Security news, decoded.
75 stories in the last 7 days, naming 205 CVEs; 60 of those CVEs are in CISA KEV.
The wire
Tuesday, Jul 1411 stories
- SecurityWeekAdobe Patches Critical ColdFusion Vulnerabilities
Adobe has issued security updates for 12 products to resolve 88 vulnerabilities, including several critical flaws in ColdFusion, Commerce, Experience Manager, and Illustrator. Among the 13 issues fixed in ColdFusion, eight are rated critical and could allow attackers to execute arbitrary code or escalate privileges. These include path traversal, code injection, and SQL injection vulnerabilities. Adobe recommends applying the latest updates immediately, particularly for ColdFusion 2025 update 11 and ColdFusion 2023 update 22. The company also addressed multiple high-severity issues in other software such as Commerce, Experience Manager, and Creative Cloud applications.
PatchColdFusion - SecurityWeek7 Severe Vulnerabilities Patched in VMware Avi Load Balancer
Broadcom has issued new updates for the VMware Avi Load Balancer to address seven severe vulnerabilities, including a critical authentication bypass flaw and multiple high-severity issues that could lead to privilege escalation or remote code execution. The flaws were reported by researchers Filip Waeytens and Lang Khuong Duy, who identified risks such as unauthorized access, arbitrary code execution, and directory traversal attacks. While no active exploitation has been observed, experts recommend applying the latest patches due to the potential risk posed by these vulnerabilities.
PatchVMware Avi Load Balancer - The Hacker NewsRabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata
Researchers have revealed two critical access control flaws in RabbitMQ that could allow attackers to steal OAuth client secrets and bypass tenant isolation. The vulnerabilities, tracked as CVE-2026-57219 and CVE-2026-57221, were present since early 2024 and affect multiple versions of the message broker. Attackers could exploit these issues to gain administrative control or access cross-tenant metadata without proper authorization. Patches are available in versions 4.3.0, 4.2.6, 4.1.11, 4.0.20, and 3.13.15.
PoC publicRabbitMQ - Bishop FoxIntroducing snowpick: Testing ServiceNow for Public Data ExposureResearchServiceNow
- The Hacker News11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
Researchers have identified 11 outdated, Microsoft-signed UEFI applications that could be exploited to bypass Secure Boot protections on modern systems. These vulnerabilities affect various Linux distributions and bootloaders from vendors including Red Hat, Oracle, and OpenSUSE. Attackers could leverage these flaws to execute arbitrary code during system startup, potentially deploying persistent malware like UEFI bootkits. The issues were addressed in Microsoft's June 2026 Patch Tuesday update and are tracked under CVE-2026-8863 and CVE-2026-10797.
AdvisoryUEFI Shim Bootloader - BleepingComputerSAP warns of critical flaws in NetWeaver and Commerce Cloud
SAP has issued security updates addressing 16 vulnerabilities, including three critical flaws affecting its NetWeaver Application Server ABAP, Approuter, and Commerce Cloud. These include a memory corruption issue (CVE-2026-44747), an HTTP request smuggling flaw (CVE-2026-27690), and a vulnerability due to default credentials (CVE-2026-44761). While no active exploitation has been observed, these flaws could allow unauthorized access, data manipulation, or service disruption. Users are advised to apply the latest patches immediately.
PatchNetWeaver Application Server ABAP - SecurityWeekSAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud
SAP has issued urgent security updates to fix several high-risk vulnerabilities affecting its core enterprise platforms. Among the most severe is CVE-2026-44747, a memory corruption flaw in NetWeaver Application Server ABAP with a CVSS score of 9.9. Attackers could exploit this to manipulate data or disrupt services. A separate HTTP request smuggling vulnerability (CVE-2026-27690) impacts Approuter, allowing unauthenticated attackers to send malicious requests. Additionally, a hardcoded credential issue in Commerce Cloud (CVE-2026-44761) could enable unauthorized access if default configurations are left unchanged. SAP urges users to apply the latest patches immediately.
PatchNetWeaver Application Server ABAP - SecurityWeekUS, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers
Government agencies from the U.S., UK, and several European countries have issued a joint warning about ongoing cyberattacks by Russian state-backed threat actors targeting routers and other networking equipment used in critical infrastructure. Attackers like Berserk Bear, Energetic Bear, and others are exploiting known vulnerabilities such as CVE-2008-4128 and CVE-2018-0171 to gain unauthorized access and execute arbitrary commands on Cisco devices. These attacks primarily affect sectors including energy, finance, healthcare, and government. Defenders are urged to disable outdated SNMP versions, enforce secure password policies, and apply patches to mitigate risks.
