCFORGE Ransomware Targets PyTorch, SafeTensors Model Files
CVE Vulnerability Alerts
Qilin Affiliates Exploit PAN-OS CVE-2026-0257 GlobalProtect Bypass

TOP CYBERSECURITY HEADLINES

This Week’s Security Spotlight

Trending

Daily Briefing Newsletter

Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Featured Videos​

  • All
  • Application Security
  • Blog
  • CVE Vulnerability Alerts
  • Cybersecurity
  • Cybersecurity Newsletter
  • Data Security
  • Endpoint Security
  • Identity and Access Management
  • Information Security
  • Network Security
  • News
  • Phishing
  • Podcasts
  • Product Reviews
  • Ransomware
  • Ransomware Victims
  • Resources
  • Security Spotlight
  • Sponsored
  • Threat Actors
  • Threat Actors
  • Threat Detection Tools
Qilin Affiliates Exploit PAN-OS CVE-2026-0257 GlobalProtect Bypass
Arctic Wolf documented Qilin affiliates exploiting CVE-2026-0257, a PAN-OS GlobalProtect auth bypass, to gain trusted VPN access for double-extortion attacks.
JetBrains Patches TeamCity CVE-2026-63077 CVSS 9.8 RCE Flaw
JetBrains patched CVE-2026-63077, a CVSS 9.8 unauthenticated RCE in TeamCity CI/CD servers exploitable via the agent polling protocol without any credentials.
AI-Assisted Linux Kernel CVE-2026-53264 Root Exploit Released
Lee Jia Jie used AI assistance to discover CVE-2026-53264, a Linux kernel use-after-free enabling local root escalation. A public exploit is now available.
Arista VeloCloud CVE-2026-16812 Exploited, CISA Orders Patch
Arista confirmed CVE-2026-16812, a CVSS 10.0 OS command injection in VeloCloud Orchestrator, is actively exploited. CISA ordered federal patches by July 30.
Dysphoria IoT Botnet Hits 200K Devices With Blockchain C2
Dysphoria, successor to the disrupted JackSkid botnet, infected 200,000 IoT devices worldwide and adopted Ethereum and Solana Name Service to anchor its C2.
Public Exploit Released for vBulletin CVE-2026-61511 RCE
SSD Secure Disclosure released a weaponized unauthenticated RCE exploit for CVE-2026-61511 in vBulletin 6.x, exposing forum sites not yet on version 6.2.2.
n8n Sandbox Escape GHSA-gv7g-jm28-cr3m Exposes Host OS Commands
n8n versions before 2.31.5 let authenticated users escape the expression sandbox via arrow functions and Reflect.get(), executing OS commands on the host.
Operation BlueDash Delivers RMM Tools via Fake Teams Lures
Operation BlueDash deploys Level RMM and ScreenConnect against enterprises through fake Microsoft Teams and Zoom pages linked to a Nigerian threat actor.
Cruciferra Crypter Combines BYOVD and Process Ghosting to Kill EDR
Cruciferra, a MaaS crypter active since fall 2025, bypasses EDR via BYOVD and Process Ghosting. TA4922, Silver Fox, and 11 malware families are linked to ...
Victims Sue Apple Over $1.8M Bitcoin Theft Via Fake Sparrow App
Three individuals sued Apple over a fake iOS Sparrow Wallet app that stole $1.8 million in Bitcoin by harvesting seed phrases. Apple was warned in ...
ShinyHunters Claims Ernst & Young Breach via Third-Party System
ShinyHunters posted Ernst & Young to its leak site, claiming a supply-chain attack on a third-party ticket system that exposed client tax and financial data.
Origin Energy Breach Exposes Data on 900,000 Australian Customers
Origin Energy disclosed a breach affecting 900,000 Australian customers, exposing names, bank account fragments, and addresses amid unconfirmed ransom claims.
MedusaHVNC Hides Covert Browser Sessions in Windows Desktops
BlackFog exposed MedusaHVNC, a MaaS RAT that runs browsers on a hidden Windows virtual desktop to commit banking fraud without the victim's awareness.
Fastjson CVE-2026-16723 Under Active Attack With No Patch
Fastjson CVE-2026-16723, a CVSS 9.0 Java RCE flaw with no patch, is under active attack against financial services, healthcare, computing, and retail targets.
TELESHIM Backdoor Hits Middle East Governments via Telegram C2
Zscaler ThreatLabz uncovered TELESHIM, MIXEDKEY, and BINDCLOAK — three new malware families an East Asia-linked APT used against Middle Eastern governments.
DentaQuest Breach Affects 23.4 Million, PHI and SSNs Exposed
DentaQuest's breach notification confirms up to 23.4 million Medicaid dental enrollees potentially affected, with SSNs and dental PHI stolen in a network hack.
PEAR Ransomware Breach at MCBS Hits 1.26 Million Patients
PEAR ransomware group claimed 3 TB stolen from MCBS, a medical billing firm whose breach exposed 1.26 million patients at seven healthcare organizations.
SourTrade Malvertising Assembles Malware in Browser Memory
SourTrade malvertising downloads encrypted fragments and assembles a Windows executable in browser memory, evading file-based detection across 12 countries.
ShinyHunters Breach Data Fuels $2,000 Bitcoin Sextortion Wave
Attackers are sending $2,000 Bitcoin sextortion emails that cite specific ShinyHunters-breached companies to make false surveillance threats appear credible.
Steam ClickFix Campaign Installs SYSTEM-Level XMRig Miner
Attackers target Steam discussion forums with ClickFix social engineering, tricking players into running PowerShell that installs a SYSTEM-level XMRig miner.