Timeline

Intelligence Timeline

A real, chronological record of every report as it was published — 300 most-recent entries. Refreshed automatically as new intelligence is ingested.

2026-07-21 · MEDIUM

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

2026-07-21 · MEDIUM

Windows LegacyHive zero-day flaw gets free, unofficial patches

2026-07-21 · MEDIUM

NotCVE registry index — public records of vulnerabilities that shipped without a CVE

2026-07-21 · MEDIUM

XSSer v.1.9 - "Bl4ck Swarm!" released

2026-07-21 · MEDIUM

New Release: UFONet v2.0 - "R3DST4R!"...

2026-07-21 · HIGH

Exploit for CVE-2026-23550 exploit

CVE-2026-23550
2026-07-21 · HIGH

fastjson-jsontype-rce-lab exploit

2026-07-21 · HIGH

Exploit for Out-of-bounds Write in Watchguard Fireware exploit

2026-07-21 · HIGH

wp2shell-Wordpress-TOWN exploit

2026-07-21 · HIGH

Exploit for CVE-2026-12191 exploit

CVE-2026-12191
2026-07-21 · HIGH

Exploit for CVE-2026-44680 exploit

CVE-2026-44680
2026-07-21 · HIGH

Exploit for CVE-2026-11374 exploit

CVE-2026-11374
2026-07-20 · MEDIUM

Estée Lauder discloses data breach via Oracle E-Business flaw

2026-07-20 · MEDIUM

SonicWall SMA1000 flaws exploited as zero-days to push custom malware

2026-07-20 · HIGH

js-yaml: YAML merge-key chains can force quadratic CPU consumption

CVE-2026-59869CVE-2026-59869
2026-07-20 · HIGH

Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions

CVE-2026-59928CVE-2026-59928
2026-07-20 · HIGH

File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup

CVE-2026-55667CVE-2026-55667
2026-07-20 · HIGH

Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading

CVE-2026-54059CVE-2026-54059
2026-07-20 · MEDIUM

JadePuffer agentic attacks now target AI model data with ransomware

2026-07-20 · MEDIUM

Is web penetration testing still a good career to invest in, or should I pivot while I'm still a junior?

2026-07-20 · HIGH

Composer: Arbitrary file write outside vendor via malicious transitive package name

CVE-2026-59948CVE-2026-59948
2026-07-20 · HIGH

vLLM denial of service via prompt embeds on M-RoPE models

CVE-2026-55514CVE-2026-55514
2026-07-20 · HIGH

Tornado: Quadratic DoS via Repeated Header Coalescing

CVE-2025-67725CVE-2025-67725
2026-07-20 · HIGH

Tornado: Quadratic DoS via Crafted Multipart Parameters

CVE-2025-67726CVE-2025-67726
2026-07-20 · MEDIUM

Open Directory Stages NGINX Rift and Ghost CMS Exploits Against Government and Finance Across Eleven Countries

2026-07-20 · CRITICAL

Critical wp2shell RCE Vulnerability Complete Coverage Including PoC and Active Exploitation Details

2026-07-20 · MEDIUM

Pay up or not? Ransomware surge has victims facing tough choices

2026-07-20 · MEDIUM

Would you leave a comfortable Network Security role for AI Security?

2026-07-20 · HIGH

Public PoC released for Critical ServiceNow Sandbox RCE Vulnerability

2026-07-20 · HIGH

Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs

2026-07-20 · HIGH

Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now!

