Uncategorized

iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days

iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days 2026-07-13 at 08:36 By The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation in the wild. The vulnerabilities, both rated 10.0

iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days Read More »

Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install

Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install 2026-07-11 at 20:59 By Version 8.14.0 of the jscrambler npm package shipped with a malicious preinstall hook that silently drops and runs a native infostealer during installation, one build each for Windows, macOS, and Linux. Published on July 11, 2026, it needs no import and no CLI call. Installing

Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install Read More »

Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns

Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns 2026-07-11 at 20:49 By Cybersecurity researchers have disclosed details of sustained cyber espionage activity against several Pakistani law enforcement organizations undertaken by suspected China- and India-aligned threat actors between February 2024 and April 2026. “At Balochistan Police, the compromised assets included servers hosting web applications that

Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns Read More »

Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions

Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions 2026-07-11 at 14:36 By Zimbra is urging customers to apply updates to address a critical security vulnerability impacting the Classic Web Client that could result in arbitrary code execution. The vulnerability has been described as a case of stored cross-site scripting (XSS)

Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions Read More »

Apple sues OpenAI for trade theft, sending shock waves through Silicon Valley

Apple sues OpenAI for trade theft, sending shock waves through Silicon Valley 2026-07-10 at 23:50 By Ariel Zilber Apple sued OpenAI and two ex-employees in a bombshell suit accusing them of misappropriation of the consumer tech giant’s trade secrets. This article is an excerpt from Latest Technology News | New York Post View Original Source

Apple sues OpenAI for trade theft, sending shock waves through Silicon Valley Read More »

URGENT – Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat

URGENT – Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat 2026-07-10 at 23:49 By Progress Software has told ShareFile customers to shut down the Windows servers running their Storage Zone Controllers, confirming to The Hacker News that it is responding to a “credible external security threat.” The company has temporarily

URGENT – Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat Read More »

Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot

Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot 2026-07-10 at 20:42 By Researchers at firmware security firm Binarly have found six new flaws in U-Boot, the small program that starts up hardware as varied as home routers, smart cameras, and the management chips inside data-center servers. Four of the bugs

Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot Read More »

Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages

Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages 2026-07-10 at 20:29 By Unknown threat actors compromised the Injective Labs SDK project’s GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases. The compromised version, @injectivelabs/[email protected], came embedded with fake telemetry functionality

Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages Read More »

European Union warns Meta to change ‘addictive’ Facebook, Instagram features — or get big fines

European Union warns Meta to change ‘addictive’ Facebook, Instagram features — or get big fines 2026-07-10 at 19:07 By Thomas Barrabi European regulators told Meta on Friday to make big changes to Facebook and Instagram’s “addictive” features — or face steep fines. This article is an excerpt from Latest Technology News | New York Post

European Union warns Meta to change ‘addictive’ Facebook, Instagram features — or get big fines Read More »

Laser Attack Resets Tangem Wallet Passwords on Cards That Can’t Be Patched

Laser Attack Resets Tangem Wallet Passwords on Cards That Can’t Be Patched 2026-07-10 at 17:51 By Researchers at Ledger’s Donjon security team have shown that a precisely timed laser pulse, aimed at the chip inside a Tangem crypto wallet card, can reset the card’s password to anything the attacker picks. No old password. No backup card. Once

Laser Attack Resets Tangem Wallet Passwords on Cards That Can’t Be Patched Read More »

Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws

Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws 2026-07-10 at 17:19 By Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, could enable credential theft, privilege escalation, and arbitrary code execution on the host. A brief description of the high-severity vulnerabilities is as

Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws Read More »

New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic

New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic 2026-07-10 at 16:15 By The China-linked cybercrime group known as Silver Fox has been attributed to a new Rust-based remote access trojan (RAR) called MODBEACON. Chinese cybersecurity company QiAnXin said that while the threat cluster may appear like a low-sophistication, high-activity operation that propagates malware

New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic Read More »

Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking

Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking 2026-07-10 at 15:17 By Researchers ran 281 of the most popular free VPN apps on the Google Play Store through a new testing system and found that many fail at the basics people install a VPN for, i.e., keeping their traffic

Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking Read More »

Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access

Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access 2026-07-10 at 15:17 By A threat actor has been targeting organizations spanning multiple sectors with voice-based fake security requests that prompt Microsoft 365 users to enroll a new Entra passkey with an aim to carry out data extortion attacks. The threat actor, tracked

Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access Read More »

Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers

Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers 2026-07-10 at 14:47 By A single wrong variable on one line in XQUIC, Alibaba’s QUIC and HTTP/3 library, lets any remote client crash the server with a short burst of completely legal traffic. There is no patch. FoxIO researcher Sébastien Féry disclosed the flaw on

Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers Read More »

From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale

From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale 2026-07-10 at 14:39 By Most enterprises assume their asset inventory is close enough to accurate. The evidence suggests otherwise. According to a survey of over 600 security leaders in the 2026 Axonius Actionability Report, only 45% of organizations consolidate their asset

From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale Read More »

Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites

Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites 2026-07-10 at 14:30 By A cybercrime crew left one of its own servers wide open on the internet for three weeks, and it exposed the operation’s inner workings: the hacking tools, the activity logs, and target lists naming more than 1.4 million websites. Far fewer

Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites Read More »

Scroll to Top