Security researcher Paul Moore has once again exposed critical weaknesses in the EU’s flagship age verification system, this time by bypassing the latest app release (version 2026.07-1) using a Chrome extension powered by ClaudeAI. The proof-of-concept shows that, despite months…
Category: Cyber Security News
Multiple Notepad++ Vulnerabilities Enable PowerShell Command Injection Attacks
Notepad++ v8.9.7 has been released with critical security fixes addressing multiple vulnerabilities, including a high-risk PowerShell command injection flaw that could enable arbitrary code execution during installation. The update resolves five distinct issues spanning path traversal, buffer overflow, and authentication…
Microsoft Active Directory Services 0-Day Vulnerability Actively Exploited in the Wild
Microsoft has released security updates for CVE-2026-56155, an actively exploited elevation-of-privilege vulnerability in Active Directory Federation Services (AD FS). This flaw allows an authenticated local attacker with low privileges to gain administrator-level access on affected systems. CVE-2026-56155 stems from insufficient…
Windows BitLocker 0‑Day Vulnerability Allows Hackers to Bypass Security Feature
A newly disclosed Windows BitLocker 0‑day vulnerability, tracked as CVE-2026-50661, exposes encrypted devices to physical attacks that can completely undermine Microsoft’s disk encryption guarantees. The flaw, classified as a security feature bypass, stems from a protection mechanism failure in BitLocker’s…
Hackers Spoof 3.7 Million OAuth Client IDs to Stealthily Enumerate 2 Million Entra ID Users
Threat actors are increasingly exploiting spoofed OAuth client IDs to enumerate Microsoft Entra ID accounts and identify potentially valid credentials while evading traditional detection methods, according to recent research from Proofpoint. OAuth client IDs are globally unique identifiers assigned to…
Fortinet Patches Seven Vulnerabilities Across FortiOS, FortiProxy, FortiPAM, and FortiSandbox
Fortinet disclosed seven new security advisories on July 14, 2026, affecting FortiOS, FortiProxy, FortiPAM, and FortiSandbox. The flaws range from low-severity header injection bugs to medium-severity buffer overflows and a notably concerning unauthenticated VNC exposure in FortiSandbox. While none carry…
Massive Microsoft Patch Tuesday Update: 570 Vulnerabilities Fixed, Including 3 Zero-Days
Microsoft’s July 2026 Patch Tuesday delivers fixes for approximately 570 vulnerabilities across its product ecosystem, following June’s record-breaking release of 206 flaws that also included three publicly disclosed zero-days. CVE ID Vulnerability Impact Severity Zero-Day Status CVE-2026-56164 Microsoft SharePoint Server…
Miasma Turns Trusted npm Packages Into Persistent Backdoors for Developer Machines
Miasma has returned through software packages that many developers would normally trust. Four AsyncAPI packages on npm were altered to deliver a Miasma v3 payload, creating a route for long-term remote access. The campaign does not depend on malware running…
AsyncAPI npm Packages With 2M Weekly Downloads Compromised via GitHub Actions
A supply chain compromise has placed AsyncAPI npm packages at the center of a developer security incident. Five trojanized releases, with roughly 2.9 million combined weekly downloads, were published after an attacker gained access to an npm publishing token. The…
FortiSandbox Vulnerability Allows Attackers to Access VNC Servers of VMs
Fortinet has disclosed a high-severity vulnerability in FortiSandbox that could allow unauthenticated attackers to access the VNC servers of virtual machines used for malware scanning. Tracked as CVE-2026-59835, the flaw is classified as an Exposure of Resource to Wrong Sphere…
Claude for Chrome Vulnerability Lets Attackers Read Gmail, Docs, and Calendar Data
Anthropic’s Claude for Chrome browser extension has two unpatched flaws that allow attackers to read a victim’s Gmail, Google Docs, and Calendar data using just six lines of JavaScript, even after eight subsequent releases. Manifold researchers first reported the issues…
11-Year-Old Linux UEFI Shim Bootloaders Let Attackers Bypass Secure Boot
11-year-old Microsoft-signed UEFI shim bootloaders, some dating back over a decade, let attackers completely bypass UEFI Secure Boot on nearly any UEFI-based machine, regardless of the installed operating system. ESET researchers uncovered that the vulnerable shims, all at version 0.9 or…
One Malicious OAuth Approval Can Give Hackers Persistent Access to Salesforce Data
One mistaken approval inside Salesforce can hand attackers a quiet, durable route into a company’s most sensitive customer records. Recent campaigns tied to tradecraft associated with ShinyHunters show how a trusted application connection, rather than a software flaw, can be…
xAI Grok Build CLI Uploaded Entire Git Repositories and Unredacted .env Secrets to Cloud Storage
A wire-level analysis of xAI’s Grok Build CLI revealed that version 0.2.93 transmitted unredacted file contents, including secrets from .env files, and uploaded full Git repositories along with their commit history to cloud storage These findings are based on traffic…
Turkish Banks Targeted by 8,400 Phishing Domains and 6,600 Social Media Scam Ads
Turkey’s banking customers are facing a large fraud campaign built around fake websites and social media advertisements. Criminals are abusing trusted financial brands to draw people into credential theft, fake loan offers, and other scams designed to steal money quickly.…
Maximizing SOC Efficiency: How to Eliminate Alert Overload and Cut MTTR by 21 Minutes Per Case
Security Operations Centers (SOCs) face overwhelming challenges not due to a lack of alerts but because each alert requires a new investigation. Analysts must validate indicators, identify malicious behavior, assess the scope of threats, and determine whether to contain or…
CISA Warns of Decades-Old Cisco IOS Vulnerability Actively Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that attackers are actively exploiting CVE-2008-4128, a cross-site request forgery (CSRF) vulnerability affecting Cisco IOS versions 12.4(12) and 12.4(4). This vulnerability was added to CISA’s Known Exploited Vulnerabilities…
New Qilin Ransomware Attack Uses DCSync Technique to Abuse AD Replication Protocol
A recent Qilin ransomware intrusion has revealed a stealthy privilege escalation technique that abuses Active Directory’s built-in replication protocols to harvest domain credentials, including the coveted KRBTGT hash and NTLM password hashes for every account in the domain. Security researcher…
SAP Security Update July 2026 – Patch for Critical SAP NetWeaver Flaw that Enables Memory Corruption
SAP has released its July 2026 Security Patch Day updates, addressing a critical memory corruption vulnerability in the SAP NetWeaver Application Server ABAP. The most severe issue, tracked as CVE-2026-44747, has a CVSS score of 9.9 and affects multiple SAP…
UK and Allies Warn of Russian Hackers Actively Hacking Organizations’ Routers Worldwide
The UK, joined by international cybersecurity partners, has issued an urgent warning about Russian state-backed hackers targeting poorly secured routers and network devices worldwide. The alert focuses on Center 16, a cyber unit linked to Russia’s Federal Security Service, or…