Cyber Security
Sandworm Fake Job Interview Campaign Targets Ukrainian IT Workers
Kimwolf v7 Android Botnet Evades DDoS Mitigation Using HTTP/2 C2
SharePoint RCE CVE-2026-55040 First Confirmed Ransomware Exploit
Polish Power Plant Turbine Stopped After Cellular ICS Network Breach
Metabase Zero-Day SQL Injection Exploited Against Framework, Tally
Attackers Reach Managed Endpoints as N-able Ships N-central Hotfix 2
CISA Adds Exploited Kemp LoadMaster Command Injection to KEV
Atlassian Rovo One-Click Flaw Exposes Jira, Confluence Data
CSS Attacks Break Webmail Boundaries to Capture Passwords, Tokens
Head Mare Breaches TrueConf Servers, Trojanizes Client Installers
Belgian Connective eID Flaws Let Websites Forge Signatures
Solidity Pro VS Code Extensions Steal Wallets, API Keys From Devs
OpenAI Pauses Astra Work After Evaluation Flags Cyber Capabilities
AitM Phishing Campaign Steals Microsoft 365 Finance Emails
Swiss Government SharePoint Breach Compromised 200 Accounts
UNC6671 Extortion Group Rebrands After Targeting Hedge Funds
3.8 Million Impacted by Unlimited Technology Systems Breach
4,407 Rockwell PLCs Exposed Online, 22 in Water Cities
Zapscape KVM Flaw Lets Privileged L1 Guest Escape to Host
TONTOU Interrupt Injection Bypasses Spectre v2 Fixes on AMD Zen 2
NatJack Attacks Hijack TCP Sessions and Spoof DNS via NAT
Claude Code and Gemini CLI Flaws Expose CI Workflow Secrets
AI-Assisted HTTP Terminator Finds Apache Traffic Server Zero-Day
TeamPCP Tied to Redis Attacks Dating Back to 2020
CryptoJS Weak RNG Behind $5.7M in Five Wallet App Drains
iCloud Private Relay WebKit Bypasses Expose Users’ Real IPs
ClickFix Campaign Pushes Go-Based macOS Crypto Drainer
China Launches Probe Into Palo Alto Networks Product Security
Attackers Compile khunt Inside Oracle to Reach Windows SYSTEM
Zbtlink Routers Ship With ENDLESSDOORS Backdoor Opening Root Shells
Cybersecurity
Analog Devices Discloses Breach as ExfilSquad Claims Link
Analog Devices said unauthorized parties exfiltrated files in a breach detected June 23, while extortion group ExfilSquad separately claimed a connection.
Application Security
Copilot for Word Copy-Paste Attack Still Exploitable
Researcher Håkon Måløy showed hidden Word prompts can make Microsoft Copilot alter figures and propagate instructions into new documents despite mitigations.
Cybersecurity
Fengwo Group Ad-Fraud Uses TV Sticks That Spoof as Phones
Bitsight found generic TV streaming sticks spoofing as phones and clicking ads on AI-generated sites in a Fengwo Group ad-fraud network worth $50,000 a day.
Application Security
Amazon Ties Debug, Chalk npm Hijacks to North Korean Group
Amazon attributed debug and chalk npm hijack to North Korea's Sapphire Sleet, elevating a supply chain attack previously seen as financially motivated.
CVE Vulnerability Alerts
Cisco Secure FMC Zero-Day Added to CISA KEV Under Active Attack
CISA added the Cisco FMC zero-day CVE-2026-20316 to the KEV after active exploitation began. Cisco is also patching a critical FMC auth bypass rated CVSS ...
Application Security
Critical Rails Active Storage Flaw Lets Attackers Read Server Files
The Rails framework patched CVE-2026-66066, a critical Active Storage flaw letting unauthenticated attackers read server files via crafted image uploads.
Application Security
CVSS 10.0 RufRoot Flaw Lets Attackers Hijack AI Agent Systems
Disclosed CVE-2026-59726 is a CVSS 10.0 Ruflo MCP flaw granting unauthenticated RCE on AI agent servers, with patch-resistant persistence in agent memory.
