Microsoft SharePoint Server flaws are being actively exploited to gain remote code execution, install persistent web shells, and steal cryptographic keys from exposed systems. The attacks put on-premises SharePoint deployments at risk of data theft, network compromise, ransomware, and prolonged…
Category: Cyber Security News
Kimai Docker Flaw Lets Unauthenticated Attackers Forge Cookies and Take Over Accounts
Kimai users utilizing the official Docker image are strongly urged to update their installations following the disclosure of a critical vulnerability that could allow unauthenticated attackers to forge authentication cookies and potentially take over accounts, including super administrator accounts. This…
Public PoC released for Critical ServiceNow Sandbox RCE Vulnerability
ServiceNow has released security updates for a critical vulnerability in its AI platform after researchers published a proof of concept demonstrating pre-authentication remote code execution. The flaw, tracked as CVE-2026-6875, is a sandbox escape issue that could allow an unauthenticated…
GoldenEyeDog Hackers Group Behind DigiCert Breach that Hijacks Code-Signing Certificates
GoldenEyeDog, a Chinese cybercrime group linked to the Golden Gh0st malware family, is back in focus after an intrusion at DigiCert exposed the risks around code-signing certificates. The attackers used the access to intercept customer certificate activation codes and sign…
Threat Actors Allegedly Listed Starbucks Data on Hacker Forums
Starbucks has allegedly been listed on a cybercrime forum by a threat actor using the handle “anes2010,” who claims to be selling a database containing 176 million unique user records reportedly extracted in June 2026. Starbucks has not publicly confirmed…
North Korean Hackers Hide OTTERCOOKIE Malware in SVG Images to Backdoor Developers
North Korean-linked hackers are hiding OTTERCOOKIE-aligned malware inside ordinary SVG flag images, turning a familiar part of a web project into a concealed delivery channel. The operation targets software developers who believe they are completing a coding test for a…
U.S. Prosecutors Charge Russian Trio in Cybercrimes Causing More Than $62 Million in Losses
Federal prosecutors have charged three Russian nationals over infrastructure that allegedly enabled ransomware, malware, phishing, and other cyberattacks against organizations in the United States and abroad. The seven-year investigation links the activity to more than $62 million in victim losses…
15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and Achieve Remote Code Execution
A newly disclosed flaw tracked as CVE-2026-42533 affects nginx’s script engine and has been silently exploitable since March 2011, when the map directive gained regex support. Security researcher Stan Shaw reported the bug to F5 SIRT, which coordinated a fix…
Weekly Cyber Security Newsletter Bulletin – EY Breach, Wpzshell Exploit, Notepad++ Flaws +20 Stories
This week’s cybersecurity situation shows a clear reality: every part of technology, from identity systems to common productivity tools, can be hacked or compromised. Microsoft’s July Patch Tuesday alone addressed roughly 570 vulnerabilities, including two zero-days already being exploited in…
NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure
A sharp structural shift has been identified in the botnet landscape. Security researchers at XLab have uncovered NadMesh, a Go-based botnet that has been spreading rapidly since early July 2026. This malware marks a distinct evolution from opportunistic worm behavior…
Hugging Face Confirms AI-Driven Breach: Attackers used Autonomous Agents, defenders countered with AI
Hugging Face disclosed this week that it detected and contained a production infrastructure intrusion, driven end-to-end by an autonomous AI agent system, and defended against it using its own AI-based forensic analysis. The attackers exploited two code-execution flaws in Hugging…
New Spirals Ransomware Uses IIS Web Shell and PsExec to Encrypt IT Firm in Under 24 Hours
A previously unseen ransomware family dubbed “Spirals” struck an IT services company in South Asia in June 2026. Symantec’s Threat Hunter Team reports that the attackers moved from the initial breach to full network encryption in under 24 hours. The…
Citrix Secure Access and Endpoint Client for Windows Vulnerability Enables Privilege Escalation
Cloud Software Group has disclosed two security vulnerabilities affecting Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows, with one flaw allowing low-privileged attackers to gain full SYSTEM access on affected machines. The more severe issue,…
New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released
A critical pre-authentication remote code execution (RCE) vulnerability dubbed “wp2shell” has been discovered in WordPress Core, putting an estimated 500 million+ websites at risk of full takeover by unauthenticated attackers. Security researcher Adam Kues of Searchlight Cyber’s Assetnote research team…
OpenSSL “HollowByte” Vulnerability Lets Hackers Crash Servers With Just 11 Bytes
A newly disclosed vulnerability in OpenSSL, dubbed “HollowByte,” allows a remote, unauthenticated attacker to trigger a denial-of-service (DoS) condition using a malicious payload as small as 11 bytes. Discovered by the Okta Red Team, the flaw exploits how OpenSSL pre-allocates…
PentestCode – New AI Agent That Automates Penetration Testing with 18 Specialized Tools
A new open-source tool is bringing autonomous AI agents into offensive security workflows. PentestCode, a hard fork of OpenCode rebuilt specifically for penetration testing, runs security tools, analyzes their output, and makes tactical decisions all from a terminal interface, with…
EY Data Breach – Hackers Gain Access to IT Support System and Download Documents
Ernst & Young LLP (EY) is notifying clients that an unauthorized third party breached a support ticket platform used by its IT staff, downloading documents containing client tax data during a roughly two-week window this spring. The Big Four accounting…
Ransomware Attack on Coca-Cola-Owned Fairlife Halts Production Across the United States
Coca-Cola has reported a ransomware attack affecting its dairy subsidiary, Fairlife, resulting in a temporary shutdown of production operations across the United States. This incident was disclosed in a Form 8-K filing submitted to the U.S. Securities and Exchange Commission…
AWS Cost Explorer Bug Shows Trillion-Dollar Billing Estimates
AWS customers worldwide were startled after the AWS Billing and Cost Management Console and Cost Explorer began displaying extraordinarily high projected cloud costs. Some organizations reported estimated monthly bills reaching trillions of dollars, triggering budget alerts and prompting concerns over…
New Windows LegacyHive 0-Day Vulnerability Allows Hackers to Gain Admin Access
A Windows zero-day vulnerability, dubbed LegacyHive (MSNightmare), abuses the User Profile Service to enable local privilege escalation, tampering with administrator accounts, and admin-level code execution. LegacyHive targets the Windows User Profile Service (ProfSvc), which is responsible for loading and unloading user…