
CISA Adds ColdFusion, Langflow, Two Joomla CVEs to KEV
CISA added four actively exploited flaws to KEV on July 7, requiring federal agencies to patch ColdFusion, Langflow, and two

CISA added four actively exploited flaws to KEV on July 7, requiring federal agencies to patch ColdFusion, Langflow, and two

An attacker spent approximately $4 million on BONK tokens to control 99.9% of votes in a low-turnout ballot and drain

Noma Security’s GitLost technique tricks GitHub Agentic Workflows into leaking private repository contents via public issue comments, with no patch

Sand Security found a one-click session isolation flaw in Writer AI letting attackers access any enterprise tenant’s private models, credentials,

BeyondTrust patched a CVSS 9.2 auth bypass in Remote Support and PRA for SaaS users months ago but withheld notice

Adobe ColdFusion CVE-2026-48282 (CVSS 10) moved from PoC release to confirmed in-the-wild exploitation in under two hours, according to KEVIntel

Proofpoint named UNK_MassTraction, a China-aligned group using Roundcube CVE-2024-42009 to steal credentials and 2FA tokens from university physics departments.

North Korea’s PolinRider campaign used stolen maintainer credentials to push malicious updates to 108 packages across npm, Packagist, Go, and

A zero-click flaw in Opera GX’s mod system let malicious websites silently install data-harvesting browser extensions on the gaming browser’s

SkillCloak obfuscation lets malicious AI coding agent skills bypass over 90 percent of static detection tools, risking source code and
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.