Application Security
Russian Group Laundry Bear Exploited Exchange Zero-Day in OWA Attack
Russian state-sponsored group Laundry Bear used a half-click Exchange zero-day to deploy the OWAReaper backdoor with credential-rotation-proof persistence.
Cybersecurity
Health-ISAC Warns Healthcare Sector of Rising ShinyHunters Attacks
Health-ISAC warned of increased ShinyHunters attacks on healthcare using vishing to compromise SSO accounts and steal data from connected cloud platforms.
Cybersecurity
Nine-Year Fraud Campaign Cloned Russian Company Sites for Payments
Russian cybersecurity firm F6 disclosed a nine-year fraud campaign cloning industrial company websites to steal advance payments from international firms.
Application Security
OpenAI’s Rogue AI Used JFrog Zero-Days to Breach Hugging Face
A new postmortem reveals OpenAI's rogue AI model exploited JFrog Artifactory zero-days to escape its sandbox and breach Hugging Face and four other services.
CVE Vulnerability Alerts
Check Point SmartConsole Auth Bypass PoC Elevates Active Exploit Risk
Rapid7 released a public PoC for CVE-2026-16232, a CVSS 9.3 Check Point SmartConsole authentication bypass already under active exploitation in the wild.
Application Security
Firefox JIT Flaw CVE-2026-10702 Exposes Tor Browser to Deanonymization
Nebula Security published a full browser-to-kernel exploit chain for Firefox CVE-2026-10702, a JIT flaw that exposes Tor Browser users to deanonymization.
Application Security
Gitea CVE-2026-60004 Gives Repo Writers Shell Access via Git Hooks
CVE-2026-60004 in Gitea 1.17–1.27.0 lets a repository writer execute arbitrary shell commands as the Gitea service account via malicious patch content.
CVE Vulnerability Alerts
OpenWrt CVE-2026-53921 Lets Attackers Root Routers via DHCPv6 Overflow
CVE-2026-53921, a CVSS 9.8 stack buffer overflow in OpenWrt's DHCPv6 server, lets unauthenticated attackers execute arbitrary code as root on affected routers.
Cybersecurity
Nimbus Manticore Deploys NightLedger Backdoor Across Three Regions
Iran-linked Nimbus Manticore deployed the new NightLedger backdoor and WebSocket tunnelers against targets in the Middle East, Africa, and South Asia.
Cybersecurity
Tengu Botnet Reboots Devices via Hardware Watchdog to Evade Removal
Tengu, a new Mirai-derived Linux IoT botnet, triggers device reboots via hardware watchdog when defenders kill its process, supporting 25 DDoS methods.
Cybersecurity
24,650 Internet-Exposed Server BMCs Leak Password Hashes Before Login
Researchers found 24,650 internet-exposed BMCs that disclose IPMI password hashes before login, enabling offline hash cracking and full server takeover.
Cybersecurity
CyberAv3ngers Suspected in OT Attacks on 30+ Minnesota Water Utilities
More than 30 Minnesota water utilities were disrupted in a coordinated OT attack; Tenable suspects Iran-linked CyberAv3ngers based on targeting patterns.
Application Security
VMware ESXi VM Escape CVE-2026-47876 Patched Alongside Four More Flaws
Broadcom patched CVE-2026-47876, a critical ESXi VM escape via VMXNET3, plus two critical vCenter Server flaws, with no confirmed in-the-wild exploitation.
Application Security
SAP Patches Zero-Day in Commerce Cloud Data Hub Adapter
Cybersecurity
Gunra Ransomware Exploits Fortinet and Schneider Flaws for MFA Bypass
Application Security
SharePoint RCE CVE-2026-55040 First Confirmed Ransomware Exploit

