Overview Earlier this month, security sleuth and researcher “Chaotic Eclipse” (also known as Nightmare-Eclipse) published a zero-day exploit known as YellowKey, which allowed them to access BitLoc...
Overview of the First VPN Service 🚀 The Federal Bureau of Investigation (FBI) has released a FLASH report to share indicators of compromise (IOCs) and tactics related to the First VPN Service. Thi...
🚨 Important Security Alert! An attachment in an email impersonating DHL about a shipment contains a link to a preconfigured SimpleHelp remote access tool—an ideal starting point for attackers to e...
Weak Logins Detected in ESAFENET CDG 3 Document Management System
Weak Logins Detected in ESAFENET CDG 3 Document Management System 🚨 Attention Security Professionals! 🚨 Recent scans for the ESAFENET CDG 3 Document Management System have revealed weak logins, i...
CVE-2026-17497 - NoteGen Arbitrary OS Command Execution via Tauri Shell
CVE-2026-17497 - NoteGen Arbitrary OS Command Execution via Tauri Shell Overview NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 w...
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable A malvertising operation dubbed SourTrade is making victims’ browsers build the final Windows executable themselve...
CVE-2026-10681 - SMP Race in Thread Index Allocation
CVE-2026-10681 - SMP Race in Thread Index Allocation CVE-2026-10681 details an SMP race in thread_idx_alloc() that allows concurrent k_object_alloc(K_OBJ_THREAD) callers to share a kernel-object p...
Pope's Official Prayer App Leaks 700K+ Users' Info
Major Data Breach Alert! 🚨 Click To Pray, a prayer app endorsed by the Pope, has committed a cardinal sin by leaking the personal information of over 700,000 users! 😱 This alarming revelation come...
Google Introduces Selfie Video Verification for Account Recovery
Google Introduces Selfie Video Verification for Account Recovery 🚀 Google has started rolling out a new way to recover access to your account if you’ve lost your phone or forgotten your password: ...
Call of Duty Mobile Scam Uses Fake Free Points to Steal Player Accounts
Warning: Phishing Alert! 🚨 Call of Duty Mobile players should be vigilant against a phishing campaign disguised as a free Call of Duty Points giveaway. Victims are prompted to log in with their em...
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
Bing Images Vulnerabilities 🚨 A crafted SVG submitted to Bing’s image search ran commands as NT AUTHORITY\SYSTEM on Microsoft’s production image-processing workers, and as root on the Linux machin...
Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
Thailand’s Ministry of Finance Targeted with Hermes AI 🚨 Hunt.io has uncovered a cyber-espionage attack on Thailand’s Finance Ministry using the Hermes AI agent and Hades malware for reconnaissanc...
Hotel Wi-Fi Routers Compromised to Steal Corporate Login Credentials
Hotel Wi-Fi Routers Compromised to Steal Corporate Login Credentials A widespread DNS poisoning campaign is targeting hotels, conference venues, and the hospitality sector with credential harvesti...
2026-07-24 Daily Vulns
WhatsApp Web Chats Exposed by Adobe's Acrobat Extension Flaw
WhatsApp Web Chats Exposed by Adobe’s Acrobat Extension Flaw 🚨 A recently disclosed vulnerability, known as HermeticReader, has put WhatsApp Web chats at risk due to a flaw in the Adobe Acrobat PD...
New Dolphin X Malware Uses AI to Rank High-Value Targets
New Dolphin X Malware Uses AI to Rank High-Value Targets 🚀 A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercrimina...
Data Breach Exposes Client Information at Origin Energy
Data Breach Exposes Client Information at Origin Energy 🚨 Australian energy provider Origin Energy has confirmed a data breach by an unknown threat actor that exposed customers’ personally identif...
Ta488 Targets Zimbra Mailservers with Half Click Exploits
Overview 🚨 Proofpoint has uncovered that the Russia-aligned threat actor TA488 (also known as Void Blizzard or Laundry Bear) has been exploiting a previously unknown vulnerability in Zimbra mailse...
TA458 Roundpress Exploits A New Threat in Webmail Security
TA458 Roundpress Exploits: A New Threat in Webmail Security 🚨 The Russia-aligned threat actor TA458, known for its involvement in Operation RoundPress, continues to target webmail services using i...
New Dolphin X Malware Uses AI to Rank High-Value Targets
New Dolphin X Malware Uses AI to Rank High-Value Targets 🚀 A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercrimina...