Cyber Security
Application Security
Amazon Ties Debug, Chalk npm Hijacks to North Korean Group
Andrew Doyle
July 30, 2026
Amazon attributed debug and chalk npm hijack to North Korea's Sapphire Sleet, elevating a supply chain attack previously seen as financially motivated.
CVE Vulnerability Alerts
Cisco Secure FMC Zero-Day Added to CISA KEV Under Active Attack
Mitchell Langley
July 30, 2026
CISA added the Cisco FMC zero-day CVE-2026-20316 to the KEV after active exploitation began. Cisco is also patching a critical FMC auth bypass rated CVSS ...
Application Security
Critical Rails Active Storage Flaw Lets Attackers Read Server Files
Andrew Doyle
July 30, 2026
The Rails framework patched CVE-2026-66066, a critical Active Storage flaw letting unauthenticated attackers read server files via crafted image uploads.
Application Security
CVSS 10.0 RufRoot Flaw Lets Attackers Hijack AI Agent Systems
Andrew Doyle
July 30, 2026
Disclosed CVE-2026-59726 is a CVSS 10.0 Ruflo MCP flaw granting unauthenticated RCE on AI agent servers, with patch-resistant persistence in agent memory.
Application Security
Russian Group Laundry Bear Exploited Exchange Zero-Day in OWA Attack
Andrew Doyle
July 30, 2026
Russian state-sponsored group Laundry Bear used a half-click Exchange zero-day to deploy the OWAReaper backdoor with credential-rotation-proof persistence.
Cybersecurity
Health-ISAC Warns Healthcare Sector of Rising ShinyHunters Attacks
Andrew Doyle
July 30, 2026
Health-ISAC warned of increased ShinyHunters attacks on healthcare using vishing to compromise SSO accounts and steal data from connected cloud platforms.
Cybersecurity
Nine-Year Fraud Campaign Cloned Russian Company Sites for Payments
Mitchell Langley
July 30, 2026
Russian cybersecurity firm F6 disclosed a nine-year fraud campaign cloning industrial company websites to steal advance payments from international firms.
Application Security
OpenAI’s Rogue AI Used JFrog Zero-Days to Breach Hugging Face
Mitchell Langley
July 29, 2026
A new postmortem reveals OpenAI's rogue AI model exploited JFrog Artifactory zero-days to escape its sandbox and breach Hugging Face and four other services.
CVE Vulnerability Alerts
Check Point SmartConsole Auth Bypass PoC Elevates Active Exploit Risk
Mitchell Langley
July 29, 2026
Rapid7 released a public PoC for CVE-2026-16232, a CVSS 9.3 Check Point SmartConsole authentication bypass already under active exploitation in the wild.
Application Security
Firefox JIT Flaw CVE-2026-10702 Exposes Tor Browser to Deanonymization
Gabby Lee
July 29, 2026
Nebula Security published a full browser-to-kernel exploit chain for Firefox CVE-2026-10702, a JIT flaw that exposes Tor Browser users to deanonymization.
Application Security
Gitea CVE-2026-60004 Gives Repo Writers Shell Access via Git Hooks
Gabby Lee
July 29, 2026
CVE-2026-60004 in Gitea 1.17–1.27.0 lets a repository writer execute arbitrary shell commands as the Gitea service account via malicious patch content.
CVE Vulnerability Alerts
OpenWrt CVE-2026-53921 Lets Attackers Root Routers via DHCPv6 Overflow
Gabby Lee
July 29, 2026
CVE-2026-53921, a CVSS 9.8 stack buffer overflow in OpenWrt's DHCPv6 server, lets unauthenticated attackers execute arbitrary code as root on affected routers.
Cybersecurity
Nimbus Manticore Deploys NightLedger Backdoor Across Three Regions
Mitchell Langley
July 29, 2026
Iran-linked Nimbus Manticore deployed the new NightLedger backdoor and WebSocket tunnelers against targets in the Middle East, Africa, and South Asia.
Cybersecurity
Tengu Botnet Reboots Devices via Hardware Watchdog to Evade Removal
Mitchell Langley
July 29, 2026
Tengu, a new Mirai-derived Linux IoT botnet, triggers device reboots via hardware watchdog when defenders kill its process, supporting 25 DDoS methods.
Cybersecurity
24,650 Internet-Exposed Server BMCs Leak Password Hashes Before Login
Mitchell Langley
July 29, 2026
Researchers found 24,650 internet-exposed BMCs that disclose IPMI password hashes before login, enabling offline hash cracking and full server takeover.
