Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
Swati KhandelwalJul 27, 2026Vulnerability / Website Security Public exploit details released on July 27 show how an unauthenticated request can...
Category Added in a WPeMatico Campaign
Swati KhandelwalJul 27, 2026Vulnerability / Website Security Public exploit details released on July 27 show how an unauthenticated request can...
Ravie LakshmananJul 27, 2026Cybersecurity / Hacking Monday starts with the usual promise that everything is under control. Then the logs...
Swati KhandelwalJul 27, 2026Vulnerability / Enterprise Security n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow...
Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs "secure document" lures to deliver legitimate remote monitoring and...
The China-linked cybercrime group behind the use of income tax-related phishing lures targeting Indian taxpayers, tax professionals, and corporate finance...
Ravie LakshmananJul 27, 2026Cyber Attack / Threat Intelligence Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor...
Ravie LakshmananJul 27, 2026Software Supply Chain / DevSecOps GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool...
A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime...
Swati KhandelwalJul 25, 2026Vulnerability / Application Security Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in...
Swati KhandelwalJul 25, 2026Vulnerability / Application Security Security researchers at depthfirst published working exploit code on July 24 for a GitLab...
For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers...
Ravie LakshmananJul 25, 2026Vulnerability / Ransomware Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest)...
The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to...
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found...
Swati KhandelwalJul 24, 2026Vulnerability / Enterprise Security Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that...