Intelligence Timeline
A real, chronological record of every report as it was published — 300 most-recent entries. Refreshed automatically as new intelligence is ingested.
2026-07-21 · MEDIUMNew ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
Windows LegacyHive zero-day flaw gets free, unofficial patches
NotCVE registry index — public records of vulnerabilities that shipped without a CVE
XSSer v.1.9 - "Bl4ck Swarm!" released
New Release: UFONet v2.0 - "R3DST4R!"...
Exploit for CVE-2026-23550 exploit
CVE-2026-23550
2026-07-21 · HIGH
fastjson-jsontype-rce-lab exploit
Exploit for Out-of-bounds Write in Watchguard Fireware exploit
wp2shell-Wordpress-TOWN exploit
Exploit for CVE-2026-12191 exploit
CVE-2026-12191
2026-07-21 · HIGH
Exploit for CVE-2026-44680 exploit
CVE-2026-44680
2026-07-21 · HIGH
Exploit for CVE-2026-11374 exploit
CVE-2026-11374
2026-07-20 · MEDIUM
Estée Lauder discloses data breach via Oracle E-Business flaw
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
js-yaml: YAML merge-key chains can force quadratic CPU consumption
CVE-2026-59869CVE-2026-59869
2026-07-20 · HIGH
Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions
CVE-2026-59928CVE-2026-59928
2026-07-20 · HIGH
File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup
CVE-2026-55667CVE-2026-55667
2026-07-20 · HIGH
Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
CVE-2026-54059CVE-2026-54059
2026-07-20 · MEDIUM
JadePuffer agentic attacks now target AI model data with ransomware
Is web penetration testing still a good career to invest in, or should I pivot while I'm still a junior?
Composer: Arbitrary file write outside vendor via malicious transitive package name
CVE-2026-59948CVE-2026-59948
2026-07-20 · HIGH
vLLM denial of service via prompt embeds on M-RoPE models
CVE-2026-55514CVE-2026-55514
2026-07-20 · HIGH
Tornado: Quadratic DoS via Repeated Header Coalescing
CVE-2025-67725CVE-2025-67725
2026-07-20 · HIGH
Tornado: Quadratic DoS via Crafted Multipart Parameters
CVE-2025-67726CVE-2025-67726
2026-07-20 · MEDIUM
Open Directory Stages NGINX Rift and Ghost CMS Exploits Against Government and Finance Across Eleven Countries
Critical wp2shell RCE Vulnerability Complete Coverage Including PoC and Active Exploitation Details
Pay up or not? Ransomware surge has victims facing tough choices
Would you leave a comfortable Network Security role for AI Security?
Public PoC released for Critical ServiceNow Sandbox RCE Vulnerability
Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now!
Hugging Face breached by autonomous AI agent
New Index Tracks Material Breaches And Refuses to Add Up the Losses
Capital One Open Sources AI-Powered VulnHunter Security Tool
20th July Threat Intelligence Report
Critical ServiceNow code execution flaw now exploited in attacks
zero-copy-web-application-firewall exploit
Exploit for Path Traversal in Jenkins exploit
everything-claude-code exploit
appsec-audit exploit
Exploit for CVE-2026-61498 exploit
CVE-2026-61498
2026-07-20 · HIGH
vibesec-static exploit
Microsoft SharePoint Vulnerabilities Actively Exploited for RCE, Web Shells, and IIS Key Theft
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
U.S. Prosecutors Charge Russian Trio in Cybercrimes Causing More Than $62 Million in Losses
Need advice on building an ML-based adaptive web vulnerability scanner — how to handle lack of datasets?
Cloudflare’s CAA flaw looks impractical for criminals — but what about actors who control the network?
