Network Security

Cybersecurity
24,650 Internet-Exposed Server BMCs Leak Password Hashes Before Login
Researchers found 24,650 internet-exposed BMCs that disclose IPMI password hashes before login, enabling offline hash cracking and full server takeover.
Cybersecurity
CyberAv3ngers Suspected in OT Attacks on 30+ Minnesota Water Utilities
More than 30 Minnesota water utilities were disrupted in a coordinated OT attack; Tenable suspects Iran-linked CyberAv3ngers based on targeting patterns.
Cybersecurity
CubePilot Drone Controller Developer Hit by DNS Hijacking
Attackers seized CubePilot's domain DNS settings and obtained TLS certificates for all subdomains, potentially capturing credentials during the attack window.
CVE Vulnerability Alerts
Qilin Affiliates Exploit PAN-OS CVE-2026-0257 GlobalProtect Bypass
Arctic Wolf documented Qilin affiliates exploiting CVE-2026-0257, a PAN-OS GlobalProtect auth bypass, to gain trusted VPN access for double-extortion attacks.
CVE Vulnerability Alerts
Arista VeloCloud CVE-2026-16812 Exploited, CISA Orders Patch
Arista confirmed CVE-2026-16812, a CVSS 10.0 OS command injection in VeloCloud Orchestrator, is actively exploited. CISA ordered federal patches by July 30.
Cybersecurity
Dysphoria IoT Botnet Hits 200K Devices With Blockchain C2
Dysphoria, successor to the disrupted JackSkid botnet, infected 200,000 IoT devices worldwide and adopted Ethereum and Solana Name Service to anchor its C2.
Cybersecurity
TELESHIM Backdoor Hits Middle East Governments via Telegram C2
Zscaler ThreatLabz uncovered TELESHIM, MIXEDKEY, and BINDCLOAK — three new malware families an East Asia-linked APT used against Middle Eastern governments.
CVE Vulnerability Alerts
CISA Issues Sunday Patch Deadline for Fortinet FortiSandbox RCE Flaws
CISA added CVE-2026-25089 and CVE-2026-39808 in Fortinet FortiSandbox to KEV, ordering FCEB agencies to patch by July 19 amid confirmed active exploitation.
CVE Vulnerability Alerts
F5 Patches CVE-2026-42533 Heap Buffer Overflow in NGINX Plus
F5 released an out-of-band patch for CVE-2026-42533, a CVSS 9.2 heap buffer overflow in NGINX Plus and Open Source requiring no authentication to exploit.
Cybersecurity
Unit 42 Exposes TuxBot v3 Iranian-Linked IoT Botnet With DDoS-for-Hire
Palo Alto Networks Unit 42 exposed TuxBot v3, an Iranian-linked IoT botnet targeting 17 CPU architectures with DDoS-for-hire capabilities and AI-generated code.