News

CVE Vulnerability Alerts
VMware Avi Load Balancer Patches Critical Control Plane Auth Bypass
Broadcom patched seven VMware Avi vulnerabilities, including a critical authentication bypass in the control plane. No active exploitation has been confirmed.
Cybersecurity
Jalisco and OmegaLord PhaaS Kits Beat M365 MFA Using OAuth Tricks
ReliaQuest disclosed Jalisco, which regenerates OAuth tokens in real time to beat Microsoft's 15-minute window, and OmegaLord, which harvests MFA phone numbers.
Cybersecurity
White House Launches Gold Eagle AI Vulnerability Routing Program
White House launched Gold Eagle, linking CISA, open source maintainers, and critical infrastructure operators through AI vulnerability triage under EO 14409.
Cybersecurity
Nine-Nation Advisory Flags FSB Center 16 Router Attacks
Cybersecurity agencies from nine countries issued a joint advisory on FSB Center 16 router attacks targeting energy, healthcare, and defense sectors globally.
Cybersecurity
Open Server Exposes Three Concurrent Evilginx M365 Operations
French security firm Lexfo discovered three Evilginx M365 phishing campaigns after attackers left a Python HTTP server with directory listing exposed.
Application Security
CISA Adds Two CVSS 10.0 Joomla Extension Zero-Days to KEV
CISA added CVE-2026-48939 and CVE-2026-56291 to KEV with a same-day federal deadline after both Joomla extension zero-days were exploited before disclosure.
Application Security
Progress Orders ShareFile SZC Server Shutdown Over Security Threat
Progress Software ordered ShareFile Storage Zone Controller customers to shut down internet-facing servers amid an undisclosed security threat investigation.
Cybersecurity
RedHook Android RAT Gains Shell Access via Wireless ADB Loopback
Group-IB analyzed a new RedHook Android RAT variant that gains shell-level access by turning the device into its own ADB client via loopback, without rooting.
Cybersecurity
Ryuk Ransomware Broker Pleads Guilty in $15M Bitcoin Theft Case
Armenian national Karen Vardanyan pleaded guilty to enabling Ryuk ransomware attacks on U.S. organizations that yielded about 1,610 Bitcoin for the gang.
Application Security
Ghostcommit PNG Attack Tricks AI Code Reviewers into Leaking .env
UMKC researchers demonstrated Ghostcommit, a PNG-based prompt injection attack that tricks AI code reviewers into exfiltrating .env secrets as code constants.