CVE-2026-14440
2026-07-20 · HIGH
CVE-2026-9833 - Tag Groups < 2.2.0 - Reflected XSS via 'tag_groups_task' Parameter
CVE-2026-9833
2026-07-20 · HIGH
CVE-2026-13432 - ThumbPress < 6.2.2 - Subscriber+ Plugin Deactivation
CVE-2026-13432
2026-07-20 · HIGH
CVE-2026-12972 - PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Payment Metadata Tampering
CVE-2026-12972
2026-07-20 · HIGH
CVE-2026-13142 - Passwordless Login by VentraConnect < 1.4.1 - Unauthenticated Account Takeover via Email OTP Brute Force
CVE-2026-13142
2026-07-20 · HIGH
CVE-2026-12973 - PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Key Disclosure and Order Status Modification
CVE-2026-12973
2026-07-20 · HIGH
More alerts are making your team slower, and an outcome-based SOC fixes that
Chrome 150 Update Patches Severe Memory Safety Bugs
Meet Dusseldorf, Microsofts open-source out-of-band security platform
Nearly half of open-source AI projects never reach production
Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances
TP-Link-TL-WR841ND-Security-Audit exploit
Exploit for CVE-2025-9951 exploit
CVE-2025-9951
2026-07-20 · HIGH
PLUGINS-DETECTOR exploit
fz-b2-rootshell exploit
WP2Shell WordPress Vulnerabilities Exploited in the Wild
Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25
Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool
Critical ServiceNow code execution flaw now exploited in attacks
CVE-2026-6875
2026-07-20 · MEDIUM
Unattributed Ransomware Campaign — Active Threat
CVE-2026-13445: IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read an
CVE-2026-13445
2026-07-19 · HIGH
CVE-2026-9202: IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow
CVE-2026-9202
2026-07-19 · HIGH
CVE-2026-9198: IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER toke
CVE-2026-9198
2026-07-19 · HIGH
CVE-2026-15322: IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to obtain sensitive information due to the
CVE-2026-15322
2026-07-19 · HIGH
CVE-2026-9171: IBM PowerVM Novalink are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote atta
CVE-2026-9171
2026-07-19 · HIGH
CVE-2026-9103: IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authenti
CVE-2026-9103
2026-07-19 · HIGH
CVE-2026-13448: IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the
CVE-2026-13448
2026-07-19 · MEDIUM
Recovering from a malicious APK installation on CMF Phone. HELP!
CVE-2026-15091: IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to imprope
CVE-2026-15091
2026-07-19 · HIGH
CVE-2026-14499: IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elev
CVE-2026-14499
2026-07-19 · HIGH
CVE-2026-58195: Agentic-Flow is an AI agent orchestration platform. Prior to 2.0.14, agentic-flow MCP server tools in src/mcp/standalone
CVE-2026-58195
2026-07-19 · HIGH
CVE-2026-9135: IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) co
CVE-2026-9135
2026-07-19 · HIGH
CVE-2026-63834 - batman-adv: tp_meter: restrict number of unacked list entries
CVE-2026-63834
2026-07-19 · HIGH
CVE-2026-13473: IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulner
CVE-2026-13473
2026-07-19 · MEDIUM
What AI cyber security platforms are spearheading the field.
CVE-2026-45162: Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, multiple Pimcore loc
CVE-2026-45162
2026-07-19 · HIGH
BythosEngine exploit
DarkSword-PROV2 exploit
react2shell-poc exploit
Exploit for CVE-2026-46420 exploit
CVE-2026-46420
2026-07-19 · MEDIUM
I resurrected a classic 2013 Active Defense tool (Honeyports), Rewritten in Python 3 with a Web UI and Threading 👍
CVE-2026-63101: Open Event Server through 1.19.1 contains a missing authentication vulnerability that allows unauthenticated attackers t
CVE-2026-63101
2026-07-19 · HIGH
CVE-2026-57860: ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI, automatically loads and executes the MCP servers defined i
CVE-2026-57860
2026-07-19 · HIGH
CVE-2026-54496: ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primit
CVE-2026-54496
2026-07-19 · HIGH
CVE-2026-16228 - SourceCodester Class and Exam Timetabling System edit_schoolyr.php sql injection
CVE-2026-16228
2026-07-19 · HIGH
CVE-2026-16229 - itsourcecode Courier Management System index.php cross site scripting
CVE-2026-16229
2026-07-19 · HIGH
CVE-2026-16227 - SourceCodester Class and Exam Timetabling System edit_subject.php sql injection
CVE-2026-16227
2026-07-19 · HIGH
Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs
nday: CVE-2026-49176_LPE_POC: Local privilege-escalation proof of concept for the Windows WalletService vulnerability fixed in July 2026.