Reported exploitedrouters - Help Net SecurityNo one knows how many old shims can still bypass UEFI Secure Boot
ESET researchers identified 11 outdated UEFI Secure Boot shims signed by Microsoft that could allow attackers to bypass secure boot protections. These shims, all at version 0.9 or lower, were revoked in Microsoft's June 9, 2026 Patch Tuesday update. The issue affects any system using the Microsoft Corporation UEFI CA 2011 certificate. Attackers can exploit this by copying an old shim along with a malicious second-stage loader onto a target device. Two vulnerabilities are involved: CVE-2026-8863 and CVE-2026-10797. Users are advised to apply the latest UEFI revocations and ensure their systems are updated.
ResearchUEFI Secure Boot shims - ESET WeLiveSecurityForgotten UEFI shims undermining Secure Boot
ESET researchers uncovered 11 outdated UEFI shim bootloaders (versions 0.9 or lower) that can be used to bypass UEFI Secure Boot on any system trusting the Microsoft Corporation UEFI CA 2011 certificate. Attackers could exploit these shims to execute untrusted code during boot, enabling malicious UEFI bootkits like Bootkitty, HybridPetya, or BlackLotus. The vulnerabilities were addressed in Microsoft's June 9th, 2026 Patch Tuesday update, which revoked the affected binaries. Two CVE IDs—CVE-2026-8863 and CVE-2026-10797—were assigned to track the issues.
ResearchUEFI shim bootloader - The Hacker NewsU.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support
The U.S. Treasury Department has imposed sanctions on FirstVPN (1VPNS) and two individuals for enabling ransomware attacks against American businesses and critical infrastructure. The service, which operated since 2014, was dismantled in May 2026 after being linked to cybercriminals who used it to mask the origins of their attacks. Alongside FirstVPN’s administrator, Dmytro Rashevskyi, and cryptor seller Yegor Silayev, the move highlights growing efforts to hold bad actors accountable for facilitating large-scale cybercrime. These actions are part of broader international measures targeting Russian state-backed cyber operations and ransomware enablers.
IncidentU.S. Treasury Department
Monday, Jul 1311 stories
- Rapid7 BlogCVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)
Researchers at Rapid7 have revealed a critical authentication bypass flaw in Microsoft SharePoint, tracked as CVE-2026-55040. This vulnerability enables unauthenticated attackers to impersonate users or administrators on vulnerable SharePoint servers by exploiting weaknesses in the JWT token validation process. The flaw is part of an exploit chain that leads to remote code execution, with the RCE component expected to be patched in August 2026. A proof-of-concept script demonstrates how attackers can enumerate user SIDs or UPNs and bypass authentication entirely. Microsoft has acknowledged the issue and released a fix for the authentication bypass in its July updates.
PoC publicMicrosoft SharePoint - BleepingComputerCISA warns of actively exploited RCE flaws in Joomla extensions
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that attackers are actively exploiting two remote code execution (RCE) vulnerabilities in popular Joomla extensions—iCagenda and Balbooa Forms. These flaws allow malicious actors to upload arbitrary files, potentially leading to full website compromise. The vulnerabilities, tracked as CVE-2026-48939 and CVE-2026-56291, were added to CISA's Known Exploited Vulnerabilities catalog with maximum priority, requiring immediate mitigation. Patches are now available for both extensions.
Reported exploitediCagenda - The Hacker News⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
This week's security landscape highlights a growing trend: vulnerabilities are being discovered and exploited faster than ever. Progress has issued an urgent advisory for ShareFile customers to shut down Windows servers running Storage Zone Controllers amid a credible external threat. Meanwhile, ransomware groups are exploiting the recently disclosed Citrix Bleed 2 flaw (CVE-2025-5777) to deploy DragonForce ransomware. Additionally, researchers have uncovered new methods to manipulate AI coding assistants into installing malicious botnets through a technique called HalluSquatting. With dozens of critical CVEs emerging weekly, organizations must prioritize patch management and proactive monitoring to mitigate risks.
Roundup - The Hacker NewsNew MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email
A new attack called MemGhost enables attackers to manipulate AI assistants by planting false 'memories' through a single email. This technique, dubbed stealth memory injection, allows an attacker to alter the agent’s internal knowledge without alerting the user. The attack exploits how personal AI agents store and retrieve information from memory files during sessions. Researchers tested the method successfully on several AI frameworks, including OpenClaw and Claude Code SDK agents. The vulnerability lies in the fact that these systems process untrusted inputs—like emails—and can modify their own memory without user consent. While no immediate patch exists, experts recommend separating tasks involving untrusted content from those that modify memory. OpenClaw acknowledged the risk and suggested mitigations such as routing emails through a restricted agent before processing.
