July 2026

Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution 2026-07-19 at 23:42 By F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and […]

Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution Read More »

Saylor turns up heat with ‘110 reasons’ why BIP-110 is a bad idea

Saylor turns up heat with ‘110 reasons’ why BIP-110 is a bad idea 2026-07-19 at 19:37 By Cointelegraph by Robert Lakin The man in control of the biggest Bitcoin corporate treasury said he shares the objectives but disagrees about the remedy detailed in the proposed temporary fork. This article is an excerpt from Cointelegraph.com News

Saylor turns up heat with ‘110 reasons’ why BIP-110 is a bad idea Read More »

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access 2026-07-19 at 17:39 By A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026. Cybersecurity company Volexity is tracking the activity under

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access Read More »

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware 2026-07-19 at 16:30 By Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC-0145,

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware Read More »

South Korean regulator begins sanctions process against Dunamu: Report

South Korean regulator begins sanctions process against Dunamu: Report 2026-07-19 at 13:17 By Cointelegraph by Zoltan Vardai The proceedings come as South Korea’s Virtual Asset User Protection Act lacks explicit sanctions provisions for hacking and computer system incidents, leaving the scope of penalties uncertain. This article is an excerpt from Cointelegraph.com News View Original Source

South Korean regulator begins sanctions process against Dunamu: Report Read More »

Electronic Transactions Association CEO Expecting More Partnerships with Bitcoin Startups

Electronic Transactions Association CEO Expecting More Partnerships with Bitcoin Startups 2026-07-19 at 12:16 By Cointelegraph by Diana Ngo Electronic Transactions Association (ETA) CEO, Jason Oxman, indicated that members of his organization might start recognizing Bitcoin’s disruptive potential, suggesting that this might lead to more partnerships between traditional electronic payment providers and Bitcoin startups. This article

Electronic Transactions Association CEO Expecting More Partnerships with Bitcoin Startups Read More »

Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs

Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs 2026-07-19 at 10:09 By Anamarija Pogorelec Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Two new high severity WordPress vulnerabilities, patch immediately! The 7.0.2 WordPress security release addresses one critical and one high severity security

Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs Read More »

Two new high severity WordPress vulnerabilities, patch immediately!

Two new high severity WordPress vulnerabilities, patch immediately! 2026-07-18 at 17:57 By Help Net Security The 7.0.2 WordPress security release addresses one critical and one high severity security issue. The vulnerabilities reported to the WordPress security team include: CVE-2026-60137 – A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo CVE-2026-60137

Two new high severity WordPress vulnerabilities, patch immediately! Read More »

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code 2026-07-18 at 16:16 By Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story below reflects all of it. An anonymous HTTP request can run

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code Read More »

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests 2026-07-18 at 16:16 By Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests Read More »

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT 2026-07-18 at 16:16 By Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT Read More »

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens 2026-07-18 at 16:16 By A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator’s own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI,

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens Read More »

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft 2026-07-18 at 16:16 By Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group),

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft Read More »

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code 2026-07-18 at 02:12 By An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until Friday, when WordPress shipped 6.9.5 and 7.0.2

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code Read More »

FTX to distribute $900M to creditors in fifth payment round

FTX to distribute $900M to creditors in fifth payment round 2026-07-18 at 00:40 By Cointelegraph by Turner Wright The FTX Recovery Trust and company have distributed about $10 billion since the exchange filed for bankruptcy in November 2022, leaving users cut off from their funds. This article is an excerpt from Cointelegraph.com News View Original

FTX to distribute $900M to creditors in fifth payment round Read More »

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests 2026-07-17 at 23:20 By Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests Read More »

Galaxy lands 15-year Texas Tech stadium naming rights deal

Galaxy lands 15-year Texas Tech stadium naming rights deal 2026-07-17 at 23:03 By Cointelegraph by Nate Kostar Galaxy Digital will rename Texas Tech’s football stadium under a 15-year agreement, expanding its West Texas presence as the state attracts growing crypto investment. This article is an excerpt from Cointelegraph.com News View Original Source

Galaxy lands 15-year Texas Tech stadium naming rights deal Read More »

Consensys unknowingly outsourced developer work to North Korean

Consensys unknowingly outsourced developer work to North Korean 2026-07-17 at 22:33 By Cointelegraph by Turner Wright Through an introduction with a “reputable third-party service provider,“ the company took on a developer who, as part of an investigation, was revealed to be tied to North Korea. This article is an excerpt from Cointelegraph.com News View Original

Consensys unknowingly outsourced developer work to North Korean Read More »

Scroll to Top