Uncategorized

Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw

Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw 2026-07-27 at 17:40 By Public exploit details released on July 27 show how an unauthenticated request can reach PHP’s eval() function inside vBulletin and execute code on an unpatched forum server. The attack requires no account, administrative access, or interaction from another user. SSD Secure […]

Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw Read More »

Nike unveils futuristic recovery slides that heat and massage tired feet

Nike unveils futuristic recovery slides that heat and massage tired feet 2026-07-27 at 17:24 By Rachel Sacks After launching the Hyperboot last year, Nike has partnered up with recovery tool brand Hyperice for another pair of footwear. This article is an excerpt from Latest Technology News | New York Post View Original Source

Nike unveils futuristic recovery slides that heat and massage tired feet Read More »

⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More

⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More 2026-07-27 at 17:10 By Monday starts with the usual promise that everything is under control. Then the logs wake up. This week, trusted tools crossed lines, old flaws found new work, exposed systems stayed exposed, and attackers kept hiding inside normal-looking

⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More Read More »

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update 2026-07-27 at 16:32 By Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs “secure document” lures to deliver legitimate remote monitoring and management (RMM) tools. “The victim was directed through compromised web infrastructure to a counterfeit Microsoft Store page claiming that Microsoft

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update Read More »

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process 2026-07-27 at 16:32 By n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform. Security Joes found the flaw while probing n8n’s February fix for CVE-2026-27577 for another

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process Read More »

Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware

Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware 2026-07-27 at 13:51 By The China-linked cybercrime group behind the use of income tax-related phishing lures targeting Indian taxpayers, tax professionals, and corporate finance teams has been observed using a sophisticated crypter service called Cruciferra. According to a new analysis by Proofpoint, Cruciferra has

Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware Read More »

TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments 2026-07-27 at 11:48 By Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Middle East. The intrusions have resulted in the deployment of previously unreported malware families dubbed TELESHIM, MIXEDKEY, and

TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments Read More »

GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption

GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption 2026-07-27 at 11:01 By GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool to wait at least three days after a release is published before opening a pull request. “The cooldown configuration option in the dependabot.yml still controls the behavior, though, so

GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption Read More »

Inside the influencer nightmare of being cloned for deepfake ads: ‘It’s you, but you know it’s not you’

Inside the influencer nightmare of being cloned for deepfake ads: ‘It’s you, but you know it’s not you’ 2026-07-26 at 17:00 By Michael Kaplan “It’s horrifying,” one influencer told The Post. This article is an excerpt from Latest Technology News | New York Post View Original Source

Inside the influencer nightmare of being cloned for deepfake ads: ‘It’s you, but you know it’s not you’ Read More »

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable 2026-07-25 at 21:48 By A malvertising operation dubbed SourTrade is making victims’ browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL. Confiant, which detailed the campaign

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable Read More »

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available 2026-07-25 at 15:52 By Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba’s JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process.

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available Read More »

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git 2026-07-25 at 11:34 By Security researcher Yuhang Wu at depthfirst has published a working proof-of-concept (PoC) exploit that executes commands as git on an unpatched self-managed GitLab 18.11.3 server. An ordinary authenticated user triggers it by committing two crafted Jupyter notebooks and requesting

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git Read More »

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery 2026-07-24 at 18:12 By The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware. “BlueNoroff has

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery Read More »

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller 2026-07-24 at 18:01 By Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. They codenamed the flaw Certighost. Because Domain Controller accounts

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller Read More »

AI billionaire who left wife for younger lover ordered to pay $645M in South Korea’s ‘divorce of the century’

AI billionaire who left wife for younger lover ordered to pay $645M in South Korea’s ‘divorce of the century’ 2026-07-24 at 17:25 By Ariel Zilber Chey Tae-won’s wealth, estimated at roughly $5 billion, had become the centerpiece of the courtroom fight after his ex-wife demanded half his fortune. This article is an excerpt from Latest

AI billionaire who left wife for younger lover ordered to pay $645M in South Korea’s ‘divorce of the century’ Read More »

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link 2026-07-24 at 14:53 By Cybersecurity researchers have disclosed a critical vulnerability in OpenAI’s ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim’s organization. The vulnerability has

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link Read More »

Scroll to Top