TL;DR Ruby on Rails has patched a critical Rails Active Storage flaw. Tracked as CVE-2026-66066 and rated...
News
TL;DR Google shipped a large Chrome security update on the Stable channel. It fixes 370 vulnerabilities, including...
Google has officially unveiled an upgrade for its native Gemini application on the macOS platform. Effective immediately,...
At a glance Malware family Copybara (Android RAT) Operators Not attributed; kit uses Portuguese-language identifiers Targets N26...
TL;DR Cisco is warning about a Cisco FMC vulnerability under active attack. Tracked as CVE-2026-20316, it lets...
TL;DR Node.js shipped fixes for 11 vulnerabilities on 29 July 2026. Three are rated high severity, and...
TL;DR CISA published ICS advisory ICSA-26-204-01 on July 23, 2026. It covers three flaws in Johnson Controls...
TL;DR OpenDJ 5.1.2 fixes four security flaws in the open-source LDAP directory server. The two most severe...
TL;DR Researchers have published full technical details and working proof-of-concept code for Certighost, tracked as CVE-2026-54121. The...
TL;DR A researcher known as Pixis has published full details and proof-of-concept code for CVE-2026-50502. The flaw...
At a glance Actor TA488 (Void Blizzard / Laundry Bear), Russia-aligned Activity Half-click XSS exploit of Outlook...
TL;DR Broadcom released patches for multiple critical flaws in VMware products. The most severe issue is a...
At a Glance Malware family TrickBot (modular Windows banking trojan and loader) Threat actor Not attributed by...
TL;DR A critical Gitea RCE flaw now has public details and a proof-of-concept exploit. Tracked as CVE-2026-60004,...
At a Glance Malware family Lampion, a Brazilian banking trojan from the ChePro lineage Threat actor No...
At a glance Malware family msaRAT, a Rust remote access trojan Threat actor Chaos ransomware group (confirmed...
The Model Context Protocol (MCP), spearheaded by Anthropic, recently launched its highly anticipated 2026-07-28 specification. The defining...
TL;DR Threat actors injected a critical backdoor into the Advanced Responsive Video Embedder plugin. This flaw tracks...
TL;DR Attackers are exploiting a SmartConsole authentication bypass in Check Point management servers. The flaw, CVE-2026-16232, lets...
TL;DR NVIDIA patched a critical NVIDIA BlueField vulnerability tracked as CVE-2026-65094. The VIRTIO-Net flaw scores a CVSS...
TL;DR IBM patched five IBM Aspera vulnerabilities across two products on July 20, 2026. They affect Aspera...
TL;DR A flaw in WordPress Coding Standards lets malicious PHP run code on the machine that lints...