Cybersecurity
CyberAv3ngers Suspected in OT Attacks on 30+ Minnesota Water Utilities
Andrew Doyle
July 29, 2026
More than 30 Minnesota water utilities were disrupted in a coordinated OT attack; Tenable suspects Iran-linked CyberAv3ngers based on targeting patterns.
Application Security
VMware ESXi VM Escape CVE-2026-47876 Patched Alongside Four More Flaws
Gabby Lee
July 29, 2026
Broadcom patched CVE-2026-47876, a critical ESXi VM escape via VMXNET3, plus two critical vCenter Server flaws, with no confirmed in-the-wild exploitation.
Cybersecurity
CubePilot Drone Controller Developer Hit by DNS Hijacking
Gabby Lee
July 29, 2026
Attackers seized CubePilot's domain DNS settings and obtained TLS certificates for all subdomains, potentially capturing credentials during the attack window.
Cybersecurity
Claude Mythos Cracks HAWK-256 Lattice Problem, Speeds AES-128 Attack
Gabby Lee
July 29, 2026
Anthropic's Claude Mythos derived a HAWK-256 key-recovery attack and 200–800x speedup for a seven-round AES-128 attack, with no impact on deployed systems.
Cybersecurity
Flying Eagle Android RAT Leaks on Telegram, 170 C2 Servers Active
Andrew Doyle
July 29, 2026
Flying Eagle Android RAT source code is on Telegram; researchers traced matching panels to 170 servers targeting Chinese users via a fake government app.
Application Security
Amazon Ties Debug, Chalk npm Hijacks to North Korean Group
Andrew Doyle
July 30, 2026
Cybersecurity
24,650 Internet-Exposed Server BMCs Leak Password Hashes Before Login
Mitchell Langley
July 29, 2026
CVE Vulnerability Alerts
Qilin Affiliates Exploit PAN-OS CVE-2026-0257 GlobalProtect Bypass
Mitchell Langley
July 28, 2026
TOP CYBERSECURITY HEADLINES
Application Security
CVSS 10.0 RufRoot Flaw Lets Attackers Hijack AI Agent Systems
Application Security
Russian Group Laundry Bear Exploited Exchange Zero-Day in OWA Attack
This Week’s Security Spotlight
CVE Vulnerability Alerts
Cisco Secure FMC Zero-Day Added to CISA KEV Under Active Attack
Mitchell Langley
July 30, 2026
Application Security
VMware ESXi VM Escape CVE-2026-47876 Patched Alongside Four More Flaws
Gabby Lee
July 29, 2026
Cybersecurity
Origin Energy Breach Exposes Data on 900,000 Australian Customers
Mitchell Langley
July 28, 2026
Cybersecurity
DentaQuest Breach Affects 23.4 Million, PHI and SSNs Exposed
Mitchell Langley
July 27, 2026
Trending
Daily Briefing Newsletter
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
Featured Videos
Podcasts
Cyber Security News
- All
- Application Security
- Blog
- CVE Vulnerability Alerts
- Cybersecurity
- Cybersecurity Newsletter
- Data Security
- Endpoint Security
- Identity and Access Management
- Information Security
- Network Security
- News
- Phishing
- Podcasts
- Product Reviews
- Ransomware
- Ransomware Victims
- Resources
- Security Spotlight
- Sponsored
- Threat Actors
- Threat Actors
- Threat Detection Tools
CVSS 10.0 RufRoot Flaw Lets Attackers Hijack AI Agent Systems
July 30, 2026
Disclosed CVE-2026-59726 is a CVSS 10.0 Ruflo MCP flaw granting unauthenticated RCE on AI agent servers, with patch-resistant persistence in agent memory.
Russian Group Laundry Bear Exploited Exchange Zero-Day in OWA Attack
July 30, 2026
Russian state-sponsored group Laundry Bear used a half-click Exchange zero-day to deploy the OWAReaper backdoor with credential-rotation-proof persistence.
Health-ISAC Warns Healthcare Sector of Rising ShinyHunters Attacks
July 30, 2026
Health-ISAC warned of increased ShinyHunters attacks on healthcare using vishing to compromise SSO accounts and steal data from connected cloud platforms.
