Application Security

Application Security
CISA Adds ColdFusion, Langflow, Two Joomla CVEs to KEV
CISA added four actively exploited flaws to KEV on July 7, requiring federal agencies to patch ColdFusion, Langflow, and two Joomla extensions by July 10.
BonkDAO Loses $20M After Attacker Buys Quorum with ~$4M
Application Security
BonkDAO Loses $20M After Attacker Buys Quorum with ~$4M
An attacker spent approximately $4 million on BONK tokens to control 99.9% of votes in a low-turnout ballot and drain $20 million from BonkDAO's Solana ...
Application Security
GitLost Prompt Injection Leaks Private GitHub Repos via Public Issues
Noma Security's GitLost technique tricks GitHub Agentic Workflows into leaking private repository contents via public issue comments, with no patch available.
Application Security
WriteOut Flaw Let Attackers Hijack Any Writer AI Enterprise Account
Sand Security found a one-click session isolation flaw in Writer AI letting attackers access any enterprise tenant's private models, credentials, and documents.
Application Security
BeyondTrust CVE-2026-40138 Auth Bypass Left Self-Hosted Users Exposed
BeyondTrust patched a CVSS 9.2 auth bypass in Remote Support and PRA for SaaS users months ago but withheld notice from self-hosted operators until July ...
Application Security
Adobe ColdFusion CVE-2026-48282 Exploited Within Hours of PoC Release
Adobe ColdFusion CVE-2026-48282 (CVSS 10) moved from PoC release to confirmed in-the-wild exploitation in under two hours, according to KEVIntel honeypot data.
Application Security
UNK_MassTraction Exploits Roundcube XSS to Hit US Physics Departments
Proofpoint named UNK_MassTraction, a China-aligned group using Roundcube CVE-2024-42009 to steal credentials and 2FA tokens from university physics departments.
Application Security
North Korea PolinRider Poisons 108 Packages via Compromised Accounts
North Korea's PolinRider campaign used stolen maintainer credentials to push malicious updates to 108 packages across npm, Packagist, Go, and Chrome Web Store.
Application Security
Opera GX Flaw Let Malicious Sites Silently Install Mods on 25M Users
A zero-click flaw in Opera GX's mod system let malicious websites silently install data-harvesting browser extensions on the gaming browser's 25 million users.
Application Security
SkillCloak Lets Malicious AI Agent Skills Evade 90% of Static Scanners
SkillCloak obfuscation lets malicious AI coding agent skills bypass over 90 percent of static detection tools, risking source code and credential theft.