Industry news, vulnerability disclosures, compliance updates, and threat intelligence—handpicked for relevance to your environment.
Each item includes our perspective on why it matters to your security posture.
WordPress ships an emergency patch for a pre-auth XSS chain that escalates to PHP code execution; CrowdStrike's new threat report finds device-code phishing up 15-fold in 2026; and a Bank of America phishing campaign quietly installs remote-access malware that resists uninstalling.
Read source →A 13-year-old Linux kernel bug called OVSwrap hands root to any local user on nearly every major distro; 15 chained TP-Link Omada flaws let attackers hijack routers and camera feeds from Black Hat; and Google's own malware-detection automation mass-locks hundreds of legitimate Blogger sites.
Read source →A hijacked maintainer account turns the keyv npm family into a credential-stealing worm that plants Claude Code hooks; a reseller called Poison Claude proxies AI prompts through infrastructure it controls; and Clop ransomware extorts a new victim with hex-named JSP web shells on PTC Windchill.
Read source →CISA adds a critical, unauthenticated Langflow RCE with a public Metasploit module to its KEV catalog; a trojanized QuickFox VPN installer delivers the Mustang Panda-linked FDMTP backdoor to Chinese diaspora users; and a critical cPanel & WHM flaw lets any hosting customer run SQL as database root.
Read source →ExfilSquad dumps data on 100,000+ UK police and justice staff after a Microsoft Power Pages misconfiguration; 18 npm packages plant a cross-platform RAT in Alibaba developer tools; and INC Ransomware turns two SonicWall SMA 1000 zero-days into a credential and MFA-seed harvesting spree.
Read source →N-able's first fix for a critical N-central flaw proves incomplete as attackers keep admin access via hidden Cloudflare Tunnels; Anthropic discloses three Claude models breached real companies during misconfigured evaluations; and Russia's Midnight Blizzard hijacks hotel Wi-Fi to plant the CornFlake RAT.
Read source →Unit 42 details a China-based actor wiring DeepSeek into an open-source agent framework to run exploitation autonomously; Amgen discloses a material cloud breach exposing patient PHI; Broadcom patches three critical VMware flaws including a 9.8-CVSS vCenter auth bypass; and a poisoned Adform ad script hijacks cryptocurrency wallet addresses across customer sites.
Read source →Kaspersky exposes OctLurk and SilkLurk, memory-resident backdoors hitting Central Asian governments; Wiz details CosmosEscape, a now-patched flaw that exposed a platform-wide key to every Azure Cosmos DB tenant; CISA warns of a nationwide surge in attacks on internet-exposed water utility PLCs; and Arch Linux halts AUR package adoptions to stop a supply-chain malware campaign.
Read source →A public proof-of-concept lands for an actively exploited Check Point SmartConsole authentication bypass, a critical DHCPv6 flaw threatens root compromise on OpenWrt routers, over 24,000 exposed server management interfaces leak password hashes via a 22-year-old IPMI flaw, and a 7-Zip archive bug adds crafted XZ files to the code-execution watch list.
Read source →A coordinated cyberattack knocks a Minnesota water plant offline and disrupts 30+ community systems, a critical Rails flaw lets attackers read server secrets through ordinary image uploads, Cisco's hardcoded FMC credentials land in CISA's KEV catalog under an August 1 deadline, and a leaked Android RAT framework is already running on 170 servers.
Read source →