CVE-2026-49176
2026-07-19 · HIGH
CVE-2026-8297: Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics En
CVE-2026-8297
2026-07-19 · MEDIUM
Breaking into the industry
Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits
APEX_FRAMEWORK exploit
wp2shell_stock_chain exploit
Exploit for CVE-2026-60137 exploit
CVE-2026-60137
2026-07-19 · HIGH
Exploit for Unrestricted Upload of File with Dangerous Type in Templaza Astroid_Framework exploit
From 50 to 703: Expanding Unit 42's Gameograf Adware Chrome Extension Campaign
CVE-2026-43977: wger is a free, open-source workout and fitness manager. In versions prior to 2.6, any authenticated user can read anoth
CVE-2026-43977
2026-07-19 · HIGH
CVE-2026-39359: Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.0.0 through
CVE-2026-39359
2026-07-19 · HIGH
CVE-2026-43978: wger is a free, open-source workout and fitness manager. In versions prior to 2.6, a gym trainer can escalate their sess
CVE-2026-43978
2026-07-18 · MEDIUM
Offering free OSINT assistance for small research tasks
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
Trump Has Systematically Dismantled Election Security Efforts. Here’s How.
New Spirals Ransomware Uses IIS Web Shell and PsExec to Encrypt IT Firm in Under 24 Hours
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core
CVE-2026-63030CVE-2026-60137
2026-07-18 · MEDIUM
What Open Source Cyber Security Apps are Your Team Self-Hosting?
White House launches AI-driven "Gold Eagle" clearinghouse to centralize public-private vulnerability coordination
ClickLock macOS stealer relies on a pasted Terminal command, not an exploit
Prompty: Arbitrary file read via file reference expansion
CVE-2026-53598CVE-2026-53598
2026-07-17 · MEDIUM
Openwrt pre-auth remote root exploit
CVE lookup that shows the actual fix (KB / package version / Apple train), plus a no-key API. Built partly because NVD's API keeps flaking out
CVE-2021-44228
CISA KEV
2026-07-17 · HIGH
Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy
CVE-2026-50148: Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.2
CVE-2026-50148
2026-07-17 · MEDIUM
can anyone help me solve exploit development challenge.
In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint
CVE-2026-50147: Metabase is an open-source business intelligence and embedded analytics tool. From 1.57.0 until 1.57.19.1, 1.58.14.1, 1.
CVE-2026-50147
2026-07-17 · HIGH
Ransomware attack halts Coca-Colas Fairlife US milk production
Gold Eagle Clearinghouse Targets Security Gap, But How Is Unclear
AI security project: PromptShield
Cyberattack halts U.S. production at Coca-Cola’s fairlife dairy business
Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive
Beacon Security Raises $13 Million for Security Data Platform
E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants
Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday
New Windows LegacyHive zero-day gives hackers admin privileges
My Test Trainer - Website Launch
Is MITRE is biased towards the historically what techniques are used rather then what's being used actively?
Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei
Windows Server 2022 reach end of mainstream support in 90 days
US charges two over laundering $43 million from investment fraud
Risk Ledger Raises $32 Million in Series B Funding
If you've given an AI agent real credentials, how are you scoping what it can reach?
Fresh SharePoint Vulnerability Exploited Soon After Disclosure
CISA urges immediate action on actively exploited Fortinet flaws
Published research article on IEEE about supply chain attacks and preventive security measures
Coca-Cola Suspends US Fairlife Production Due to Ransomware Attack
deberíaa pagar por esto?
Is ast_grep_cli 0.44.1 on PyPI compromised? Windows Defender detected Trojan:Win64/Lazy!MTB during install
Alerts on Server Loopback Traffic?