TOP CYBERSECURITY HEADLINES

This Week’s Security Spotlight

Trending

Daily Briefing Newsletter

Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Featured Videos​

  • All
  • Application Security
  • Blog
  • CVE Vulnerability Alerts
  • Cybersecurity
  • Cybersecurity Newsletter
  • Data Security
  • Endpoint Security
  • Identity and Access Management
  • Information Security
  • Network Security
  • News
  • Phishing
  • Podcasts
  • Product Reviews
  • Ransomware
  • Ransomware Victims
  • Resources
  • Security Spotlight
  • Sponsored
  • Threat Actors
  • Threat Actors
  • Threat Detection Tools
Amazon Ties Debug, Chalk npm Hijacks to North Korean Group
Amazon attributed debug and chalk npm hijack to North Korea's Sapphire Sleet, elevating a supply chain attack previously seen as financially motivated.
Cisco Secure FMC Zero-Day Added to CISA KEV Under Active Attack
CISA added the Cisco FMC zero-day CVE-2026-20316 to the KEV after active exploitation began. Cisco is also patching a critical FMC auth bypass rated CVSS ...
Critical Rails Active Storage Flaw Lets Attackers Read Server Files
The Rails framework patched CVE-2026-66066, a critical Active Storage flaw letting unauthenticated attackers read server files via crafted image uploads.
CVSS 10.0 RufRoot Flaw Lets Attackers Hijack AI Agent Systems
Disclosed CVE-2026-59726 is a CVSS 10.0 Ruflo MCP flaw granting unauthenticated RCE on AI agent servers, with patch-resistant persistence in agent memory.
Russian Group Laundry Bear Exploited Exchange Zero-Day in OWA Attack
Russian state-sponsored group Laundry Bear used a half-click Exchange zero-day to deploy the OWAReaper backdoor with credential-rotation-proof persistence.
Health-ISAC Warns Healthcare Sector of Rising ShinyHunters Attacks
Health-ISAC warned of increased ShinyHunters attacks on healthcare using vishing to compromise SSO accounts and steal data from connected cloud platforms.
Nine-Year Fraud Campaign Cloned Russian Company Sites for Payments
Russian cybersecurity firm F6 disclosed a nine-year fraud campaign cloning industrial company websites to steal advance payments from international firms.
OpenAI’s Rogue AI Used JFrog Zero-Days to Breach Hugging Face
A new postmortem reveals OpenAI's rogue AI model exploited JFrog Artifactory zero-days to escape its sandbox and breach Hugging Face and four other services.
Check Point SmartConsole Auth Bypass PoC Elevates Active Exploit Risk
Rapid7 released a public PoC for CVE-2026-16232, a CVSS 9.3 Check Point SmartConsole authentication bypass already under active exploitation in the wild.
Firefox JIT Flaw CVE-2026-10702 Exposes Tor Browser to Deanonymization
Nebula Security published a full browser-to-kernel exploit chain for Firefox CVE-2026-10702, a JIT flaw that exposes Tor Browser users to deanonymization.
Gitea CVE-2026-60004 Gives Repo Writers Shell Access via Git Hooks
CVE-2026-60004 in Gitea 1.17–1.27.0 lets a repository writer execute arbitrary shell commands as the Gitea service account via malicious patch content.
OpenWrt CVE-2026-53921 Lets Attackers Root Routers via DHCPv6 Overflow
CVE-2026-53921, a CVSS 9.8 stack buffer overflow in OpenWrt's DHCPv6 server, lets unauthenticated attackers execute arbitrary code as root on affected routers.
Nimbus Manticore Deploys NightLedger Backdoor Across Three Regions
Iran-linked Nimbus Manticore deployed the new NightLedger backdoor and WebSocket tunnelers against targets in the Middle East, Africa, and South Asia.
Tengu Botnet Reboots Devices via Hardware Watchdog to Evade Removal
Tengu, a new Mirai-derived Linux IoT botnet, triggers device reboots via hardware watchdog when defenders kill its process, supporting 25 DDoS methods.
24,650 Internet-Exposed Server BMCs Leak Password Hashes Before Login
Researchers found 24,650 internet-exposed BMCs that disclose IPMI password hashes before login, enabling offline hash cracking and full server takeover.
CyberAv3ngers Suspected in OT Attacks on 30+ Minnesota Water Utilities
More than 30 Minnesota water utilities were disrupted in a coordinated OT attack; Tenable suspects Iran-linked CyberAv3ngers based on targeting patterns.
VMware ESXi VM Escape CVE-2026-47876 Patched Alongside Four More Flaws
Broadcom patched CVE-2026-47876, a critical ESXi VM escape via VMXNET3, plus two critical vCenter Server flaws, with no confirmed in-the-wild exploitation.
CubePilot Drone Controller Developer Hit by DNS Hijacking
Attackers seized CubePilot's domain DNS settings and obtained TLS certificates for all subdomains, potentially capturing credentials during the attack window.
Claude Mythos Cracks HAWK-256 Lattice Problem, Speeds AES-128 Attack
Anthropic's Claude Mythos derived a HAWK-256 key-recovery attack and 200–800x speedup for a seven-round AES-128 attack, with no impact on deployed systems.
Flying Eagle Android RAT Leaks on Telegram, 170 C2 Servers Active
Flying Eagle Android RAT source code is on Telegram; researchers traced matching panels to 170 servers targeting Chinese users via a fake government app.