Research - Check Point Research13th July – Threat Intelligence Report
Check Point Research's latest Threat Intelligence Report highlights significant cybersecurity events from the week of July 13, 2026. Among the top incidents was a breach at U.S. auto insurer AssuranceAmerica impacting 7 million individuals due to compromised employee credentials. Latvia’s state-owned forestry company also fell victim to a ransomware attack exploiting an unpatched system for two years. In the realm of vulnerabilities, multiple Tenda router models were found vulnerable via an undocumented backdoor (CVE-2026-11405), while Linux maintainers patched a severe flaw in the KVM hypervisor (CVE-2026-53359). Additionally, AI threats emerged with JadePuffer, an LLM-driven ransomware operation exploiting CVE-2025-3248. These developments underscore the growing complexity and scale of modern cyber threats.
AdvisoryAssuranceAmerica - SecurityWeekRabbitMQ Vulnerability Threatens Enterprise Systems
A critical vulnerability in RabbitMQ, tracked as CVE-2026-5721 (CVSS 8.7), allows attackers to retrieve the broker's confidential OAuth secret without authentication through an outdated management endpoint. This flaw could enable adversaries to impersonate the broker and gain administrative access to systems using identity providers like Auth0, Azure AD, Keycloak, or UAA. The issue affects RabbitMQ versions starting from 3.13.0 and was fixed in 4.3.0, 4.2.6, 4.1.11, 4.0.20, and 3.13.15. Enterprises are urged to update immediately and secure their management interfaces to prevent potential breaches.
RabbitMQ - Help Net SecuritySecurity threat prompts Progress to disable ShareFile accounts, tell customers to shut down servers
Progress Software has issued an urgent warning about a 'credible external security threat' affecting its ShareFile Storage Zone Controllers (SZC), prompting the company to disable access to affected accounts and urge customers to manually shut down their on-premises SZC servers. The move follows reports that attackers might be exploiting two vulnerabilities—CVE-2026-2699 and CVE-2026-2701—to gain remote code execution on unpatched systems. While no unauthorized access has been confirmed, Progress is collaborating with cybersecurity experts to investigate the incident and restore services.
AdvisoryShareFile - BleepingComputerUS and allies warn of Russian critical infrastructure attacks
Cybersecurity agencies from the US and eight other nations have jointly warned that Russian state-backed hackers are targeting misconfigured and vulnerable routers to breach critical infrastructure networks. The advisory, authored by the NSA, FBI, CISA, and partners from Australia, the UK, Canada, and others, identifies several hacking groups—Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, and Static Tundra—as responsible for scanning for weak SNMP credentials and using spoofed IPs to steal router configurations. These attacks pose a serious threat to sectors like energy, communications, healthcare, and government services. Agencies recommend upgrading to SNMPv3, disabling unused features like Cisco Smart Install, enforcing strong passwords, and blocking unnecessary traffic at firewalls.
AdvisoryNSA - SecurityWeekOrganizations Warned of Exploited Joomla Extension Vulnerabilities
Security researchers have confirmed that cybercriminals are actively exploiting two severe vulnerabilities in widely used Joomla extensions, enabling unauthenticated attackers to execute arbitrary code remotely. The affected components are Balbooa Forms and iCagenda, both of which were found to contain critical file upload flaws. These issues—CVE-2026-56291 and CVE-2026-48939—have already been weaponized in attacks before patches were available, making them zero-days. Both vendors have now released updates to resolve the issues, but administrators must act quickly to apply them. CISA has also added these flaws to its Known Exploited Vulnerabilities catalog, emphasizing their urgent risk.
Reported exploitedBalbooa Forms - SecurityWeekProgress Prompts ShareFile Storage Zone Controller Shutdown Amid Security Concerns
Progress Software has advised ShareFile customers to immediately shut down their Storage Zone Controller servers following reports of a credible external security threat. The company temporarily restricted access to accounts using these controllers and is conducting an investigation. While no unauthorized access has been confirmed, speculation points to potential exploitation of two high-severity vulnerabilities—CVE-2026-2699 and CVE-2026-2701—which could allow unauthenticated remote code execution.
IncidentShareFile Storage Zone Controller - The Hacker NewsiCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
CISA has added two high-severity vulnerabilities affecting the iCagenda and Balbooa Forms extensions for Joomla to its catalog of known exploited vulnerabilities, after reports confirmed they were being actively exploited as zero-days. CVE-2026-48939 in iCagenda enables arbitrary file uploads leading to remote code execution, while CVE-2026-56291 in Balbooa Forms allows unauthenticated attackers to upload malicious PHP files. Both flaws have been addressed in updated versions—4.0.8 and 3.9.15 for iCagenda, and 2.4.1 for Balbooa Forms. Administrators are urged to update immediately and scan for suspicious files on their systems.