2026-07-20 · HIGH

Hugging Face breached by autonomous AI agent

2026-07-20 · HIGH

New Index Tracks Material Breaches And Refuses to Add Up the Losses

2026-07-20 · HIGH

Capital One Open Sources AI-Powered VulnHunter Security Tool

2026-07-20 · CRITICAL

20th July Threat Intelligence Report

2026-07-20 · HIGH

Critical ServiceNow code execution flaw now exploited in attacks

2026-07-20 · HIGH

zero-copy-web-application-firewall exploit

2026-07-20 · HIGH

Exploit for Path Traversal in Jenkins exploit

2026-07-20 · HIGH

everything-claude-code exploit

2026-07-20 · HIGH

appsec-audit exploit

2026-07-20 · HIGH

Exploit for CVE-2026-61498 exploit

CVE-2026-61498
2026-07-20 · HIGH

vibesec-static exploit

2026-07-20 · CRITICAL

Microsoft SharePoint Vulnerabilities Actively Exploited for RCE, Web Shells, and IIS Key Theft

2026-07-20 · MEDIUM

⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

2026-07-20 · HIGH

World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent

2026-07-20 · HIGH

U.S. Prosecutors Charge Russian Trio in Cybercrimes Causing More Than $62 Million in Losses

2026-07-20 · MEDIUM

Need advice on building an ML-based adaptive web vulnerability scanner — how to handle lack of datasets?

2026-07-20 · HIGH

Cloudflare’s CAA flaw looks impractical for criminals — but what about actors who control the network?

CVE-2026-14440
2026-07-20 · HIGH

CVE-2026-9833 - Tag Groups < 2.2.0 - Reflected XSS via 'tag_groups_task' Parameter

CVE-2026-9833
2026-07-20 · HIGH

CVE-2026-13432 - ThumbPress < 6.2.2 - Subscriber+ Plugin Deactivation

CVE-2026-13432
2026-07-20 · HIGH

CVE-2026-12972 - PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Payment Metadata Tampering

CVE-2026-12972
2026-07-20 · HIGH

CVE-2026-13142 - Passwordless Login by VentraConnect < 1.4.1 - Unauthenticated Account Takeover via Email OTP Brute Force

CVE-2026-13142
2026-07-20 · HIGH

CVE-2026-12973 - PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Key Disclosure and Order Status Modification

CVE-2026-12973
2026-07-20 · HIGH

More alerts are making your team slower, and an outcome-based SOC fixes that

2026-07-20 · HIGH

Chrome 150 Update Patches Severe Memory Safety Bugs

2026-07-20 · HIGH

Meet Dusseldorf, Microsofts open-source out-of-band security platform

2026-07-20 · HIGH

Nearly half of open-source AI projects never reach production

2026-07-20 · CRITICAL

Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances

2026-07-20 · HIGH

TP-Link-TL-WR841ND-Security-Audit exploit

2026-07-20 · HIGH

Exploit for CVE-2025-9951 exploit

CVE-2025-9951
2026-07-20 · HIGH

PLUGINS-DETECTOR exploit

2026-07-20 · HIGH

fz-b2-rootshell exploit

2026-07-20 · CRITICAL

WP2Shell WordPress Vulnerabilities Exploited in the Wild

2026-07-20 · MEDIUM

Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25

2026-07-20 · MEDIUM

Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool

2026-07-20 · HIGH

Critical ServiceNow code execution flaw now exploited in attacks

CVE-2026-6875
2026-07-20 · MEDIUM

Unattributed Ransomware Campaign — Active Threat

2026-07-19 · HIGH

CVE-2026-13445: IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read an

CVE-2026-13445
2026-07-19 · HIGH

CVE-2026-9202: IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow

CVE-2026-9202
2026-07-19 · HIGH

CVE-2026-9198: IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER toke

CVE-2026-9198
2026-07-19 · HIGH

CVE-2026-15322: IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to obtain sensitive information due to the

CVE-2026-15322
2026-07-19 · HIGH

CVE-2026-9171: IBM PowerVM Novalink are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote atta

CVE-2026-9171
2026-07-19 · HIGH

CVE-2026-9103: IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authenti

CVE-2026-9103
2026-07-19 · HIGH

CVE-2026-13448: IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the

CVE-2026-13448
2026-07-19 · MEDIUM

Recovering from a malicious APK installation on CMF Phone. HELP!

