KDDI Discloses Data Breach Affecting More Than 12 Million People After ISP Email Platform Attack

374/69 Thursday, July 9, 2026 KDDI, a telecommunications company in Japan, has disclosed a data breach after attackers gained access to an email platform used by five internet service providers (ISPs) in Japan, potentially exposing a large number of users’ email addresses and passwords. KDDI is Japan’s second-largest mobile telecommunications provider, with approximately 45,000 employees […]

chanapon

July 9, 2026

Warning: UAT-7810 Hackers Use LONGLEASH Malware to Target Routers and Build a Stealth Relay Network

373/69 Thursday, July 9, 2026 Security researchers have identified activity linked to a cyber threat group known as UAT-7810, which is developing a new malware toolkit to expand the capabilities of its Operational Relay Box (ORB) network. The group targets internet-connected network devices, especially unpatched Ruckus and ASUS routers. This type of network is used […]

chanapon

July 9, 2026

BeyondTrust Warns of Critical Vulnerabilities in RS and PRA That Could Allow Authentication Bypass

372/69 Wednesday, July 8, 2026 BeyondTrust has warned administrators to urgently update its Remote Support (RS) and Privileged Remote Access (PRA) products after multiple Critical vulnerabilities were discovered that could allow unauthenticated attackers to bypass authentication and access affected appliances. The key vulnerabilities are CVE-2026-40138 and CVE-2026-40139, both of which are related to flaws in […]

chanapon

July 8, 2026

Backdoor Vulnerability in Tenda Routers Allows Attackers to Bypass Login and Gain Administrator Privileges, With No Patch Available

371/69 Wednesday, July 8, 2026 CERT/CC has issued an advisory for CVE-2026-11405, an authentication vulnerability affecting the firmware of several Tenda router models. The vulnerability allows attackers who know a specific password to bypass login and access the device’s web management interface with administrator privileges without using valid credentials. This is possible even if the […]

chanapon

July 8, 2026

Threat Actors Probe Critical Gitea Docker Vulnerability Just 13 Days After Disclosure

370/69 Wednesday, July 8, 2026 Reports indicate that threat actors have begun scanning systems to identify and attempt exploitation of a Critical security vulnerability, tracked as CVE-2026-20896, in Gitea Docker images just 13 days after the flaw was publicly disclosed. The vulnerability has a CVSS score of 9.8 and directly affects organizations and developers using […]

chanapon

July 8, 2026

Adobe Urges ColdFusion Users to Update After Critical Vulnerability Confirmed as Actively Exploited

369/69 Tuesday, July 7, 2026 Security researchers have disclosed that attackers are actively exploiting a Critical vulnerability, tracked as CVE-2026-58034, in Adobe ColdFusion to target unpatched servers. Adobe has raised the vulnerability to Priority 1 and confirmed that it has been exploited in attacks. The vulnerability has a CVSS score of 10.0 and could allow […]

chanapon

July 7, 2026

Medtronic Notifies More Than 3.8 Million People After Data Breach Linked to ShinyHunters Attack

368/69 Tuesday, July 7, 2026 Medtronic, a major global medical device manufacturer, has notified 3,834,294 individuals after a cyberattack linked to the ShinyHunters data extortion group may have exposed certain personal and medical information to unauthorized access. Medtronic is a medical technology and device company with approximately 90,000 employees, operating in 150 countries, and is […]

chanapon

July 7, 2026

JADEPUFFER Operation Found Using an LLM Agent to Conduct Automated Ransomware Attacks

366/69 Monday, July 6, 2026 Security researchers have identified an AI Agent-powered ransomware operation tracked as JADEPUFFER. It is assessed to be potentially the first documented case of a ransomware attack fully automated by a Large Language Model (LLM), covering every stage of the attack chain, from initial compromise, environment reconnaissance, credential theft, lateral movement, […]

chanapon

July 6, 2026

FBI Warns TeamPCP Compromised Developer Tools to Steal Cloud Credentials and Conduct Software Supply Chain Attacks

365/69 Monday, July 6, 2026 The U.S. Federal Bureau of Investigation (FBI) issued a FLASH alert on July 2, 2026, warning about a cybercriminal group known as TeamPCP, which has been conducting Software Supply Chain attacks targeting popular developer tools and security tools to steal victims’ credentials. The group embeds malicious code into legitimate software […]

chanapon

July 6, 2026

PolinRider Campaign Found Distributing 108 Malicious Packages and Browser Extensions Targeting Software Developers

364/69 Monday, July 6, 2026 Security researchers have identified activity by a state-sponsored threat group under a campaign named PolinRider, which is linked to the Contagious Interview operation. The group has been distributing 108 malicious packages and web browser extensions through software development platforms such as npm, Packagist, Go, and Google Chrome. The campaign has […]

chanapon

July 6, 2026
1 2 3 7