A newly disclosed HTTP/2 DoS vulnerability affects several server implementations at once. A remote, unauthenticated attacker can...
News
At a Glance Actor or group TA488 (Void Blizzard, Laundry Bear) and TA458 (Operation RoundPress), both Russia-aligned...
TL;DR JetBrains fixed 18 vulnerabilities across GoLand, IntelliJ IDEA, PhpStorm, PyCharm, TeamCity, and WebStorm. Two IntelliJ IDEA...
The Apache Syncope project has patched two security flaws in its identity management platform. Both Apache Syncope...
TL;DR A security researcher has published full details and proof-of-concept code for a Foxit PDF Reader vulnerability....
TL;DR Vercel fixed three Next.js vulnerabilities, each rated CVSS 8.3. Two of them allow Server-Side Request Forgery,...
TL;DR CERT/CC published vulnerability note VU#326070 on July 16, 2026. It details an SGLang vulnerability, CVE-2026-14890, rated...
Raspberry Pi has introduced a new touchscreen to its official display range. Seven-inch and five-inch models arrived...
At a Glance Actor or group A vendor using the alias “Kontraktnik”; no real identity published Activity...
The transatlantic submarine cable Nuvem, financed and controlled by Google, is approaching full service. It principally joins...
The Microsoft-owned code repository, GitHub, recently published a blog post announcing a sweeping overhaul of its security...
Seqrite Labs recently identified a malware distribution campaign that abused the credibility of government institutions to increase...
Streamlining the Transition from iPhone At the recent Galaxy Unpacked event, Google unveiled a significantly upgraded and...
At a glance Actor / group Suspected Chinese-speaking APT group (low confidence) Activity type Cyberespionage using malicious...
At a glance Actor / group DoNot (APT-C-35); assessed by multiple vendors as India-aligned Activity type Targeted...
At a Glance Actor or group Unattributed threat actor; no group name published Activity type GitHub Actions...
TL;DR ISC released BIND 9.20.26 and 9.21.24 on July 22, 2026. The updates fix nine flaws in...
TL;DR Researchers disclosed four flaws in the Ninja Forms WordPress plugin, which runs on more than 600,000...
TL;DR Qualys disclosed RefluXFS on July 22, 2026. Tracked as CVE-2026-64600, it is a Linux kernel XFS...
TL;DR Check Point disclosed a SmartConsole authentication bypass on July 22, 2026. The flaw, CVE-2026-16232, is already...
TL;DR The Exim team published advisory EXIM-Security-2026-06-22.1 on July 22, 2026. It describes an Exim vulnerability that...