2026-07-19 · HIGH

CVE-2026-15091: IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to imprope

CVE-2026-15091
2026-07-19 · HIGH

CVE-2026-14499: IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elev

CVE-2026-14499
2026-07-19 · HIGH

CVE-2026-58195: Agentic-Flow is an AI agent orchestration platform. Prior to 2.0.14, agentic-flow MCP server tools in src/mcp/standalone

CVE-2026-58195
2026-07-19 · HIGH

CVE-2026-9135: IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) co

CVE-2026-9135
2026-07-19 · HIGH

CVE-2026-63834 - batman-adv: tp_meter: restrict number of unacked list entries

CVE-2026-63834
2026-07-19 · HIGH

CVE-2026-13473: IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulner

CVE-2026-13473
2026-07-19 · MEDIUM

What AI cyber security platforms are spearheading the field.

2026-07-19 · HIGH

CVE-2026-45162: Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, multiple Pimcore loc

CVE-2026-45162
2026-07-19 · HIGH

BythosEngine exploit

2026-07-19 · HIGH

DarkSword-PROV2 exploit

2026-07-19 · HIGH

react2shell-poc exploit

2026-07-19 · HIGH

Exploit for CVE-2026-46420 exploit

CVE-2026-46420
2026-07-19 · MEDIUM

I resurrected a classic 2013 Active Defense tool (Honeyports), Rewritten in Python 3 with a Web UI and Threading 👍

2026-07-19 · HIGH

CVE-2026-63101: Open Event Server through 1.19.1 contains a missing authentication vulnerability that allows unauthenticated attackers t

CVE-2026-63101
2026-07-19 · HIGH

CVE-2026-57860: ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI, automatically loads and executes the MCP servers defined i

CVE-2026-57860
2026-07-19 · HIGH

CVE-2026-54496: ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primit

CVE-2026-54496
2026-07-19 · HIGH

CVE-2026-16228 - SourceCodester Class and Exam Timetabling System edit_schoolyr.php sql injection

CVE-2026-16228
2026-07-19 · HIGH

CVE-2026-16229 - itsourcecode Courier Management System index.php cross site scripting

CVE-2026-16229
2026-07-19 · HIGH

CVE-2026-16227 - SourceCodester Class and Exam Timetabling System edit_subject.php sql injection

CVE-2026-16227
2026-07-19 · HIGH

Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs

2026-07-19 · HIGH

nday: CVE-2026-49176_LPE_POC: Local privilege-escalation proof of concept for the Windows WalletService vulnerability fixed in July 2026.

CVE-2026-49176
2026-07-19 · HIGH

CVE-2026-8297: Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics En

CVE-2026-8297
2026-07-19 · MEDIUM

Breaking into the industry

2026-07-19 · HIGH

Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits

2026-07-19 · HIGH

APEX_FRAMEWORK exploit

2026-07-19 · HIGH

wp2shell_stock_chain exploit

2026-07-19 · HIGH

Exploit for CVE-2026-60137 exploit

CVE-2026-60137
2026-07-19 · HIGH

Exploit for Unrestricted Upload of File with Dangerous Type in Templaza Astroid_Framework exploit

2026-07-19 · MEDIUM

From 50 to 703: Expanding Unit 42's Gameograf Adware Chrome Extension Campaign

2026-07-19 · HIGH

CVE-2026-43977: wger is a free, open-source workout and fitness manager. In versions prior to 2.6, any authenticated user can read anoth

CVE-2026-43977
2026-07-19 · HIGH

CVE-2026-39359: Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.0.0 through

CVE-2026-39359
2026-07-19 · HIGH

CVE-2026-43978: wger is a free, open-source workout and fitness manager. In versions prior to 2.6, a gym trainer can escalate their sess

CVE-2026-43978
2026-07-18 · MEDIUM

Offering free OSINT assistance for small research tasks

2026-07-18 · MEDIUM

Update now: 7-Zip fixes RCE flaw exploitable with malicious archives

2026-07-18 · MEDIUM

Trump Has Systematically Dismantled Election Security Efforts. Here’s How.

