Overview Earlier this month, security sleuth and researcher “Chaotic Eclipse” (also known as Nightmare-Eclipse) published a zero-day exploit known as YellowKey, which allowed them to access BitLoc...
Overview of the First VPN Service 🚀 The Federal Bureau of Investigation (FBI) has released a FLASH report to share indicators of compromise (IOCs) and tactics related to the First VPN Service. Thi...
🚨 Important Security Alert! An attachment in an email impersonating DHL about a shipment contains a link to a preconfigured SimpleHelp remote access tool—an ideal starting point for attackers to e...
2026-07-28 Daily Vulns
GitHub Introduces 3-Day Dependabot Cooldown to Combat Malware
GitHub Introduces 3-Day Dependabot Cooldown to Combat Malware 🚀 GitHub has introduced a default three-day cooldown period for Dependabot version updates to reduce the risk of projects automaticall...
Ernst & Young Data Breach Claimed by ShinyHunters Extortion Gang
Ernst & Young Data Breach 🚨 The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, stating that they obtained credentials for some o...
Confused Deputy' Flaws Persist in Google Cloud and Microsoft Azure
‘Confused Deputy’ Flaws Persist in Google Cloud and Microsoft Azure 🚨 “Confused Deputy” flaws persist in Google Cloud and Microsoft Azure, a category of vulnerabilities that allows an attacker to ...
OpenAI Not Part of the New Open Secure AI Alliance
OpenAI Not Part of the New Open Secure AI Alliance OpenAI is noticeably absent from the list of initial supporters of a new industry initiative aimed at promoting the creation of strong, safe, def...
Dear Diary Today I Found A Ghost In The Network
Dear Diary Today I Found A Ghost In The Network 👻 In the realm of cybersecurity, some entities operate like ghosts, hidden from plain sight. One such entity is Guangdong Chanming. If you were sear...
Weak Logins Detected in ESAFENET CDG 3 Document Management System
Weak Logins Detected in ESAFENET CDG 3 Document Management System 🚨 Attention Security Professionals! 🚨 Recent scans for the ESAFENET CDG 3 Document Management System have revealed weak logins, i...
CVE-2026-17497 - NoteGen Arbitrary OS Command Execution via Tauri Shell
CVE-2026-17497 - NoteGen Arbitrary OS Command Execution via Tauri Shell Overview NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 w...
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable A malvertising operation dubbed SourTrade is making victims’ browsers build the final Windows executable themselve...
CVE-2026-10681 - SMP Race in Thread Index Allocation
CVE-2026-10681 - SMP Race in Thread Index Allocation CVE-2026-10681 details an SMP race in thread_idx_alloc() that allows concurrent k_object_alloc(K_OBJ_THREAD) callers to share a kernel-object p...
Pope's Official Prayer App Leaks 700K+ Users' Info
Major Data Breach Alert! 🚨 Click To Pray, a prayer app endorsed by the Pope, has committed a cardinal sin by leaking the personal information of over 700,000 users! 😱 This alarming revelation come...
Google Introduces Selfie Video Verification for Account Recovery
Google Introduces Selfie Video Verification for Account Recovery 🚀 Google has started rolling out a new way to recover access to your account if you’ve lost your phone or forgotten your password: ...
Call of Duty Mobile Scam Uses Fake Free Points to Steal Player Accounts
Warning: Phishing Alert! 🚨 Call of Duty Mobile players should be vigilant against a phishing campaign disguised as a free Call of Duty Points giveaway. Victims are prompted to log in with their em...
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
Bing Images Vulnerabilities 🚨 A crafted SVG submitted to Bing’s image search ran commands as NT AUTHORITY\SYSTEM on Microsoft’s production image-processing workers, and as root on the Linux machin...
Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
Thailand’s Ministry of Finance Targeted with Hermes AI 🚨 Hunt.io has uncovered a cyber-espionage attack on Thailand’s Finance Ministry using the Hermes AI agent and Hades malware for reconnaissanc...
Hotel Wi-Fi Routers Compromised to Steal Corporate Login Credentials
Hotel Wi-Fi Routers Compromised to Steal Corporate Login Credentials A widespread DNS poisoning campaign is targeting hotels, conference venues, and the hospitality sector with credential harvesti...