Nine-Year Fraud Campaign Cloned Russian Company Sites for Payments
July 30, 2026
Russian cybersecurity firm F6 disclosed a nine-year fraud campaign cloning industrial company websites to steal advance payments from international firms.
OpenAI’s Rogue AI Used JFrog Zero-Days to Breach Hugging Face
July 29, 2026
A new postmortem reveals OpenAI's rogue AI model exploited JFrog Artifactory zero-days to escape its sandbox and breach Hugging Face and four other services.
Check Point SmartConsole Auth Bypass PoC Elevates Active Exploit Risk
July 29, 2026
Rapid7 released a public PoC for CVE-2026-16232, a CVSS 9.3 Check Point SmartConsole authentication bypass already under active exploitation in the wild.
Firefox JIT Flaw CVE-2026-10702 Exposes Tor Browser to Deanonymization
July 29, 2026
Nebula Security published a full browser-to-kernel exploit chain for Firefox CVE-2026-10702, a JIT flaw that exposes Tor Browser users to deanonymization.
Gitea CVE-2026-60004 Gives Repo Writers Shell Access via Git Hooks
July 29, 2026
CVE-2026-60004 in Gitea 1.17–1.27.0 lets a repository writer execute arbitrary shell commands as the Gitea service account via malicious patch content.
OpenWrt CVE-2026-53921 Lets Attackers Root Routers via DHCPv6 Overflow
July 29, 2026
CVE-2026-53921, a CVSS 9.8 stack buffer overflow in OpenWrt's DHCPv6 server, lets unauthenticated attackers execute arbitrary code as root on affected routers.
Nimbus Manticore Deploys NightLedger Backdoor Across Three Regions
July 29, 2026
Iran-linked Nimbus Manticore deployed the new NightLedger backdoor and WebSocket tunnelers against targets in the Middle East, Africa, and South Asia.
Tengu Botnet Reboots Devices via Hardware Watchdog to Evade Removal
July 29, 2026
Tengu, a new Mirai-derived Linux IoT botnet, triggers device reboots via hardware watchdog when defenders kill its process, supporting 25 DDoS methods.
24,650 Internet-Exposed Server BMCs Leak Password Hashes Before Login
July 29, 2026
Researchers found 24,650 internet-exposed BMCs that disclose IPMI password hashes before login, enabling offline hash cracking and full server takeover.
CyberAv3ngers Suspected in OT Attacks on 30+ Minnesota Water Utilities
July 29, 2026
More than 30 Minnesota water utilities were disrupted in a coordinated OT attack; Tenable suspects Iran-linked CyberAv3ngers based on targeting patterns.
VMware ESXi VM Escape CVE-2026-47876 Patched Alongside Four More Flaws
July 29, 2026
Broadcom patched CVE-2026-47876, a critical ESXi VM escape via VMXNET3, plus two critical vCenter Server flaws, with no confirmed in-the-wild exploitation.
CubePilot Drone Controller Developer Hit by DNS Hijacking
July 29, 2026
Attackers seized CubePilot's domain DNS settings and obtained TLS certificates for all subdomains, potentially capturing credentials during the attack window.
Claude Mythos Cracks HAWK-256 Lattice Problem, Speeds AES-128 Attack
July 29, 2026
Anthropic's Claude Mythos derived a HAWK-256 key-recovery attack and 200–800x speedup for a seven-round AES-128 attack, with no impact on deployed systems.
Flying Eagle Android RAT Leaks on Telegram, 170 C2 Servers Active
July 29, 2026
Flying Eagle Android RAT source code is on Telegram; researchers traced matching panels to 170 servers targeting Chinese users via a fake government app.
@joyfill npm Beta Packages Deploy DEV#POPPER RAT on Import
July 29, 2026
Two @joyfill npm beta packages were compromised to deliver DEV#POPPER RAT on import, risking credential theft and persistent access on developers' machines.
ENCFORGE Ransomware Targets PyTorch, SafeTensors Model Files
July 28, 2026
Sysdig documented ENCFORGE, a Go ransomware targeting 180 AI file formats including PyTorch, SafeTensors, and GGUF, deployed by the JADEPUFFER threat operator.
Fastjson 1.x Zero-Day CVE-2026-16723 Under Active Exploit, No Patch
July 28, 2026
CVE-2026-16723, a CVSS 9.0 zero-day in Fastjson 1.x with no available patch, is actively exploited targeting financial services and healthcare backends.
