2026-07-18 · MEDIUM

New Spirals Ransomware Uses IIS Web Shell and PsExec to Encrypt IT Firm in Under 24 Hours

2026-07-18 · MEDIUM

WordPress Core "wp2shell" RCE flaws get public exploits, patch now

2026-07-18 · CRITICAL

CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core

CVE-2026-63030CVE-2026-60137
2026-07-18 · MEDIUM

What Open Source Cyber Security Apps are Your Team Self-Hosting?

2026-07-18 · MEDIUM

White House launches AI-driven "Gold Eagle" clearinghouse to centralize public-private vulnerability coordination

2026-07-17 · MEDIUM

ClickLock macOS stealer relies on a pasted Terminal command, not an exploit

2026-07-17 · HIGH

Prompty: Arbitrary file read via file reference expansion

CVE-2026-53598CVE-2026-53598
2026-07-17 · MEDIUM

Openwrt pre-auth remote root exploit

2026-07-17 · HIGH

CVE lookup that shows the actual fix (KB / package version / Apple train), plus a no-key API. Built partly because NVD's API keeps flaking out

CVE-2021-44228 CISA KEV
2026-07-17 · HIGH

Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy

2026-07-17 · HIGH

CVE-2026-50148: Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.2

CVE-2026-50148
2026-07-17 · MEDIUM

can anyone help me solve exploit development challenge.

2026-07-17 · MEDIUM

In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint

2026-07-17 · HIGH

CVE-2026-50147: Metabase is an open-source business intelligence and embedded analytics tool. From 1.57.0 until 1.57.19.1, 1.58.14.1, 1.

CVE-2026-50147
2026-07-17 · HIGH

Ransomware attack halts Coca-Colas Fairlife US milk production

2026-07-17 · MEDIUM

Gold Eagle Clearinghouse Targets Security Gap, But How Is Unclear

2026-07-17 · MEDIUM

AI security project: PromptShield

2026-07-17 · MEDIUM

Cyberattack halts U.S. production at Coca-Cola’s fairlife dairy business

2026-07-17 · MEDIUM

Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive

2026-07-17 · MEDIUM

Beacon Security Raises $13 Million for Security Data Platform

2026-07-17 · MEDIUM

E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants

2026-07-17 · MEDIUM

Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday

2026-07-17 · MEDIUM

New Windows LegacyHive zero-day gives hackers admin privileges

2026-07-17 · MEDIUM

My Test Trainer - Website Launch

2026-07-17 · MEDIUM

Is MITRE is biased towards the historically what techniques are used rather then what's being used actively?

2026-07-17 · MEDIUM

Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei

2026-07-17 · MEDIUM

Windows Server 2022 reach end of mainstream support in 90 days

2026-07-17 · MEDIUM

US charges two over laundering $43 million from investment fraud

2026-07-17 · MEDIUM

Risk Ledger Raises $32 Million in Series B Funding

2026-07-17 · MEDIUM

If you've given an AI agent real credentials, how are you scoping what it can reach?

2026-07-17 · MEDIUM

Fresh SharePoint Vulnerability Exploited Soon After Disclosure

2026-07-17 · MEDIUM

CISA urges immediate action on actively exploited Fortinet flaws

2026-07-17 · MEDIUM

Published research article on IEEE about supply chain attacks and preventive security measures

2026-07-17 · MEDIUM

Coca-Cola Suspends US Fairlife Production Due to Ransomware Attack

2026-07-17 · MEDIUM

deberíaa pagar por esto?

2026-07-17 · MEDIUM

Is ast_grep_cli 0.44.1 on PyPI compromised? Windows Defender detected Trojan:Win64/Lazy!MTB during install

2026-07-17 · MEDIUM

Alerts on Server Loopback Traffic?

