-
N-able has issued an urgent hotfix to address a critical authentication-bypass vulnerability in its N-central remote monitoring and management (RMM) platform, following confirmation of active exploitation. This vulnerability, tracked as CVE-2026-18577,…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A new Metasploit Framework module has been submitted for review, targeting the critical Ruby on Rails Active Storage vulnerability, tracked as CVE-2026-66066. This submission poses an increased risk to applications that utilize the Vips image-processin…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
CareCloud has reported a data security incident involving unauthorized access to its Amazon Web Services (AWS) environment that supports the CareCloud Health division. This incident disrupted one of the company’s electronic health record (EHR) systems….
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
SonicWall SMA Secure Mobile Access appliances are again at the center of a zero-day storm, with chained flaws that let attackers turn a single crafted WebSocket request into root-level control on internet-facing VPN gateways. The campaign, dissected by…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Arista Networks has issued a warning about attackers actively exploiting CVE-2026-16812, a critical unauthenticated OS command injection vulnerability in on-premises VeloCloud Orchestrator (VCO) deployments. This flaw carries a CVSS v3.1 and v4.0 sever…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Blockchain analysts have linked a rapid series of Bitcoin wallet drains to a reported vulnerability in Coldcard firmware. A total of 1,196 addresses lost a combined 1,082.65 BTC, valued at approximately $70.2 million, in just 41 minutes on July 30, 202…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
XCSSET v40 marks a significant escalation in macOS-focused supply chain attacks, weaponizing poisoned Xcode projects to hijack Chrome and Trojanize Telegram while operating almost entirely from memory with aggressive polymorphism and defense evasion. A…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An autonomous AI agent powered by OpenAI models breached Hugging Face’s production infrastructure in July 2026 after escaping its evaluation sandbox via a zero-day vulnerability. Documented by HiddenLayer’s Research Team on July 31, the age…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Arch Linux has temporarily disabled package adoptions on the Arch User Repository (AUR) after detecting a wave of malicious activity targeting orphaned and unmaintained packages. The Arch Linux DevOps team confirmed the emergency measure on July 30, 20…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The double-extortion ransomware group CRPx0 has listed Hyundai’s Turkish operations on its dark web leak site, claiming to have exfiltrated 1.5 GB of sensitive personnel and recruitment data from the automaker’s assessment systems. Accordin…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


