Cyber Security
Cybersecurity
Nimbus Manticore Deploys NightLedger Backdoor Across Three Regions
Mitchell Langley
July 29, 2026
Iran-linked Nimbus Manticore deployed the new NightLedger backdoor and WebSocket tunnelers against targets in the Middle East, Africa, and South Asia.
Cybersecurity
Tengu Botnet Reboots Devices via Hardware Watchdog to Evade Removal
Mitchell Langley
July 29, 2026
Tengu, a new Mirai-derived Linux IoT botnet, triggers device reboots via hardware watchdog when defenders kill its process, supporting 25 DDoS methods.
Cybersecurity
24,650 Internet-Exposed Server BMCs Leak Password Hashes Before Login
Mitchell Langley
July 29, 2026
Researchers found 24,650 internet-exposed BMCs that disclose IPMI password hashes before login, enabling offline hash cracking and full server takeover.
Cybersecurity
CyberAv3ngers Suspected in OT Attacks on 30+ Minnesota Water Utilities
Andrew Doyle
July 29, 2026
More than 30 Minnesota water utilities were disrupted in a coordinated OT attack; Tenable suspects Iran-linked CyberAv3ngers based on targeting patterns.
Application Security
VMware ESXi VM Escape CVE-2026-47876 Patched Alongside Four More Flaws
Gabby Lee
July 29, 2026
Broadcom patched CVE-2026-47876, a critical ESXi VM escape via VMXNET3, plus two critical vCenter Server flaws, with no confirmed in-the-wild exploitation.
Cybersecurity
CubePilot Drone Controller Developer Hit by DNS Hijacking
Gabby Lee
July 29, 2026
Attackers seized CubePilot's domain DNS settings and obtained TLS certificates for all subdomains, potentially capturing credentials during the attack window.
Cybersecurity
Claude Mythos Cracks HAWK-256 Lattice Problem, Speeds AES-128 Attack
Gabby Lee
July 29, 2026
Anthropic's Claude Mythos derived a HAWK-256 key-recovery attack and 200–800x speedup for a seven-round AES-128 attack, with no impact on deployed systems.
Cybersecurity
Flying Eagle Android RAT Leaks on Telegram, 170 C2 Servers Active
Andrew Doyle
July 29, 2026
Flying Eagle Android RAT source code is on Telegram; researchers traced matching panels to 170 servers targeting Chinese users via a fake government app.
Application Security
@joyfill npm Beta Packages Deploy DEV#POPPER RAT on Import
Gabby Lee
July 29, 2026
Two @joyfill npm beta packages were compromised to deliver DEV#POPPER RAT on import, risking credential theft and persistent access on developers' machines.
Cybersecurity
ENCFORGE Ransomware Targets PyTorch, SafeTensors Model Files
Gabby Lee
July 28, 2026
Sysdig documented ENCFORGE, a Go ransomware targeting 180 AI file formats including PyTorch, SafeTensors, and GGUF, deployed by the JADEPUFFER threat operator.
Application Security
Fastjson 1.x Zero-Day CVE-2026-16723 Under Active Exploit, No Patch
Mitchell Langley
July 28, 2026
CVE-2026-16723, a CVSS 9.0 zero-day in Fastjson 1.x with no available patch, is actively exploited targeting financial services and healthcare backends.
Application Security
CISA Orders Patch for Langflow and WordPress wp2shell RCEs
Mitchell Langley
July 28, 2026
CISA added Langflow CVE-2026-0770 and WordPress wp2shell CVE-2026-63030 to its KEV catalog, setting a July 24 Langflow deadline and August 4 WordPress deadline as mass ...
CVE Vulnerability Alerts
Qilin Affiliates Exploit PAN-OS CVE-2026-0257 GlobalProtect Bypass
Mitchell Langley
July 28, 2026
Arctic Wolf documented Qilin affiliates exploiting CVE-2026-0257, a PAN-OS GlobalProtect auth bypass, to gain trusted VPN access for double-extortion attacks.
Application Security
JetBrains Patches TeamCity CVE-2026-63077 CVSS 9.8 RCE Flaw
Mitchell Langley
July 28, 2026
JetBrains patched CVE-2026-63077, a CVSS 9.8 unauthenticated RCE in TeamCity CI/CD servers exploitable via the agent polling protocol without any credentials.
CVE Vulnerability Alerts
AI-Assisted Linux Kernel CVE-2026-53264 Root Exploit Released
Gabby Lee
July 28, 2026
Lee Jia Jie used AI assistance to discover CVE-2026-53264, a Linux kernel use-after-free enabling local root escalation. A public exploit is now available.
