Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
Ravie LakshmananJul 21, 2026Vulnerability / Web Security A third SharePoint Server flaw patched by Microsoft as part of its Patch...
Category Added in a WPeMatico Campaign
Ravie LakshmananJul 21, 2026Vulnerability / Web Security A third SharePoint Server flaw patched by Microsoft as part of its Patch...
Ravie LakshmananJul 21, 2026Vulnerability / Network Security Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS...
Ravie LakshmananJul 21, 2026Email Security / Vulnerability Zimbra has rolled out fixes to address multiple critical security issues, including a...
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI)...
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure...
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions...
Ravie LakshmananJul 20, 2026Cybersecurity / Hacking A single request should not be able to do this much. But this week,...
At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to...
The industry spent the initial months after Anthropic's April 7 Mythos reveal focused on volume. How many new CVEs would...
Swati KhandelwalJul 20, 2026Vulnerability / Endpoint Security Opening a crafted XZ archive in 7-Zip could let an attacker run code...
A solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's open-source Gemini CLI artificial...
Ravie LakshmananJul 20, 2026AI Security / Vulnerability In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that...
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems...
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow...
Ravie LakshmananJul 19, 2026Malware / Cyber Warfare Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to...