Overview Earlier this month, security sleuth and researcher “Chaotic Eclipse” (also known as Nightmare-Eclipse) published a zero-day exploit known as YellowKey, which allowed them to access BitLoc...
Overview of the First VPN Service 🚀 The Federal Bureau of Investigation (FBI) has released a FLASH report to share indicators of compromise (IOCs) and tactics related to the First VPN Service. Thi...
🚨 Important Security Alert! An attachment in an email impersonating DHL about a shipment contains a link to a preconfigured SimpleHelp remote access tool—an ideal starting point for attackers to e...
2026-07-21 Daily Vulns
Scammers Impersonate FBI on Social Media, Prey on Crime Victims
Scammers Impersonate FBI on Social Media, Prey on Crime Victims The bureau’s Internet Crime Complaint Center (IC3) has updated an earlier warning about scammers impersonating the agency online. Fr...
Malicious Cloud Customers Can Bring Down the Power Grid
Malicious Cloud Customers Can Bring Down the Power Grid AI datacenters wreak havoc on the power grid under normal circumstances, so what happens if a bad actor controls all the GPUs and wants to c...
LG Monitors Criticized for Silently Installing McAfee Ads via Windows Update
LG Monitors Under Fire 🚨 LG is facing criticism after users discovered that connecting certain LG monitors to Windows PCs can automatically install an application that promotes paid McAfee antivir...
Cruciferra Crypter Uses Process Ghosting to Evade Detection
Cruciferra Crypter Uses Process Ghosting to Evade Detection A crypter service used by multiple unrelated cyber-criminal groups has been documented cloaking commodity malware with process ghosting,...
CVE-2026-47134 - ClearanceKit Vulnerability Exposed
CVE-2026-47134 - ClearanceKit Vulnerability 🚨 A critical vulnerability, identified as CVE-2026-47134, has been reported regarding ClearanceKit. This vulnerability allows any local-root process to ...
Scans for Hikvision Intelligent Security API
Scans for Hikvision Intelligent Security API Hikvision cameras have a long history of vulnerabilities and are often targeted by internet-wide scans detected by our honeypot network. This weekend, ...
CVE-2026-64186 - Fixing Latent Out-of-Bounds Access in IOMMU Debugfs
CVE-2026-64186 - Fixing Latent Out-of-Bounds Access in IOMMU Debugfs In the Linux kernel, a significant vulnerability has been resolved: CVE-2026-64186. This issue pertains to a latent out-of-boun...
2026-07-19 Daily Vulns
GitHub-native Command-and-Control Framework OctoC2 Released
Exciting Release: OctoC2 🚀 A new GitHub-native command-and-control framework called OctoC2 has been released for authorized security research, featuring encrypted multi-channel transport and resil...
EU Politicians Investigated Pegasus Spyware. Then It Ended Up on One of Their Phones
EU Politicians Investigated Pegasus Spyware 🚨 In the summer of 2022, Greek politician Stelios Kouloglou was investigating how intrusive spyware had been used to hack business leaders, law enforcem...
CVE-2026-16195 - Sipeed PicoClaw Group Message Authorization Flaw
CVE-2026-16195 - Sipeed PicoClaw Group Message Authorization Flaw A critical security flaw has been discovered in Sipeed PicoClaw up to version 0.2.9. This issue affects the function dispatchIncom...
CVE-2026-10130 - QueryWeaver Authentication Bypass Vulnerability
CVE-2026-10130 - QueryWeaver Authentication Bypass Vulnerability Date Published: July 18, 2026 QueryWeaver contains an authentication bypass vulnerability that allows unauthenticated attackers to...
2026-07-18 Daily Vulns
Shark Vacuum Flaw Exposes Cameras, Home Maps and Wi-Fi Passwords
Shark Vacuum Flaw Exposes Cameras, Home Maps and Wi-Fi Passwords 🚨 Shark’s cloud-connected robot vacuums are currently exposed by an unpatched AWS (Amazon Web Services) IoT (Internet of Things) po...
HollowByte DDoS Flaw Bloats OpenSSL Server Memory
HollowByte DDoS Flaw Bloats OpenSSL Server Memory 🚨 A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a mali...
Ernst & Young Investigates Data Breach Involving Third-Party Support Tickets
Ernst & Young (EY) Investigates Data Breach 🚨 Ernst & Young (EY) has disclosed a significant data breach after attackers compromised a third-party IT support system containing sensitive cl...