Resources
CISA Orders Patch for Langflow and WordPress wp2shell RCEs
Mitchell Langley
July 28, 2026
CISA added Langflow CVE-2026-0770 and WordPress wp2shell CVE-2026-63030 to its KEV catalog, setting a July 24 Langflow deadline and August 4 WordPress deadline as mass ...
Qilin Affiliates Exploit PAN-OS CVE-2026-0257 GlobalProtect Bypass
Mitchell Langley
July 28, 2026
Arctic Wolf documented Qilin affiliates exploiting CVE-2026-0257, a PAN-OS GlobalProtect auth bypass, to gain trusted VPN access for double-extortion attacks.
JetBrains Patches TeamCity CVE-2026-63077 CVSS 9.8 RCE Flaw
Mitchell Langley
July 28, 2026
JetBrains patched CVE-2026-63077, a CVSS 9.8 unauthenticated RCE in TeamCity CI/CD servers exploitable via the agent polling protocol without any credentials.
AI-Assisted Linux Kernel CVE-2026-53264 Root Exploit Released
Gabby Lee
July 28, 2026
Lee Jia Jie used AI assistance to discover CVE-2026-53264, a Linux kernel use-after-free enabling local root escalation. A public exploit is now available.
Arista VeloCloud CVE-2026-16812 Exploited, CISA Orders Patch
Mitchell Langley
July 28, 2026
Arista confirmed CVE-2026-16812, a CVSS 10.0 OS command injection in VeloCloud Orchestrator, is actively exploited. CISA ordered federal patches by July 30.
Public Exploit Released for vBulletin CVE-2026-61511 RCE
Gabby Lee
July 28, 2026
SSD Secure Disclosure released a weaponized unauthenticated RCE exploit for CVE-2026-61511 in vBulletin 6.x, exposing forum sites not yet on version 6.2.2.
Fastjson CVE-2026-16723 Under Active Attack With No Patch
Andrew Doyle
July 27, 2026
Fastjson CVE-2026-16723, a CVSS 9.0 Java RCE flaw with no patch, is under active attack against financial services, healthcare, computing, and retail targets.
Rockwell Patches Four Arena Code Execution Flaws Across Sectors
Gabby Lee
July 27, 2026
Rockwell Automation patched four memory corruption CVEs in Arena, its simulation software used by hospitals, supply chain firms, and defense contractors.
DragonForce Posts Eighteen Victims Across Eight Countries in 48 Hours
Andrew Doyle
July 17, 2026
DragonForce posted eighteen victims across eight countries in 48 hours, including a US defense subcontractor, four law firms, and chemical manufacturers.
CISA Adds SharePoint CVE-2026-58644 to KEV After Zero-Day Confirmed
Gabby Lee
July 17, 2026
CISA added SharePoint CVE-2026-58644, a CVSS 9.8 deserialization flaw, to KEV after Microsoft confirmed zero-day exploitation. Federal deadline is July 19.
Weekly Newsletter
Weekly Cybersecurity Newsletter: 14th to 18th August
Andrew Doyle
July 19, 2025
Explore our latest cybersecurity podcast episodes featuring ransomware attacks, phishing campaigns, corporate breaches, legal showdowns, and deep dives into evolving threats and digital defenses.
This Week In Cybersecurity: 23rd June to 27th June
Andrew Doyle
June 30, 2025
News Stories New ‘FileFix’ Attack Exploits Windows File Explorer to Deliver Stealthy Commands Threat actors use the search-ms URI protocol ...
This Week In Cybersecurity: 26th to 30th May, 2025
Andrew Doyle
May 30, 2025
"Cybersecurity threats escalate as ransomware attacks target major organizations, exposing sensitive data and highlighting vulnerabilities in systems across various industries. Stay informed."
This Week In Cybersecurity: 19th to 23rd May, 2025
Andrew Doyle
May 23, 2025
This week, significant cybersecurity incidents include ransomware attacks, data breaches affecting major organizations, and ongoing threats from state-sponsored groups, highlighting vulnerabilities across various sectors.
This Week In Cybersecurity: 21st – 25th April, 2025
Andrew Doyle
April 25, 2025
Targeted malware, ransomware, phishing, and ad fraud hit SK Telecom, Baltimore schools, Google, and more this week—exposing critical data and abusing trusted systems.
Trending
Daily Briefing Newsletter
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.














