News

CVE Vulnerability Alerts
AI-Assisted Linux Kernel CVE-2026-53264 Root Exploit Released
Lee Jia Jie used AI assistance to discover CVE-2026-53264, a Linux kernel use-after-free enabling local root escalation. A public exploit is now available.
CVE Vulnerability Alerts
Arista VeloCloud CVE-2026-16812 Exploited, CISA Orders Patch
Arista confirmed CVE-2026-16812, a CVSS 10.0 OS command injection in VeloCloud Orchestrator, is actively exploited. CISA ordered federal patches by July 30.
Cybersecurity
Dysphoria IoT Botnet Hits 200K Devices With Blockchain C2
Dysphoria, successor to the disrupted JackSkid botnet, infected 200,000 IoT devices worldwide and adopted Ethereum and Solana Name Service to anchor its C2.
Application Security
Public Exploit Released for vBulletin CVE-2026-61511 RCE
SSD Secure Disclosure released a weaponized unauthenticated RCE exploit for CVE-2026-61511 in vBulletin 6.x, exposing forum sites not yet on version 6.2.2.
Application Security
n8n Sandbox Escape GHSA-gv7g-jm28-cr3m Exposes Host OS Commands
n8n versions before 2.31.5 let authenticated users escape the expression sandbox via arrow functions and Reflect.get(), executing OS commands on the host.
Cybersecurity
Operation BlueDash Delivers RMM Tools via Fake Teams Lures
Operation BlueDash deploys Level RMM and ScreenConnect against enterprises through fake Microsoft Teams and Zoom pages linked to a Nigerian threat actor.
Cybersecurity
Cruciferra Crypter Combines BYOVD and Process Ghosting to Kill EDR
Cruciferra, a MaaS crypter active since fall 2025, bypasses EDR via BYOVD and Process Ghosting. TA4922, Silver Fox, and 11 malware families are linked to ...
Cybersecurity
Victims Sue Apple Over $1.8M Bitcoin Theft Via Fake Sparrow App
Three individuals sued Apple over a fake iOS Sparrow Wallet app that stole $1.8 million in Bitcoin by harvesting seed phrases. Apple was warned in ...
Cybersecurity
ShinyHunters Claims Ernst & Young Breach via Third-Party System
ShinyHunters posted Ernst & Young to its leak site, claiming a supply-chain attack on a third-party ticket system that exposed client tax and financial data.
Cybersecurity
Origin Energy Breach Exposes Data on 900,000 Australian Customers
Origin Energy disclosed a breach affecting 900,000 Australian customers, exposing names, bank account fragments, and addresses amid unconfirmed ransom claims.