Gitea users are urged to update immediately after a critical vulnerability was disclosed that allows public-only repository access tokens to indirectly write to private pull request branches and trigger private Actions workflows. Tracked as CVE-2026-58443, the vulnerability affects Gitea versions…
Category: Cyber Security News
Linux Patches 400+ Kernel Vulnerabilities in 24 Hours With AI-Powered Detection
The Linux kernel project has released fixes for over 400 vulnerabilities within approximately 24 hours. These vulnerabilities span various areas, including networking, filesystems, memory management, Bluetooth, virtualization, drivers, and security components. This rapid wave of Common Vulnerabilities and Exposures (CVE)…
One Security Alert Exposed a GenAI-Powered Malware Factory Containing More Than 1,000 Attack Files
A single security alert has exposed an unusually detailed view of how a threat actor builds, tests, and delivers malware. The exposed WebDAV server held more than 1,000 files, including phishing lures, shortcut files, droppers, testing notes, and tools used…
Microsoft Defender XDR Blind Spot Can Hide Public Connections Behind FourToSixMapping
Security teams relying on Microsoft Defender XDR’s DeviceNetworkEvents table for hunting and detection may be missing critical external network connections due to a lesser-known IP address classification quirk. The issue centers on FourToSixMapping, a RemoteIPType value that can cause public…
SonicWall 0-day Vulnerabilities Exploited in the Wild to Deploy Custom Malware
Attackers actively exploited two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) VPN appliances to gain root access and deploy custom malware. In early July 2026, the cybersecurity firm Volexity was involved in investigating an intrusion related to the SonicWall…
The Privilege Paths Attackers See, That You Don’t – A Complete PAM Guide
Why identity fragmentation is the blind spot behind most breaches—and what a platform approach changes The Identity Problem Hiding in Plain Sight Identity is at the centre of nearly every major breach—yet most organisations still can’t answer one fundamental question: what…
Hackers Turn Telegram Bots Into Secret Backdoor Controllers for Government Systems
A newly uncovered cyberespionage campaign has turned Telegram bots into quiet controllers for backdoors planted inside Middle Eastern government networks. The operation relies on familiar Windows components and legitimate-looking files, allowing attackers to establish access without immediately drawing attention. The…
Furtex – Linux Toolkit for Post-Exploitation and Evasion for Security Researchers and Red Teamers
A new open-source project, Furtex, has emerged as a Linux-focused post-exploitation and evasion research toolkit for authorized security researchers and red-team operators. The project combines raw io_uring system calls, BPF and eBPF tooling, and EDR-evasion research utilities without relying on…
Hackers Exploiting Palo Alto’s PAN-OS Vulnerability to Deploy Qilin Ransomware
Threat actors are actively exploiting a critical authentication bypass flaw in Palo Alto Networks firewalls to breach corporate networks and deploy Qilin ransomware, according to new research from Arctic Wolf Labs. The security firm investigated multiple intrusions throughout June 2026,…
Hackers Are Turning Microsoft 365 Calendar Invites Into Secret Malware Command Channels
A stealthy new malware strain called HOLLOWGRAPH that hijacks Microsoft 365 calendars to secretly communicate with hackers, disguising malicious commands as ordinary calendar invites. HOLLOWGRAPH is a .NET-compiled malware component that abuses the Microsoft Graph API through a compromised Microsoft…
Paidwork Data Breach Exposes 23 Million Users’ Banking and Personal Data
A massive data breach has hit Paidwork, a popular gig economy platform, exposing sensitive banking and personal information belonging to more than 23 million users worldwide. The incident, first surfacing in March 2026 when hackers listed the stolen data for…
Critical wp2shell RCE Vulnerability – Complete Coverage Including PoC and Active Exploitation Details
A critical pre-authentication remote code execution (RCE) vulnerability chain nicknamed “wp2shell” has been disclosed in WordPress Core, putting an estimated 500 million-plus websites at risk of full takeover by completely unauthenticated attackers. The chain combines two separately tracked flaws CVE-2026-63030,…
Windows Bind Link Abuse Lets Attackers Blind EDR and Bypass AMSI, AppLocker, and Sysmon
Windows defenders are facing a new way for attackers to hide activity after gaining administrator access. The technique abuses Windows bind links, a legitimate feature that redirects one file path to another without changing the original file on disk. Rather…
Microsoft Releases KB5121767 Out-of-Band Update to Fix Dell USB-C Compatibility Bug
Microsoft has released the out-of-band update KB5121767 for Windows 11 to resolve a system performance and compatibility issue affecting a limited number of Dell devices. The update addresses issues with the Intel Innovation Platform Framework (Intel IPF) driver following recent Windows updates.…
Researchers Claim LG Monitors are Silently Installing Adware on Windows Using App
LG monitor software may install advertising-related components on Windows systems without clearly informing users through its companion application, which manages monitor settings, display profiles, and other device features. The software may silently install adware-like components in the background as part…
Microsoft to End OneDrive Sync App Updates for Windows 10
Microsoft will stop delivering OneDrive sync app updates to systems running Windows 10 version 21H2 and earlier on August 15, 2026, creating a new support concern for organizations still operating legacy Windows endpoints. The change was announced in Microsoft 365…
GPT-5.6 Sol Ultra Found Wp2shell RCE Flaw That Could Be Worth $500,000 for About $25
GPT-5.6 Sol Ultra has reportedly uncovered a critical pre-authentication remote code execution (RCE) vulnerability in WordPress after approximately $25 worth of AI usage. This highlights how advanced models could reshape vulnerability research. Researchers at Searchlight Cyber tasked GPT-5.6 Sol Ultra…
ClickFix Campaign Delivers Modular TELEPUZ Malware With 36 Remote Commands
A new malware operation is using ClickFix pages to trick Windows users into running malicious commands themselves. The campaign delivers TELEPUZ, a lightweight but capable remote-access malware that can receive dozens of instructions from its operators. The attack begins with…
Microsoft SharePoint Vulnerabilities Actively Exploited for RCE, Web Shells, and IIS Key Theft
Microsoft SharePoint Server flaws are being actively exploited to gain remote code execution, install persistent web shells, and steal cryptographic keys from exposed systems. The attacks put on-premises SharePoint deployments at risk of data theft, network compromise, ransomware, and prolonged…
Kimai Docker Flaw Lets Unauthenticated Attackers Forge Cookies and Take Over Accounts
Kimai users utilizing the official Docker image are strongly urged to update their installations following the disclosure of a critical vulnerability that could allow unauthenticated attackers to forge authentication cookies and potentially take over accounts, including super administrator accounts. This…