XSS2Shell (CVE-2026-64638): Patch WordPress Now
XSS2Shell (CVE-2026-64638): Patch WordPress Now A new WordPress Core vulnerability chain called XSS2Shell turns a login page XSS bug into a much more serious risk for exposed WordPress sites. The issu...
Cracking Kynx: The Stealer Hunting for Your Wallets, Games, and AI Too...
Cracking Kynx: The Stealer Hunting for Your Wallets, Games, and AI Tools Kynx is a new Malware-as-a-Service infostealer, built in C++ with AI assistance and promoted on a Turkish game cheating forum. ...
Cisco Catalyst SD-WAN and IOS XE: Critical Flaws Fixed
Cisco Catalyst SD-WAN and IOS XE: Critical Flaws Fixed Cisco published a new set of security advisories, addressing vulnerabilities across Catalyst SD-WAN, IOS XE, Cisco Integrated Management Controll...
Snowflake Hacker Pleads Guilty, Faces 32 Years
Snowflake Hacker Pleads Guilty, Faces 32 Years Snowflake hacker Connor Riley Moucka pleaded guilty on August 5, 2026, in the U.S. District Court for the Western District of Washington, admitting to co...
Formula 1 Phishing Campaign & Kit Analysis
Formula 1 Phishing Campaign & Kit Analysis SOCRadar Threat Research Unit (STRU) has identified and analyzed a sophisticated, multi-stage phishing campaign that exploits the high-intensity demand f...
Why Was Telegram Removed From the App Store?
Why Was Telegram Removed From the App Store? [Update] August 5, 2026: Durov Claims “Takedown Extortionist” Triggered App Store Removal Telegram briefly disappeared from the App Store worldwide on Mond...
CVE-2026-48449: Adobe Campaign Classic RCE
CVE-2026-48449: Adobe Campaign Classic RCE Adobe Campaign Classic is affected by CVE-2026-48449, a critical incorrect authorization vulnerability allowing Remote Code Execution (RCE). With a maximum s...
Minnesota Water Cyberattack: FBI and EPA Warn of PLC Attacks Across Se...
Minnesota Water Cyberattack: FBI and EPA Warn of PLC Attacks Across Seven States Key Takeaways A coordinated cyberattack hit operational technology at more than 30 Minnesota community water systems o...
CVE-2026-20316: Cisco Secure FMC Static-Credential Flaw Exploited in Z...
CVE-2026-20316: Cisco Secure FMC Static-Credential Flaw Exploited in Zero-Day Attacks Cisco has confirmed that CVE-2026-20316 is actively exploited against Cisco Secure Firewall Management Center (FMC...
Critical VMware vCenter and ESX Flaws Fixed
Critical VMware vCenter and ESX Flaws Fixed Broadcom has released a new VMware advisory, VMSA-2026-0006, addressing five vulnerabilities in VMware vCenter, ESX, Workstation, Fusion, and related VMware...
Russia Charges Pavel Durov: What It Means for Cybercrime
Russia Charges Pavel Durov: What It Means for Cybercrime On July 29, 2026, Russia’s Federal Security Service charged Telegram founder Pavel Durov with aiding terrorist activity and placed him on an in...
Operation Talked: A Russia-Linked Cyber Espionage Campaign Targeting U...
Operation Talked: A Russia-Linked Cyber Espionage Campaign Targeting Ukraine’s Defense Industry TL;DR: OPERATION TALKED is an ongoing Russia-linked espionage campaign, exposed after the actor left the...
Meccha Chameleon Discord Server Hijacked After Steam Workshop Malware ...
Meccha Chameleon Discord Server Hijacked After Steam Workshop Malware Incident The compromise removed official staff from the community server and turned a trusted communication channel into a potenti...
CVE-2025-66376: Russian APT Exploits Zimbra Zero-Day
CVE-2025-66376: Russian APT Exploits Zimbra Zero-Day CVE-2025-66376 is a stored cross-site scripting vulnerability in the Classic UI of Zimbra Collaboration Suite, creating a path to mailbox theft and...
SharedRoot: Sandbox Escape in Claude Cowork
SharedRoot: Sandbox Escape in Claude Cowork SharedRoot is the name researchers gave to a sandbox-escape chain affecting the local execution mode of Claude Cowork on macOS. The chain uses CVE-2026-4633...
Iranian Hackers Broaden PLC Attacks on US Critical Infrastructure
Iranian Hackers Broaden PLC Attacks on US Critical Infrastructure On July 22, 2026, seven US government agencies updated joint Cybersecurity Advisory AA26-097A, first published in April, warning that ...
Oracle July 2026 CPU: 1,449 Patches, 10 Score Max
Oracle July 2026 CPU: 1,449 Patches, 10 Score Max Oracle July 2026 Critical Patch Update ships 1,449 patches covering 1,434 CVEs across 334 products in 32 product families, making it the largest quart...
Adobe Acrobat WhatsApp Flaw “HermeticReader”
Adobe Acrobat WhatsApp Flaw “HermeticReader” Adobe and WhatsApp have rolled out a new way to handle PDF files without ever leaving a chat, and the timing puts a spotlight on a vulnerability that Adobe...
WhatsApp Usernames Explained: Privacy Gains and Scam Risks
WhatsApp Usernames Explained: Privacy Gains and Scam Risks How WhatsApp’s shift from phone numbers to usernames changes privacy for users, and the brand and executive impersonation surface it opens fo...
CVE-2026-50522 PoC Fuels SharePoint Attacks
CVE-2026-50522 PoC Fuels SharePoint Attacks Attackers are exploiting CVE-2026-50522, a critical Microsoft SharePoint Server vulnerability, after public proof-of-concept (PoC) exploit code became avail...