CVE Vulnerability Alerts
Arista VeloCloud CVE-2026-16812 Exploited, CISA Orders Patch
Mitchell Langley
July 28, 2026
Arista confirmed CVE-2026-16812, a CVSS 10.0 OS command injection in VeloCloud Orchestrator, is actively exploited. CISA ordered federal patches by July 30.
Cybersecurity
Dysphoria IoT Botnet Hits 200K Devices With Blockchain C2
Andrew Doyle
July 28, 2026
Dysphoria, successor to the disrupted JackSkid botnet, infected 200,000 IoT devices worldwide and adopted Ethereum and Solana Name Service to anchor its C2.
Application Security
Public Exploit Released for vBulletin CVE-2026-61511 RCE
Gabby Lee
July 28, 2026
SSD Secure Disclosure released a weaponized unauthenticated RCE exploit for CVE-2026-61511 in vBulletin 6.x, exposing forum sites not yet on version 6.2.2.
Application Security
n8n Sandbox Escape GHSA-gv7g-jm28-cr3m Exposes Host OS Commands
Andrew Doyle
July 28, 2026
n8n versions before 2.31.5 let authenticated users escape the expression sandbox via arrow functions and Reflect.get(), executing OS commands on the host.
Cybersecurity
Operation BlueDash Delivers RMM Tools via Fake Teams Lures
Mitchell Langley
July 28, 2026
Operation BlueDash deploys Level RMM and ScreenConnect against enterprises through fake Microsoft Teams and Zoom pages linked to a Nigerian threat actor.
Cybersecurity
Russian Actor Uses AI to Exploit PaperCut, Hits 440+ Organizations
Andrew Doyle
September 11, 2026
Cybersecurity
ShinyHunters Claims Breach of Florida DMV DAVID Database
Mitchell Langley
September 9, 2026
Application Security
GoldFactory and Mantax Otax Target Indonesian Android Bank Users
Andrew Doyle
September 11, 2026
CVE Vulnerability Alerts
Aurora Ransomware Operators Use Cursor AI to Execute Network Attacks
Andrew Doyle
September 2, 2026
TOP CYBERSECURITY HEADLINES
Application Security
UNC3569 Exploits Sogou Input Method to Deploy GRAYRABBIT Backdoor
Application Security
Attackers Use BYOD Weaknesses to Access M365 via Graph API
This Week’s Security Spotlight
Cybersecurity
Russian Actor Uses AI to Exploit PaperCut, Hits 440+ Organizations
Andrew Doyle
September 11, 2026
Cybersecurity
LG Accused of Privacy Violations Over Smart TV Data Collection
Mitchell Langley
September 9, 2026
Application Security
OpenAI Agents Made 18,000 Unauthorized Edits to German Wiki
Mitchell Langley
September 8, 2026
Application Security
Judge Rules Pentagon Actions Against Anthropic Unlawful
Gabby Lee
September 1, 2026
Trending
Daily Briefing Newsletter
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
Featured Videos
Podcasts
- All
- Application Security
- Blog
- CVE Vulnerability Alerts
- Cybersecurity
- Cybersecurity Newsletter
- Data Security
- Endpoint Security
- Identity and Access Management
- Information Security
- Network Security
- News
- Phishing
- Podcasts
- Product Reviews
- Ransomware
- Ransomware Victims
- Resources
- Security Spotlight
- Sponsored
- Threat Actors
- Threat Actors
- Threat Detection Tools
CyberAv3ngers Suspected in OT Attacks on 30+ Minnesota Water Utilities
July 29, 2026
More than 30 Minnesota water utilities were disrupted in a coordinated OT attack; Tenable suspects Iran-linked CyberAv3ngers based on targeting patterns.
VMware ESXi VM Escape CVE-2026-47876 Patched Alongside Four More Flaws
July 29, 2026
Broadcom patched CVE-2026-47876, a critical ESXi VM escape via VMXNET3, plus two critical vCenter Server flaws, with no confirmed in-the-wild exploitation.
CubePilot Drone Controller Developer Hit by DNS Hijacking
July 29, 2026
Attackers seized CubePilot's domain DNS settings and obtained TLS certificates for all subdomains, potentially capturing credentials during the attack window.
Claude Mythos Cracks HAWK-256 Lattice Problem, Speeds AES-128 Attack
July 29, 2026
Anthropic's Claude Mythos derived a HAWK-256 key-recovery attack and 200–800x speedup for a seven-round AES-128 attack, with no impact on deployed systems.
