TL;DR: A public proof-of-concept now targets CVE-2026-42530, an NGINX HTTP/3 RCE flaw rated CVSS 9.2. The use-after-free...
News
TL;DR: A public proof-of-concept now targets CVE-2026-66373, a Redis RCE flaw in the RESTORE command. The double-free...
At a glance Actor Unnamed operator; ReliaQuest notes tradecraft similar to APT28 (Fancy Bear, Forest Blizzard) but...
At a glance Field Detail Actor / group BlueNoroff (TA444), a subgroup of North Korea’s Lazarus Group...
OpenAI recently commenced pilot testing for a novel “Sign in with ChatGPT” authentication feature across select partner...
Google has officially distributed invitations for its annual hardware launch event, confirming the debut of the next-generation...
TL;DR GitLab has shipped a new patch release for self-managed installs. Versions 19.2.1, 19.1.3, and 19.0.5 fix...
TL;DR Ruby on Rails has patched a critical Rails Active Storage flaw. Tracked as CVE-2026-66066 and rated...
TL;DR Google shipped a large Chrome security update on the Stable channel. It fixes 370 vulnerabilities, including...
Google has officially unveiled an upgrade for its native Gemini application on the macOS platform. Effective immediately,...
At a glance Malware family Copybara (Android RAT) Operators Not attributed; kit uses Portuguese-language identifiers Targets N26...
TL;DR Cisco is warning about a Cisco FMC vulnerability under active attack. Tracked as CVE-2026-20316, it lets...
TL;DR Node.js shipped fixes for 11 vulnerabilities on 29 July 2026. Three are rated high severity, and...
TL;DR CISA published ICS advisory ICSA-26-204-01 on July 23, 2026. It covers three flaws in Johnson Controls...
TL;DR OpenDJ 5.1.2 fixes four security flaws in the open-source LDAP directory server. The two most severe...
TL;DR Researchers have published full technical details and working proof-of-concept code for Certighost, tracked as CVE-2026-54121. The...
TL;DR A researcher known as Pixis has published full details and proof-of-concept code for CVE-2026-50502. The flaw...
At a glance Actor TA488 (Void Blizzard / Laundry Bear), Russia-aligned Activity Half-click XSS exploit of Outlook...
TL;DR Broadcom released patches for multiple critical flaws in VMware products. The most severe issue is a...
At a Glance Malware family TrickBot (modular Windows banking trojan and loader) Threat actor Not attributed by...
TL;DR A critical Gitea RCE flaw now has public details and a proof-of-concept exploit. Tracked as CVE-2026-60004,...
At a Glance Malware family Lampion, a Brazilian banking trojan from the ChePro lineage Threat actor No...