2026-02-26 Daily Vulns
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2006-3730 n/a - n/a Integer...
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2006-3730 n/a - n/a Integer...
Treasury Sanctions Exploit Broker Network for Theft and Sale of U.S. Government Cyber Tools Today, the Department of the Treasury’s Office of Foreign Assets Control (OFAC) designated Sergey Sergey...
SLH Offers Financial Incentives for Vishing Attacks 🚨 The notorious cybercrime collective known as Scattered LAPSUS$ Hunters (SLH) has been observed offering financial incentives to recruit women ...
One-click Disaster: Microsoft’s Entra Tokens at Risk 🚨 A single click could grant third-party apps permanent access to corporate email accounts without a password, putting organizations at risk of...
A Surprising Discovery 🚀 A software engineer’s earnest effort to steer his new DJI robot vacuum with a video game controller inadvertently granted him a sneak peek into thousands of people’s homes...
Kali & LLM - macOS with Claude Desktop GUI This post will focus on an alternative method of using Kali Linux, moving beyond direct terminal command execution. Instead, we will leverage a Large...
Defense Contractor Employee Jailed for Selling 8 Zero-Days to Russian Broker A 39-year-old Australian national who was previously employed at U.S. defense contractor L3Harris has been sentenced to...
DNB Podcast: The Long Game and the Laptop Farm In this episode of Dragon News Bytes, Will Baxter and Eli Woodward sit down in person to dissect the “long game” of modern cyber espionage. 🚀 We dive...
Critical Cisco SD-WAN Bug Exploited in Zero-Day Attacks 🚨 Cisco is warning about a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN, tracked as CVE-2026-20127. This vulnerabil...
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2018-25158 Chamilo - Chamillo LMS...
Anthropic Claims Chinese AI Firms ‘Distilled’ Claude to Train Their Models Questions about how AI models can be copied and replicated are moving from theory into active security debates after Anth...
Understanding the Behavioral Science Behind Online Harassment Harassment is messy. It crosses platforms, jurisdictions, and legal definitions. It often involves large numbers of participants actin...
RoguePilot Flaw in GitHub Codespaces Enabled Copilot to Leak GITHUB_TOKEN 🚨 A vulnerability in GitHub Codespaces could have been exploited by bad actors to seize control of repositories by injecti...
Massiv: The New Threat to Your Mobile Banking Security 🚨 Recent research performed by our Mobile Threat Intelligence (MTI) team revealed yet another Android banking Trojan, named Massiv. This new ...
Go Library Maintainer Critiques GitHub’s Dependabot as a ‘Noise Machine’ 🚨 A Go library maintainer has urged developers to turn off GitHub’s Dependabot, arguing that false positives from the depen...
Crypto-Funded Human Trafficking Is Exploding 🚨 Cryptocurrency’s frictionless, transnational, low-regulation transactions have long promised the ability to pay anyone in the world for anything. Mor...
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2025-13563 BuddhaThemes - Lizza L...
Wormable XMRig Campaign Uses BYOVD Exploit and Time-Based Logic Bomb 🚨 Cybersecurity researchers have disclosed details of a new cryptojacking campaign that uses pirated software bundles as lures ...
New Phishing Framework Starkiller Proxies Real Login Pages to Bypass MFA A highly sophisticated phishing framework named Starkiller has recently emerged, offering attackers an advanced method to s...
How to Set Up Private DNS Mode on Your iPhone - Why You Should Do It ASAP Unencrypted DNS can expose your browsing activity, but private DNS helps keep it secure on iPhone. A private DNS for your ...