Flying Eagle Android RAT Leaks on Telegram, 170 C2 Servers Active
July 29, 2026
Flying Eagle Android RAT source code is on Telegram; researchers traced matching panels to 170 servers targeting Chinese users via a fake government app.
@joyfill npm Beta Packages Deploy DEV#POPPER RAT on Import
July 29, 2026
Two @joyfill npm beta packages were compromised to deliver DEV#POPPER RAT on import, risking credential theft and persistent access on developers' machines.
ENCFORGE Ransomware Targets PyTorch, SafeTensors Model Files
July 28, 2026
Sysdig documented ENCFORGE, a Go ransomware targeting 180 AI file formats including PyTorch, SafeTensors, and GGUF, deployed by the JADEPUFFER threat operator.
Fastjson 1.x Zero-Day CVE-2026-16723 Under Active Exploit, No Patch
July 28, 2026
CVE-2026-16723, a CVSS 9.0 zero-day in Fastjson 1.x with no available patch, is actively exploited targeting financial services and healthcare backends.
CISA Orders Patch for Langflow and WordPress wp2shell RCEs
July 28, 2026
CISA added Langflow CVE-2026-0770 and WordPress wp2shell CVE-2026-63030 to its KEV catalog, setting a July 24 Langflow deadline and August 4 WordPress deadline as mass ...
Qilin Affiliates Exploit PAN-OS CVE-2026-0257 GlobalProtect Bypass
July 28, 2026
Arctic Wolf documented Qilin affiliates exploiting CVE-2026-0257, a PAN-OS GlobalProtect auth bypass, to gain trusted VPN access for double-extortion attacks.
JetBrains Patches TeamCity CVE-2026-63077 CVSS 9.8 RCE Flaw
July 28, 2026
JetBrains patched CVE-2026-63077, a CVSS 9.8 unauthenticated RCE in TeamCity CI/CD servers exploitable via the agent polling protocol without any credentials.
AI-Assisted Linux Kernel CVE-2026-53264 Root Exploit Released
July 28, 2026
Lee Jia Jie used AI assistance to discover CVE-2026-53264, a Linux kernel use-after-free enabling local root escalation. A public exploit is now available.
Arista VeloCloud CVE-2026-16812 Exploited, CISA Orders Patch
July 28, 2026
Arista confirmed CVE-2026-16812, a CVSS 10.0 OS command injection in VeloCloud Orchestrator, is actively exploited. CISA ordered federal patches by July 30.
Dysphoria IoT Botnet Hits 200K Devices With Blockchain C2
July 28, 2026
Dysphoria, successor to the disrupted JackSkid botnet, infected 200,000 IoT devices worldwide and adopted Ethereum and Solana Name Service to anchor its C2.
Public Exploit Released for vBulletin CVE-2026-61511 RCE
July 28, 2026
SSD Secure Disclosure released a weaponized unauthenticated RCE exploit for CVE-2026-61511 in vBulletin 6.x, exposing forum sites not yet on version 6.2.2.
n8n Sandbox Escape GHSA-gv7g-jm28-cr3m Exposes Host OS Commands
July 28, 2026
n8n versions before 2.31.5 let authenticated users escape the expression sandbox via arrow functions and Reflect.get(), executing OS commands on the host.
Operation BlueDash Delivers RMM Tools via Fake Teams Lures
July 28, 2026
Operation BlueDash deploys Level RMM and ScreenConnect against enterprises through fake Microsoft Teams and Zoom pages linked to a Nigerian threat actor.
Cruciferra Crypter Combines BYOVD and Process Ghosting to Kill EDR
July 28, 2026
Cruciferra, a MaaS crypter active since fall 2025, bypasses EDR via BYOVD and Process Ghosting. TA4922, Silver Fox, and 11 malware families are linked to ...
Victims Sue Apple Over $1.8M Bitcoin Theft Via Fake Sparrow App
July 28, 2026
Three individuals sued Apple over a fake iOS Sparrow Wallet app that stole $1.8 million in Bitcoin by harvesting seed phrases. Apple was warned in ...
ShinyHunters Claims Ernst & Young Breach via Third-Party System
July 28, 2026
ShinyHunters posted Ernst & Young to its leak site, claiming a supply-chain attack on a third-party ticket system that exposed client tax and financial data.





