2026-07-17 · MEDIUM

Advice on Detection Engineering

2026-07-17 · MEDIUM

The Invisible Guardians of the Internet: An Introduction to Content Moderation &amp; Trust &amp; Safety

2026-07-17 · MEDIUM

cybersec VS data science

2026-07-17 · MEDIUM

ISC Stormcast For Friday, July 17th, 2026 https://isc.sans.edu/podcastdetail/10012, (Fri, Jul 17th)

2026-07-16 · MEDIUM

Beta BIOS/UEFI

2026-07-16 · MEDIUM

New ClickLock macOS malware traps users into revealing login password

2026-07-16 · MEDIUM

Coca-Cola says Fairlife ransomware attack halts US dairy production

2026-07-16 · HIGH

ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users

CVE-2026-54077CVE-2026-54077
2026-07-16 · HIGH

ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read

2026-07-16 · HIGH

MCP Python SDK: WebSocket server transport does not support Host/Origin validation

CVE-2026-59950CVE-2026-59950
2026-07-16 · HIGH

ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)

2026-07-16 · HIGH

ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js

2026-07-16 · HIGH

ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization

2026-07-16 · HIGH

ArcadeDB: Read-only users can mutate database schema (incomplete fix of CVE-2026-44221)

CVE-2026-54076CVE-2026-54076
2026-07-16 · HIGH

Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection

CVE-2026-55578CVE-2026-55578
2026-07-16 · HIGH

MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal

CVE-2026-52869CVE-2026-52869
2026-07-16 · HIGH

Pheditor has an authenticated terminal command whitelist bypass

CVE-2026-54540CVE-2026-54540
2026-07-16 · HIGH

Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode

CVE-2026-53714CVE-2026-53714
2026-07-16 · HIGH

MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks

CVE-2026-52870CVE-2026-52870
2026-07-16 · HIGH

Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads to build-time RCE

CVE-2026-52833CVE-2026-52833
2026-07-16 · MEDIUM

New OkoBot framework deploys 20 payloads to steal data, crypto

2026-07-16 · MEDIUM

Claude Chrome extension flaw lets malicious extensions trigger AI actions

2026-07-16 · MEDIUM

Apple Sued Over Reported 'Hide My Email' Flaw

2026-07-16 · MEDIUM

New Exploitable BOLA Found in Immich (self-hosted media platform)

2026-07-16 · MEDIUM

With AI, Your Entire Internet History is Attributable to you Personally

2026-07-16 · MEDIUM

Teen hackers jailed after live-streaming the 16-hour TfL attack

2026-07-16 · MEDIUM

Open-sourced my Claude Code team kit for secure multi-agent development and governance. Feedback welcome.

2026-07-16 · MEDIUM

This might be a dumb question

2026-07-16 · MEDIUM

How to Measure the Revenue Impact of Security Hardening Projects with a Simple Formula

2026-07-16 · MEDIUM

ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories

2026-07-16 · MEDIUM

SOC Analyst platforms and lacks

2026-07-16 · MEDIUM

Legacy Systems, Real-World Impacts: The Reality of OT Security

2026-07-16 · MEDIUM

Preciso de ajuda

2026-07-16 · MEDIUM

[$13337] Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking

2026-07-16 · MEDIUM

No Shark is Safe: Millions of Shark Vacuums are Vulnerable to RCE

2026-07-16 · MEDIUM

Top 10 Data Center and AI Infrastructure Security Risks

2026-07-16 · MEDIUM

23andMe to pay $18 million in new genetics data breach settlement

2026-07-16 · MEDIUM

Two Scattered Spider Hackers Sentenced to Jail in UK

2026-07-16 · MEDIUM

The British teenager who hacked into Vegas casinos from an east London flat

2026-07-16 · MEDIUM

&#8216;ClickLock Stealer&#8217; Bypasses macOS Security With Social Engineering, Process Killing

2026-07-16 · MEDIUM

AI Data Centers Are Being Built Faster Than They Can Be Secured

2026-07-16 · MEDIUM

Critical NGINX vulnerability discovered: hackers can attempt to crash servers or even gain code execution

