Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
Swati KhandelwalJul 25, 2026Vulnerability / Application Security Security researchers at depthfirst published working exploit code on July 24 for a GitLab...
Category Added in a WPeMatico Campaign
Swati KhandelwalJul 25, 2026Vulnerability / Application Security Security researchers at depthfirst published working exploit code on July 24 for a GitLab...
For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers...
Ravie LakshmananJul 25, 2026Vulnerability / Ransomware Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest)...
The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to...
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found...
Swati KhandelwalJul 24, 2026Vulnerability / Enterprise Security Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that...
Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single phishing link...
A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITYSYSTEM on Microsoft's production image-processing workers, and as...
AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we've collectively...
Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before...
Ravie LakshmananJul 24, 2026Threat Intelligence / Browser Security The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced...
Swati KhandelwalJul 24, 2026Web Security / Vulnerability Eight security flaws in NodeBB went public on Wednesday, along with the code...
Swati KhandelwalJul 24, 2026Vulnerability / Database Security Redis shipped seven security releases on July 23 after researchers published authenticated RCE...
A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload...
Ravie LakshmananJul 23, 2026Hacking News / Cybersecurity News Most of this week's trouble came dressed as something useful. A package...