Overview Earlier this month, security sleuth and researcher “Chaotic Eclipse” (also known as Nightmare-Eclipse) published a zero-day exploit known as YellowKey, which allowed them to access BitLoc...
Overview of the First VPN Service 🚀 The Federal Bureau of Investigation (FBI) has released a FLASH report to share indicators of compromise (IOCs) and tactics related to the First VPN Service. Thi...
🚨 Important Security Alert! An attachment in an email impersonating DHL about a shipment contains a link to a preconfigured SimpleHelp remote access tool—an ideal starting point for attackers to e...
Turns Out the Ghost Was the PLA
Turns Out the Ghost Was the PLA Our research uncovered a tidy little overlap that points straight at APT15 and the PLA Cyberspace Force’s 8th Technical Reconnaissance Base (8th TRB). This tool, kn...
Siemens Mendix Runtime Vulnerability Advisory
Siemens Mendix Runtime Vulnerability Advisory Source: CISA Date Published: July 28, 2026 Mendix documentation for access rules does not adequately describe the special behavior of the System.User...
Multiple Vulnerabilities in ELECOM Wireless LAN Routers and Access Points
Multiple Vulnerabilities in ELECOM Wireless LAN Routers and Access Points 🚨 Multiple wireless LAN routers and access points provided by ELECOM CO.,LTD. contain several vulnerabilities. Specificall...
Mirage Kitten's New Malware Set NightLedger Backdoor and Two Tunneling Tools
Mirage Kitten’s New Malware Set 🚀 Mirage Kitten, also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore, is an advanced persistent threat (APT) group focused on cyber-espionage operations ag...
igloohome Smart Lock Mobile Application Vulnerability Alert
igloohome Smart Lock Mobile Application Vulnerability Alert 🚨 The igloohome Smart Lock Mobile Application has a critical vulnerability that could allow unauthorized access to its functions and bac...
New Crypter-as-a-Service Cruciferra Fuels Stealthy Malware Attacks Worldwide
New Crypter-as-a-Service Cruciferra Fuels Stealthy Malware Attacks Worldwide 🚀 Proofpoint has uncovered Cruciferra, a crypter-as-a-service that assists hackers in evading antivirus systems and del...
MikroTik RouterOS and Cloud Hosted Router Vulnerability Advisory
MikroTik RouterOS and Cloud Hosted Router Vulnerability Advisory 🚨 CISA has published an advisory regarding a critical vulnerability in MikroTik RouterOS and Cloud Hosted Router. This vulnerabilit...
CubePilot Drone Software Developer Hit by DNS Hijacking
CubePilot Drone Software Developer Hit by DNS Hijacking 🚨 CubePilot, an Australian firm that designs flight controllers for drones (UAVs), announced a severe operational disruption caused by a DNS...
AutoIT Payload Injector A New Wave of Malware
AutoIT Payload Injector: A New Wave of Malware For a long time, AutoIT has been a common tool in the malware ecosystem. Threat actors continue to use it due to its ease of use and powerful capabil...
2026-07-28 Daily Vulns
Java Spring Boot Heapdump Scans Expose Sensitive Data
Java Spring Boot Heapdump Scans 🚀 Spring Boot exposes the endpoint “/actuator/heapdump” to collect debug information. By default, the endpoint will return a file heapdump.hprof, which includes a b...
GitHub Introduces 3-Day Dependabot Cooldown to Combat Malware
GitHub Introduces 3-Day Dependabot Cooldown to Combat Malware 🚀 GitHub has introduced a default three-day cooldown period for Dependabot version updates to reduce the risk of projects automaticall...
Ernst & Young Data Breach Claimed by ShinyHunters Extortion Gang
Ernst & Young Data Breach 🚨 The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, stating that they obtained credentials for some o...
Confused Deputy' Flaws Persist in Google Cloud and Microsoft Azure
‘Confused Deputy’ Flaws Persist in Google Cloud and Microsoft Azure 🚨 “Confused Deputy” flaws persist in Google Cloud and Microsoft Azure, a category of vulnerabilities that allows an attacker to ...
What’s Your Data Worth on the Dark Web? (Lock and Code S07E15)
What’s Your Data Worth on the Dark Web? (Lock and Code S07E15) Source: Malwarebytes Date Published: July 27, 2026 Twenty years ago, a British mathematician named Clive Humby popularized a phrase ...
OpenAI Not Part of the New Open Secure AI Alliance
OpenAI Not Part of the New Open Secure AI Alliance OpenAI is noticeably absent from the list of initial supporters of a new industry initiative aimed at promoting the creation of strong, safe, def...
MedusaHVNC Trojan Creates Hidden Desktops to Hijack Browsers and Steal Data
MedusaHVNC Trojan: A New Threat to Your Data 🚨 The MedusaHVNC RAT is a sophisticated remote access trojan that utilizes hidden Windows desktops to remotely control browsers, steal data, and evade ...