Overview Earlier this month, security sleuth and researcher “Chaotic Eclipse” (also known as Nightmare-Eclipse) published a zero-day exploit known as YellowKey, which allowed them to access BitLoc...
Overview of the First VPN Service 🚀 The Federal Bureau of Investigation (FBI) has released a FLASH report to share indicators of compromise (IOCs) and tactics related to the First VPN Service. Thi...
🚨 Important Security Alert! An attachment in an email impersonating DHL about a shipment contains a link to a preconfigured SimpleHelp remote access tool—an ideal starting point for attackers to e...
Vulnerabilities in Mira Hormone Monitor and Android App
Vulnerabilities in Mira Hormone Monitor and Android App 🚨 The recent report from CISA highlights critical vulnerabilities in the Mira Hormone Monitor and its Android App. Successful exploitation o...
Social Media Platforms Crack Down on Drone Factory Recruiting Game
Social Media Platforms Crack Down on Drone Factory Recruiting Game A video game about drone warfare may look like an unusual cybersecurity story. But cybersecurity isn’t only about malware or stol...
Shattering the Dream Operation Dream Job Exposed
Shattering the Dream: Operation Dream Job Exposed Check Point Research is tracking a long-running campaign called Operation Dream Job, targeting organizations worldwide, with a particular focus on...
Johnson Controls C-CURE 9000 and Victor Application Server Vulnerabilities
Johnson Controls C-CURE 9000 and Victor Application Server Vulnerabilities 🚨 On August 11, 2026, CISA published an advisory regarding critical vulnerabilities in the Johnson Controls C-CURE 9000 a...
Delta Probes Wi-Fi Deauth Attack on Flight Carrying DEF CON Attendees
Delta Air Lines Investigates Wi-Fi Incident 🚨 Delta Air Lines is currently investigating an unauthorized Wi-Fi network that appeared aboard a flight from Las Vegas to Atlanta, which was carrying p...
Apache Gravitino 1.2.1 - SSRF
Apache Gravitino 1.2.1 - SSRF 🚀 The Exploit Database is maintained by OffSec, an information security training company that provides various Information Security Certifications as well as high-end...
Enriched URL Reports VirusTotal URL Scanning 2.0
Enriched URL Reports - VirusTotal URL Scanning 2.0 🚀 Traditional URL analysis has been redefined! The launch of URL Scanning 2.0 significantly expands VirusTotal’s URL analysis capabilities by int...
CVE-2026-73249 - calibre Content Server Vulnerability
CVE-2026-73249 - calibre Content Server Vulnerability A critical vulnerability, identified as CVE-2026-73249, has been discovered in the calibre Content Server. This issue affects versions prior t...
Edge is Dropping Older Extensions, Affecting Popular Privacy Tools
Microsoft Edge Extension Changes 🚀 Microsoft is beginning the retirement of Manifest V2 (MV2) extensions in Edge this month, with consumer completion targeted for the end of 2026 and managed-enter...
Abyssos Technical Analysis of a New Modular RAT
Abyssos: Technical Analysis of a New Modular RAT In late June 2026, Zscaler ThreatLabz identified a new malware family that we track as Abyssos. Abyssos is a new modular remote administration tool...
Smile, You're on Camera. Part 2 Hiring Lazarus APT's IT Workers in a Fake DeFi Startup
Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup Researchers created a fake DeFi startup and hired suspected Famous Chollima operatives, providing a rare ins...
CVE-2026-11812 - UpdateHub Vulnerability Causes DoS
CVE-2026-11812 - UpdateHub Vulnerability 🚨 The UpdateHub management subsystem has been identified with a critical vulnerability that can lead to a denial of service (DoS) due to a race condition o...
U.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled Data
U.S. Defense Manufacturer IEH Hit by Phishing Attack 🚨 IEH Corporation, a prominent U.S. defense and aerospace manufacturer based in Brooklyn, New York, has fallen victim to a phishing attack that...
CVE-2026-12372 - Server-Side Request Forgery (SSRF) in nltk/nltk
CVE-2026-12372 - Server-Side Request Forgery (SSRF) in nltk/nltk A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The nltk.path...
Hackers Breach TrueConf to Trojanize Client Installers with Backdoors
Hackers Breach TrueConf to Trojanize Client Installers with Backdoors 🚨 The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to repla...
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
Atlassian Rovo Vulnerability 🚨 Summary: Attacker-controlled instructions can make Atlassian’s Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an ou...
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
Atlassian Rovo Vulnerability 🚨 Summary: Attacker-controlled instructions can make Atlassian’s Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an ou...