2026-07-16 · HIGH

Proof of concept for CVE-2026-58635 LPE in Windows Braille Narrator service

CVE-2026-58635
2026-07-16 · MEDIUM

Scattered Spider members behind TfL hack get five years in prison

2026-07-16 · MEDIUM

Oak Emerges From Stealth Mode With $60 Million in Funding

2026-07-16 · MEDIUM

Files relating to India’s largest nuclear power plant Kudankulam exposed in data breach

2026-07-16 · MEDIUM

Splunk, Zoom Patch Critical Vulnerabilities

2026-07-16 · MEDIUM

Please Stop Making Me Opt Out of AI

2026-07-16 · MEDIUM

CISA orders feds to patch actively exploited Oracle flaw by Saturday

2026-07-16 · MEDIUM

Russian hackers trojanize WebEx, Zoom apps to push Starland malware

2026-07-16 · MEDIUM

Moroccan intelligence insider reveals widespread use of Pegasus hacking software | Morocco

2026-07-16 · MEDIUM

Learning DevSecOps - Week 2

2026-07-16 · MEDIUM

When Inclusive Language ends in phishing

2026-07-16 · MEDIUM

F5 Patches Multiple NGINX, BIG-IP Vulnerabilities

2026-07-16 · MEDIUM

China&#8217;s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans

2026-07-16 · MEDIUM

Old UEFI Shims Expose Systems to Secure Boot Bypass

2026-07-16 · MEDIUM

AI Agent for reconaissasion

2026-07-16 · MEDIUM

Police Disrupt a €140M Cyber Fraud Ring in Spain

2026-07-16 · MEDIUM

Nightmare Eclipse Drops &#8216;LegacyHive&#8217; Windows Zero-Day

2026-07-16 · MEDIUM

Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities

2026-07-16 · HIGH

ASUS bsitf.sys (CVE-2026-13585): Arbitrary Physical Memory Mapping via Unvalidated IOCTL

CVE-2026-13585
2026-07-16 · MEDIUM

i get stuck

2026-07-16 · HIGH

CVE-2026-56877 - Skillable SCORM userId authorisation bypass

CVE-2026-56877
2026-07-16 · HIGH

[NotCVE-2026-0001] Cloudflare Universal SSL CAA augmentation weakens RFC 8657 account binding — CVE-2026-14440 assigned 163 days after public no-CVE disclosure

CVE-2026-0001CVE-2026-14440
2026-07-16 · MEDIUM

Subject: Advisory Submission: EZ Game Booster - Cleartext Storage of Sensitive Credentials (CWE-312)

2026-07-16 · MEDIUM

ISC Stormcast For Thursday, July 16th, 2026 https://isc.sans.edu/podcastdetail/10010, (Thu, Jul 16th)

2026-07-15 · MEDIUM

Greene County, Georgia, cybersecurity incident disrupts services

2026-07-15 · HIGH

dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS

CVE-2026-50274CVE-2026-50274
2026-07-15 · HIGH

dd-trace-rb: Improper parsing of W3C baggage headers may lead to DoS

CVE-2026-50276CVE-2026-50276
2026-07-15 · HIGH

Pomerium Pre-Auth Memory Exhaustion via Unbounded zstd Decompression in HPKE Callback

CVE-2026-50285CVE-2026-50285
2026-07-15 · HIGH

systeminformation: OS command injection in networkInterfaces() via interfaces(5) source-directive path on Linux

CVE-2026-50289CVE-2026-50289
2026-07-15 · HIGH

@andrea9293/mcp-documentation-server: Web UI API binds to all interfaces without authentication by default

CVE-2026-54504CVE-2026-54504
2026-07-15 · HIGH

dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS

CVE-2026-50271CVE-2026-50271
2026-07-15 · HIGH

dd-trace-js: Improper parsing of W3C baggage headers may lead to DoS

CVE-2026-50272CVE-2026-50272
2026-07-15 · HIGH

dd-trace-dotnet: Improper parsing of W3C baggage headers may lead to DoS

CVE-2026-50273CVE-2026-50273
2026-07-15 · HIGH

dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS

CVE-2026-50270CVE-2026-50270
2026-07-15 · HIGH

ViewComponent: around_render HTML-Safety Bypass

CVE-2026-54498CVE-2026-54498
2026-07-15 · HIGH

django-haystack: Remote Code Execution via `eval()` in Elasticsearch Result Deserialization

2026-07-15 · MEDIUM

Dutch police bust investment fraud ring stealing over €100 million

2026-07-15 · HIGH

TensorZero Gateway: Arbitrary file read and SSRF in internal object storage endpoint

CVE-2026-54457CVE-2026-54457
2026-07-15 · HIGH

obsidian-local-rest-api: Authenticated path traversal via URL-encoded %2F in /vault/{path} — arbitrary host file read/write/delete

2026-07-15 · MEDIUM

Zoom warns of critical account takeover vulnerability

2026-07-15 · MEDIUM

TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development

2026-07-15 · MEDIUM

Google Gemini CLI abused as a hacking agent, malware botnet operator

2026-07-15 · MEDIUM

Getting mitre techniques a customer raw detection rule covers

2026-07-15 · HIGH

MantisBT: Stored XSS in print_all_bug_page_word.php

CVE-2026-62944CVE-2026-62944
2026-07-15 · MEDIUM

Guten Tag, Bonjour, Hola to Our European Cyber Defenders!

2026-07-15 · HIGH

Koel: Incomplete fix for CVE-2026-47260 — systemic SSRF in podcast & radio fetch paths

CVE-2026-54491CVE-2026-54491
2026-07-15 · HIGH

Protobuf: Unbounded recursion depth in embedded-message decoding

CVE-2026-54451CVE-2026-54451
2026-07-15 · HIGH

garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store

CVE-2026-54447CVE-2026-54447
2026-07-15 · HIGH

LangBot: Authenticated RCE Via MCP Configuration

CVE-2026-54449CVE-2026-54449
2026-07-15 · MEDIUM

Is 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI Strife

2026-07-15 · HIGH

Koel: Authenticated Full-Read SSRF via Subsonic Internet Radio Stations

CVE-2026-54493CVE-2026-54493
2026-07-15 · HIGH

MantisBT: SQL Injection via history_order Configuration Value

CVE-2026-47142CVE-2026-47142
2026-07-15 · HIGH

MantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.php

CVE-2026-49273CVE-2026-49273
2026-07-15 · MEDIUM

​ ​AsyncAPI npm packages infected with credential-stealing malware

2026-07-15 · MEDIUM

File-Binding, Process-Binding, and Silo-Binding - new process impersonation techniques for EDR evasion

2026-07-15 · MEDIUM

Unpatched Cursor Vulnerability Exposes Users to Code Execution

2026-07-15 · MEDIUM

Sophos: The State of Ransomware 2026: Payments are dropping but encryption is climbing

2026-07-15 · MEDIUM

Coverage-First SOC: why domains and telemetry matter as much as threat intel

2026-07-15 · MEDIUM

Runtime detection for ECS/EC2, what are people actually using?

2026-07-15 · MEDIUM

CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities

2026-07-15 · MEDIUM

KQL Queries for new Chaotic Eclipse Zero day 'Legacy Hive'

2026-07-15 · MEDIUM

Virtual Event Today: Cloud &#038; Data Security Summit

2026-07-15 · MEDIUM

Windows Bind Link Attacks Can Hide Malware From EDR Tools

2026-07-15 · MEDIUM

2-Click Cursor Exploit Enables Dev Environment Takeover

2026-07-15 · MEDIUM

US Charges Russian Individuals and Firms for Running Cybercrime Services

2026-07-15 · MEDIUM

Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow

2026-07-15 · MEDIUM

Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution

2026-07-15 · MEDIUM

White House Launches AI-Driven &#8216;Gold Eagle&#8217; Vulnerability Coordination Initiative

2026-07-15 · MEDIUM

CISA warns admins to patch actively exploited SharePoint flaws

2026-07-15 · MEDIUM

Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption

2026-07-15 · MEDIUM

Need help reverse engineering an Android APK used in a UPI fraud

2026-07-15 · MEDIUM

HN Security - My Semgrep C/C++ ruleset is ready for prime time again

2026-07-15 · MEDIUM

The Memory Heist - How I tricked Claude into leaking your deepest, darkest secrets

2026-07-15 · MEDIUM

Microsoft: Some Dell PCs shut down after recent Windows updates

2026-07-15 · MEDIUM

(More) Unauthenticated Arbitrary Code Execution in ServiceNow

2026-07-15 · MEDIUM

Nigeria Deepens Cybersecurity Efforts as Cybercriminals See More Profits

2026-07-15 · MEDIUM

US charges alleged operators of Russian bulletproof hosting service

2026-07-15 · MEDIUM

Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates

2026-07-15 · MEDIUM

Recent DShield SIEM Update, (Tue, Jul 14th)

2026-07-15 · MEDIUM

ISC Stormcast For Wednesday, July 15th, 2026 https://isc.sans.edu/podcastdetail/10008, (Wed, Jul 15th)

2026-07-15 · MEDIUM

ISC2 Board of Directors Election is open.

2026-07-14 · MEDIUM

Hochul halts new data center approvals via executive order

2026-07-14 · HIGH

SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now

CVE-2026-15409CVE-2026-15410
2026-07-14 · HIGH

NetLicensing-MCP: Unauthenticated Use of Server-Side NetLicensing API Key in HTTP Mode

CVE-2026-54446CVE-2026-54446
2026-07-14 · MEDIUM

Spanish Police take down €140 million cyber fraud ring, arrest four

2026-07-14 · HIGH

Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder

CVE-2026-44891CVE-2026-44891
2026-07-14 · HIGH

nebula-mesh: Operator session tokens stored in plaintext in the database

CVE-2026-53603CVE-2026-53603
2026-07-14 · HIGH

Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode

CVE-2026-54629CVE-2026-54629
2026-07-14 · HIGH

Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`

2026-07-14 · HIGH

Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend

CVE-2026-61549CVE-2026-61549
2026-07-14 · HIGH

nebula-mesh: Certificate revocation is never enforced at the mesh

CVE-2026-61699CVE-2026-61699
2026-07-14 · HIGH

nebula-mesh: CA private key not zeroized on web mobile-bundle error paths

CVE-2026-53604CVE-2026-53604
2026-07-14 · HIGH

Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode

CVE-2026-54628CVE-2026-54628
2026-07-14 · HIGH

yutu: Arbitrary File Write via MCP `caption-download` Tool

CVE-2026-50158CVE-2026-50158
2026-07-14 · HIGH

EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField

CVE-2026-54087CVE-2026-54087
2026-07-14 · HIGH

Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser

CVE-2026-54448CVE-2026-54448
2026-07-14 · HIGH

Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware

2026-07-14 · HIGH

TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services

2026-07-14 · MEDIUM

Microsoft Patches a Record 570 Security Flaws

2026-07-14 · MEDIUM

Nearly 300 GitHub repos pose as legit software to push malware

2026-07-14 · MEDIUM

Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th)

2026-07-14 · MEDIUM

Microsoft releases Windows 10 KB5099539 extended security update

2026-07-14 · MEDIUM

LegacyHive : Windows user profile service arbitrary hive load elevation of privileges vulnerability

2026-07-14 · HIGH

Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation

CVE-2026-50141CVE-2026-50141
2026-07-14 · MEDIUM

🇨🇳 Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries

2026-07-14 · MEDIUM

Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days

2026-07-14 · HIGH

Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode

CVE-2026-50013CVE-2026-50013
2026-07-14 · HIGH

MKP: Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines` Causes Memory Exhaustion

CVE-2026-50125CVE-2026-50125
2026-07-14 · HIGH

Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges

CVE-2026-50131CVE-2026-50131
2026-07-14 · MEDIUM

Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims

2026-07-14 · MEDIUM

Windows 11 KB5101650 &amp; KB5099414 cumulative updates released