BeyondTrust Warns of Critical Vulnerabilities in RS and PRA That Could Allow Authentication Bypass

372/69 Wednesday, July 8, 2026 BeyondTrust has warned administrators to urgently update its Remote Support (RS) and Privileged Remote Access (PRA) products after multiple Critical vulnerabilities were discovered that could allow unauthenticated attackers to bypass authentication and access affected appliances. The key vulnerabilities are CVE-2026-40138 and CVE-2026-40139, both of which are related to flaws in […]

chanapon

July 8, 2026

Backdoor Vulnerability in Tenda Routers Allows Attackers to Bypass Login and Gain Administrator Privileges, With No Patch Available

371/69 Wednesday, July 8, 2026 CERT/CC has issued an advisory for CVE-2026-11405, an authentication vulnerability affecting the firmware of several Tenda router models. The vulnerability allows attackers who know a specific password to bypass login and access the device’s web management interface with administrator privileges without using valid credentials. This is possible even if the […]

chanapon

July 8, 2026

Threat Actors Probe Critical Gitea Docker Vulnerability Just 13 Days After Disclosure

370/69 Wednesday, July 8, 2026 Reports indicate that threat actors have begun scanning systems to identify and attempt exploitation of a Critical security vulnerability, tracked as CVE-2026-20896, in Gitea Docker images just 13 days after the flaw was publicly disclosed. The vulnerability has a CVSS score of 9.8 and directly affects organizations and developers using […]

chanapon

July 8, 2026

Adobe Urges ColdFusion Users to Update After Critical Vulnerability Confirmed as Actively Exploited

369/69 Tuesday, July 7, 2026 Security researchers have disclosed that attackers are actively exploiting a Critical vulnerability, tracked as CVE-2026-58034, in Adobe ColdFusion to target unpatched servers. Adobe has raised the vulnerability to Priority 1 and confirmed that it has been exploited in attacks. The vulnerability has a CVSS score of 10.0 and could allow […]

chanapon

July 7, 2026

Medtronic Notifies More Than 3.8 Million People After Data Breach Linked to ShinyHunters Attack

368/69 Tuesday, July 7, 2026 Medtronic, a major global medical device manufacturer, has notified 3,834,294 individuals after a cyberattack linked to the ShinyHunters data extortion group may have exposed certain personal and medical information to unauthorized access. Medtronic is a medical technology and device company with approximately 90,000 employees, operating in 150 countries, and is […]

chanapon

July 7, 2026

JADEPUFFER Operation Found Using an LLM Agent to Conduct Automated Ransomware Attacks

366/69 Monday, July 6, 2026 Security researchers have identified an AI Agent-powered ransomware operation tracked as JADEPUFFER. It is assessed to be potentially the first documented case of a ransomware attack fully automated by a Large Language Model (LLM), covering every stage of the attack chain, from initial compromise, environment reconnaissance, credential theft, lateral movement, […]

chanapon

July 6, 2026

FBI Warns TeamPCP Compromised Developer Tools to Steal Cloud Credentials and Conduct Software Supply Chain Attacks

365/69 Monday, July 6, 2026 The U.S. Federal Bureau of Investigation (FBI) issued a FLASH alert on July 2, 2026, warning about a cybercriminal group known as TeamPCP, which has been conducting Software Supply Chain attacks targeting popular developer tools and security tools to steal victims’ credentials. The group embeds malicious code into legitimate software […]

chanapon

July 6, 2026

PolinRider Campaign Found Distributing 108 Malicious Packages and Browser Extensions Targeting Software Developers

364/69 Monday, July 6, 2026 Security researchers have identified activity by a state-sponsored threat group under a campaign named PolinRider, which is linked to the Contagious Interview operation. The group has been distributing 108 malicious packages and web browser extensions through software development platforms such as npm, Packagist, Go, and Google Chrome. The campaign has […]

chanapon

July 6, 2026

Apple Releases Updates to Fix Multiple Vulnerabilities in iOS, macOS, and Safari

363/69 Friday, July 3, 2026 Apple has released security updates for iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, and Safari 26.5.2 to address multiple vulnerabilities in key components, including WebKit, Kernel, WebRTC, Web Extensions, IOGPUFamily, and libxslt. Most of the vulnerabilities are related to the processing of specially crafted web content, which could lead to […]

chanapon

July 3, 2026

Kubota North America Says Attackers Had Network Access for Over a Month, Affecting Employee and Dependent Data

362/69 Friday, July 3, 2026 Kubota North America Corporation, the North American business of Japan-based industrial manufacturer Kubota Corporation, has disclosed a cybersecurity incident after finding that threat actors had access to certain parts of the company’s network for more than one month, between March 16 and April 20, 2026. The investigation found that the […]

chanapon

July 3, 2026
1 11 12 13 112