Advice on Detection Engineering
The Invisible Guardians of the Internet: An Introduction to Content Moderation & Trust & Safety
cybersec VS data science
ISC Stormcast For Friday, July 17th, 2026 https://isc.sans.edu/podcastdetail/10012, (Fri, Jul 17th)
Beta BIOS/UEFI
New ClickLock macOS malware traps users into revealing login password
Coca-Cola says Fairlife ransomware attack halts US dairy production
ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users
CVE-2026-54077CVE-2026-54077
2026-07-16 · HIGH
ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read
MCP Python SDK: WebSocket server transport does not support Host/Origin validation
CVE-2026-59950CVE-2026-59950
2026-07-16 · HIGH
ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)
ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js
ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization
ArcadeDB: Read-only users can mutate database schema (incomplete fix of CVE-2026-44221)
CVE-2026-54076CVE-2026-54076
2026-07-16 · HIGH
Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection
CVE-2026-55578CVE-2026-55578
2026-07-16 · HIGH
MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal
CVE-2026-52869CVE-2026-52869
2026-07-16 · HIGH
Pheditor has an authenticated terminal command whitelist bypass
CVE-2026-54540CVE-2026-54540
2026-07-16 · HIGH
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode
CVE-2026-53714CVE-2026-53714
2026-07-16 · HIGH
MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
CVE-2026-52870CVE-2026-52870
2026-07-16 · HIGH
Nuclio: Unsanitized runtimeAttributes.repositories injected into Groovy build.gradle leads to build-time RCE
CVE-2026-52833CVE-2026-52833
2026-07-16 · MEDIUM
New OkoBot framework deploys 20 payloads to steal data, crypto
Claude Chrome extension flaw lets malicious extensions trigger AI actions
Apple Sued Over Reported 'Hide My Email' Flaw
New Exploitable BOLA Found in Immich (self-hosted media platform)
With AI, Your Entire Internet History is Attributable to you Personally
Teen hackers jailed after live-streaming the 16-hour TfL attack
Open-sourced my Claude Code team kit for secure multi-agent development and governance. Feedback welcome.
This might be a dumb question
How to Measure the Revenue Impact of Security Hardening Projects with a Simple Formula
ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories
SOC Analyst platforms and lacks
Legacy Systems, Real-World Impacts: The Reality of OT Security
Preciso de ajuda
[$13337] Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking
No Shark is Safe: Millions of Shark Vacuums are Vulnerable to RCE
Top 10 Data Center and AI Infrastructure Security Risks
23andMe to pay $18 million in new genetics data breach settlement
Two Scattered Spider Hackers Sentenced to Jail in UK
The British teenager who hacked into Vegas casinos from an east London flat
‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing
AI Data Centers Are Being Built Faster Than They Can Be Secured
Critical NGINX vulnerability discovered: hackers can attempt to crash servers or even gain code execution
Proof of concept for CVE-2026-58635 LPE in Windows Braille Narrator service
CVE-2026-58635
2026-07-16 · MEDIUM
Scattered Spider members behind TfL hack get five years in prison
Oak Emerges From Stealth Mode With $60 Million in Funding
Files relating to India’s largest nuclear power plant Kudankulam exposed in data breach
Splunk, Zoom Patch Critical Vulnerabilities
Please Stop Making Me Opt Out of AI
CISA orders feds to patch actively exploited Oracle flaw by Saturday
Russian hackers trojanize WebEx, Zoom apps to push Starland malware
Moroccan intelligence insider reveals widespread use of Pegasus hacking software | Morocco
Learning DevSecOps - Week 2
When Inclusive Language ends in phishing
F5 Patches Multiple NGINX, BIG-IP Vulnerabilities
China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans
Old UEFI Shims Expose Systems to Secure Boot Bypass
AI Agent for reconaissasion
Police Disrupt a €140M Cyber Fraud Ring in Spain
Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day
Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities
ASUS bsitf.sys (CVE-2026-13585): Arbitrary Physical Memory Mapping via Unvalidated IOCTL
CVE-2026-13585
2026-07-16 · MEDIUM
i get stuck
CVE-2026-56877 - Skillable SCORM userId authorisation bypass
CVE-2026-56877
2026-07-16 · HIGH
[NotCVE-2026-0001] Cloudflare Universal SSL CAA augmentation weakens RFC 8657 account binding — CVE-2026-14440 assigned 163 days after public no-CVE disclosure
CVE-2026-0001CVE-2026-14440
2026-07-16 · MEDIUM
Subject: Advisory Submission: EZ Game Booster - Cleartext Storage of Sensitive Credentials (CWE-312)
ISC Stormcast For Thursday, July 16th, 2026 https://isc.sans.edu/podcastdetail/10010, (Thu, Jul 16th)
Greene County, Georgia, cybersecurity incident disrupts services
dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS
CVE-2026-50274CVE-2026-50274
2026-07-15 · HIGH
dd-trace-rb: Improper parsing of W3C baggage headers may lead to DoS
CVE-2026-50276CVE-2026-50276
2026-07-15 · HIGH
Pomerium Pre-Auth Memory Exhaustion via Unbounded zstd Decompression in HPKE Callback
CVE-2026-50285CVE-2026-50285
2026-07-15 · HIGH
systeminformation: OS command injection in networkInterfaces() via interfaces(5) source-directive path on Linux
CVE-2026-50289CVE-2026-50289
2026-07-15 · HIGH
@andrea9293/mcp-documentation-server: Web UI API binds to all interfaces without authentication by default
CVE-2026-54504CVE-2026-54504
2026-07-15 · HIGH
dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS
CVE-2026-50271CVE-2026-50271
2026-07-15 · HIGH
dd-trace-js: Improper parsing of W3C baggage headers may lead to DoS
CVE-2026-50272CVE-2026-50272
2026-07-15 · HIGH
dd-trace-dotnet: Improper parsing of W3C baggage headers may lead to DoS
CVE-2026-50273CVE-2026-50273
2026-07-15 · HIGH
dd-trace-java: Improper parsing of W3C baggage headers may lead to DoS
CVE-2026-50270CVE-2026-50270
2026-07-15 · HIGH
ViewComponent: around_render HTML-Safety Bypass
CVE-2026-54498CVE-2026-54498
2026-07-15 · HIGH
django-haystack: Remote Code Execution via `eval()` in Elasticsearch Result Deserialization
Dutch police bust investment fraud ring stealing over €100 million
TensorZero Gateway: Arbitrary file read and SSRF in internal object storage endpoint
CVE-2026-54457CVE-2026-54457
2026-07-15 · HIGH
obsidian-local-rest-api: Authenticated path traversal via URL-encoded %2F in /vault/{path} — arbitrary host file read/write/delete
Zoom warns of critical account takeover vulnerability
TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development
Google Gemini CLI abused as a hacking agent, malware botnet operator
Getting mitre techniques a customer raw detection rule covers
MantisBT: Stored XSS in print_all_bug_page_word.php
CVE-2026-62944CVE-2026-62944
2026-07-15 · MEDIUM
Guten Tag, Bonjour, Hola to Our European Cyber Defenders!
Koel: Incomplete fix for CVE-2026-47260 — systemic SSRF in podcast & radio fetch paths
CVE-2026-54491CVE-2026-54491
2026-07-15 · HIGH
Protobuf: Unbounded recursion depth in embedded-message decoding
CVE-2026-54451CVE-2026-54451
2026-07-15 · HIGH
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
CVE-2026-54447CVE-2026-54447
2026-07-15 · HIGH
LangBot: Authenticated RCE Via MCP Configuration
CVE-2026-54449CVE-2026-54449
2026-07-15 · MEDIUM
Is 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI Strife
Koel: Authenticated Full-Read SSRF via Subsonic Internet Radio Stations
CVE-2026-54493CVE-2026-54493
2026-07-15 · HIGH
MantisBT: SQL Injection via history_order Configuration Value
CVE-2026-47142CVE-2026-47142
2026-07-15 · HIGH
MantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.php
CVE-2026-49273CVE-2026-49273
2026-07-15 · MEDIUM
AsyncAPI npm packages infected with credential-stealing malware
File-Binding, Process-Binding, and Silo-Binding - new process impersonation techniques for EDR evasion
Unpatched Cursor Vulnerability Exposes Users to Code Execution
Sophos: The State of Ransomware 2026: Payments are dropping but encryption is climbing
Coverage-First SOC: why domains and telemetry matter as much as threat intel
Runtime detection for ECS/EC2, what are people actually using?
CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities
KQL Queries for new Chaotic Eclipse Zero day 'Legacy Hive'
Virtual Event Today: Cloud & Data Security Summit
Windows Bind Link Attacks Can Hide Malware From EDR Tools
2-Click Cursor Exploit Enables Dev Environment Takeover
US Charges Russian Individuals and Firms for Running Cybercrime Services
Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow
Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution
White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative
CISA warns admins to patch actively exploited SharePoint flaws
Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption
Need help reverse engineering an Android APK used in a UPI fraud
HN Security - My Semgrep C/C++ ruleset is ready for prime time again
The Memory Heist - How I tricked Claude into leaking your deepest, darkest secrets
Microsoft: Some Dell PCs shut down after recent Windows updates
(More) Unauthenticated Arbitrary Code Execution in ServiceNow
Nigeria Deepens Cybersecurity Efforts as Cybercriminals See More Profits
US charges alleged operators of Russian bulletproof hosting service
Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates
Recent DShield SIEM Update, (Tue, Jul 14th)
ISC Stormcast For Wednesday, July 15th, 2026 https://isc.sans.edu/podcastdetail/10008, (Wed, Jul 15th)
ISC2 Board of Directors Election is open.
Hochul halts new data center approvals via executive order
SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
CVE-2026-15409CVE-2026-15410
2026-07-14 · HIGH
NetLicensing-MCP: Unauthenticated Use of Server-Side NetLicensing API Key in HTTP Mode
CVE-2026-54446CVE-2026-54446
2026-07-14 · MEDIUM
Spanish Police take down €140 million cyber fraud ring, arrest four
Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder
CVE-2026-44891CVE-2026-44891
2026-07-14 · HIGH
nebula-mesh: Operator session tokens stored in plaintext in the database
CVE-2026-53603CVE-2026-53603
2026-07-14 · HIGH
Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode
CVE-2026-54629CVE-2026-54629
2026-07-14 · HIGH
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`
Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend
CVE-2026-61549CVE-2026-61549
2026-07-14 · HIGH
nebula-mesh: Certificate revocation is never enforced at the mesh
CVE-2026-61699CVE-2026-61699
2026-07-14 · HIGH
nebula-mesh: CA private key not zeroized on web mobile-bundle error paths
CVE-2026-53604CVE-2026-53604
2026-07-14 · HIGH
Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode
CVE-2026-54628CVE-2026-54628
2026-07-14 · HIGH
yutu: Arbitrary File Write via MCP `caption-download` Tool
CVE-2026-50158CVE-2026-50158
2026-07-14 · HIGH
EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField
CVE-2026-54087CVE-2026-54087
2026-07-14 · HIGH
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser
CVE-2026-54448CVE-2026-54448
2026-07-14 · HIGH
Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware
TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services
Microsoft Patches a Record 570 Security Flaws
Nearly 300 GitHub repos pose as legit software to push malware
Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th)
Microsoft releases Windows 10 KB5099539 extended security update
LegacyHive : Windows user profile service arbitrary hive load elevation of privileges vulnerability
Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation
CVE-2026-50141CVE-2026-50141
2026-07-14 · MEDIUM
🇨🇳 Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries
Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days
Hoverfly: Process Crash via Concurrent Map Write Race Condition in Diff Mode
CVE-2026-50013CVE-2026-50013
2026-07-14 · HIGH
MKP: Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines` Causes Memory Exhaustion
CVE-2026-50125CVE-2026-50125
2026-07-14 · HIGH
Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges
CVE-2026-50131CVE-2026-50131
2026-07-14 · MEDIUM