-
Oracle has released 943 security patches as part of its August 2026 Critical Security Patch Update (CSPU), addressing newly disclosed vulnerabilities across its enterprise software portfolio. This update affects Oracle products under both Premier Suppo…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A threat actor calling itself “Ransom Busters” is targeting ransomware victims with a deceptive recovery offer, claiming it can restore encrypted files and delete stolen data from ransomware infrastructure. GuidePoint Security’s Research and Intelligen…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
More than 30 domains tied to MacSync Stealer, exposing a rotating macOS-focused infrastructure that supports payload delivery, command-and-control, credential theft, staging, and chunked data exfiltration. The investigation shows why defenders should p…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
D-Link has disclosed and patched 15 Common Vulnerabilities and Exposures (CVEs) affecting its DWR-M961 4G/LTE router, specifically hardware revision C1. This follows the discovery of multiple command injection and buffer overflow vulnerabilities in the…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The RAVEN offensive framework can turn compromised Elasticsearch and Kibana environments into durable data-theft and persistence operations. RAVEN, short for Reconnaissance & Attack on Vulnerable Elasticsearch Nodes, is an open-source modular frame…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical vulnerability in the Apache HttpComponents Client can allow man-in-the-middle attackers to impersonate trusted servers when applications use the asynchronous version of HttpClient. This vulnerability is tracked as CVE-2026-71290 and arises f…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting Broadcom VMware vCenter to its Known Exploited Vulnerabilities (KEV) Catalog. The vulnerability, tracked as CVE-2026-59310, is a path traversa…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A Google-sponsored search result for Claude installation instructions is being used to deliver a sophisticated macOS stealer and remote-access trojan (RAT) named MacSync. The campaign abuses a legitimate Claude shared-conversation page on the claude.ai…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A large-scale malware operation called StopAndProtect is exploiting thousands of compromised WordPress websites to distribute ransomware, steal files, harvest credentials, and remotely monitor victims through deceptive ClickFix CAPTCHA prompts. Researc…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The Cl0p ransomware and extortion operation is likely exploiting a critical PTC Windchill vulnerability to deploy a purpose-built Java web shell that can harvest credentials, map engineering data vaults, and exfiltrate files without requiring additiona…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


