-
Threat actors are actively exploiting CVE-2026-6875, a critical pre-authentication remote code execution vulnerability in the ServiceNow AI Platform. This vulnerability allows attackers to escape a restricted server-side script sandbox and execute code…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
JADEPUFFER has escalated from automated database extortion to purpose-built AI model destruction, deploying a custom Go ransomware dubbed ENCFORGE to encrypt and effectively wipe high‑value AI and ML artifacts across an entire stack. A missing‑authenti…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
AsyncAPI’s npm ecosystem suffered a coordinated supply chain compromise on July 14, 2026, delivering a Miasma‑associated Node.js backdoor through trusted GitHub Actions–driven release workflows and exposing high‑value developer and CI/CD environments t…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An ongoing exploitation of two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) devices. These vulnerabilities allowed a threat actor, identified as UTA0533, to gain root-level access, install persistent malware, and deploy the ORANGETA…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Iran-linked APT42 is escalating its espionage operations with AI-assisted phishing and an expanded TAMECAT backdoor, enabling long-lived access to defense and government identities rather than just endpoints. Recent activity shows tightly integrated so…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Abbott has disclosed a cybersecurity incident involving unauthorized access to a limited number of internal systems used by its Cancer Diagnostics business. Upon discovering the activity, the company acted swiftly by launching an investigation, engagin…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The Linux kernel security team published approximately 440,440 CVE advisories over 24 hours, reflecting a significant release of vulnerability records linked to fixes already incorporated into the upstream kernel tree. These notices were distributed th…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
AgentBaiting is the clearest sign yet that AI agents and their capability ecosystems have become a first‑class malware delivery surface, with FakeGit’s 7,600‑repo operation pushing SmartLoader and StealC directly into AI Skills and MCP workflows. By tu…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Gitea administrators are strongly encouraged to upgrade their systems following the discovery of a critical authorization vulnerability. This flaw allows public-only API tokens to modify private pull request branches and potentially trigger Gitea Actio…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Fileless stealer and PureRAT operators are abusing a WebDAV‑backed “malware delivery lab” to raid browser passwords, Telegram sessions, and cryptocurrency wallets in a campaign that blends fileless info‑stealing with a modular .NET RAT. The incident be…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


