-
GoldenEyeDog, a Chinese cybercrime group increasingly tracked as an advanced threat cluster, has been linked to a sophisticated intrusion into DigiCert that enabled the theft and abuse of legitimate code-signing certificates. The group has been active …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Kimai users who are running the official Docker image are strongly urged to update their installations after a critical vulnerability, tracked as CVE-2026-52824 and GHSA-jr9p-4h4j-6c58, was discovered. This vulnerability exposes installations to the ri…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A sophisticated North Korean threat campaign dubbed “Contagious Interview” has resurfaced with new delivery techniques, leveraging weaponized SVG image files to deploy the OTTERCOOKIE malware while coinciding with a separate supply chain intrusion targ…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly published Linux toolkit named Furtex showcases a wide range of concepts related to post-exploitation, persistence, data access, and monitoring evasion. It is built around io_uring, eBPF, BPF maps, and raw system calls. The project includes over…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Hugging Face has disclosed a security incident involving unauthorized access to certain parts of its production infrastructure, affecting a limited set of internal datasets and several service credentials. The AI platform made this disclosure on July 1…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly disclosed a pre-authentication remote code execution (RCE) vulnerability in WordPress Core, dubbed “wp2shell,” that requires no authentication and affects stock WordPress installations with zero plugins installed. Given that WordPre…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Ernst & Young LLP (EY) has confirmed a data security incident in which an unauthorized third party breached a third-party IT service management platform used by its tax practice, exfiltrating documents containing client personal and financial infor…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly disclosed vulnerability reminds us how deeply our digital infrastructure relies on foundational libraries. The Okta Red Team recently discovered “HollowByte,” a Denial of Service (DoS) flaw in OpenSSL that allows a remote, unauthent…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Cloud Software Group has issued a High-severity security bulletin (CTX696734) disclosing two vulnerabilities in the Citrix Secure Access Client for Windows and the Citrix Endpoint Analysis Client for Windows. The more serious of the two, tracked as CVE…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A financially motivated, Russian-speaking threat actor tracked as UAT-11795, orchestrating a large-scale campaign since at least June 2025. A sophisticated Python-based remote access trojan dubbed “Starland RAT,” alongside a stealthy in-memory PowerShe…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