Reported exploitedBalbooa Forms
Sunday, Jul 121 story
- Help Net SecurityWeek in review: Accenture data breach, great open-source cybersecurity tools
Accenture has confirmed a potential data breach after a hacker claimed to have stolen over 35GB of source code. Meanwhile, attackers are exploiting a critical vulnerability in Adobe ColdFusion (CVE-2026-48282) and another flaw in Langflow (CVE-2026-55255), both recently added to CISA's exploited vulnerabilities list. These incidents highlight the urgency for organizations to apply patches promptly and strengthen their defenses.
Roundup
Saturday, Jul 113 stories
- BleepingComputerAustralia warns of global campaign targeting vulnerable CMS platforms
The Australian Cyber Security Centre (ACSC) has issued a warning about a global exploitation campaign targeting vulnerable content management systems (CMS) and related plugins. Attackers are deploying webshells on compromised websites, enabling them to steal data, install malware, and gain deeper access to networks. The ACSC reports that numerous small- to medium-sized businesses in Australia have already been impacted. Affected products include WordPress plugins like Simple File List (CVE-2025-34085), Ninja Forms (CVE-2026-0740), and Breeze Cache (CVE-2026-3844), as well as other CMS platforms such as Craft CMS (CVE-2025-32432) and MetInfo CMS (CVE-2026-29014).
Reported exploitedSimple File List - The Hacker NewsCritical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
Zimbra has issued a security update to resolve a critical vulnerability in the Classic Web Client that could enable arbitrary code execution through specially crafted emails. The flaw, classified as a stored cross-site scripting (XSS) issue, allows attackers to inject and execute malicious scripts within a user’s session upon opening an affected email. Though no exploitation has been reported so far, past XSS vulnerabilities in Zimbra have drawn significant interest from threat actors. Users are strongly advised to upgrade to Zimbra Collaboration Suite version 10.1.19 to mitigate this risk.
PatchClassic Web Client - Rapid7 BlogWeekly Metasploit Update: Exploits for FlowiseAI CSV Agent and MacOS Package Kit
Rapid7 has added new exploit modules to the Metasploit Framework targeting two recently discovered vulnerabilities in FlowiseAI and macOS PackageKit. The FlowiseAI CSV Agent flaw (CVE-2026-41264) allows unauthenticated remote code execution via a malicious CSV file, while the macOS PackageKit vulnerability (CVE-2024-27822) enables local privilege escalation through ZSH environment manipulation. These additions expand the attack surface of AI tools and operating systems, highlighting the importance of timely patching.
ResearchFlowiseAI
Friday, Jul 1010 stories
- The Hacker NewsURGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat
Progress Software has instructed ShareFile users to stop using the Windows servers hosting their Storage Zone Controllers following reports of a 'credible external security threat.' The company confirmed it is collaborating with security experts and has temporarily restricted access to impacted accounts as part of its precautionary measures. While no evidence of unauthorized account or data access has been found, details about the nature of the threat remain undisclosed. This directive affects only the Storage Zone Controller component, not standard cloud-based ShareFile accounts. Users are advised to keep the controllers offline until further guidance is issued.
IncidentShareFile Storage Zone Controller - The Hacker NewsSix New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot
Security researchers from Binarly have uncovered six critical vulnerabilities in U-Boot, a widely used bootloader for devices ranging from home routers to server management chips. Two of the flaws could allow an attacker to execute arbitrary code before the device verifies the authenticity of the software, potentially compromising the entire system. The remaining four issues can cause crashes that disrupt device operation. These bugs stem from improper validation of untrusted images during the boot process and affect versions dating back to U-Boot v2013.07. While no CVE identifiers have been assigned yet, Binarly has published proof-of-concept exploits for each flaw. Vendors are urged to apply upstream fixes immediately, as official patches are not included in the latest stable release.
PoC publicBinarly - BleepingComputerHackers exploit critical auth bypass in Gitea Docker image
Attackers are actively exploiting a critical authentication bypass flaw in the official Docker image for Gitea, a self-hosted Git service. The vulnerability, tracked as CVE-2026-20896, allows unauthenticated users to impersonate any account—including admin—by manipulating the X-WEBAUTH-USER header. This affects deployments using the default configuration that trusts this header from any IP address. Security researchers confirmed real-world exploitation began just days after the advisory was issued. Gitea has released patched versions 1.26.3 and 1.26.4, urging all users to update immediately.
Reported exploitedGitea Docker image - The Hacker NewsUnpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers
A critical vulnerability dubbed XRING in Alibaba's XQUIC library enables remote clients to crash HTTP/3 servers using standard traffic. Discovered by FoxIO researcher Sébastien Féry, the flaw affects all versions up to v1.9.4 and impacts products like Tengine. The issue stems from a miscalculation in handling QPACK header compression, leading to memory corruption and server termination. Despite being disclosed on July 8, no patch or CVE has been issued as of July 10. Operators are advised to disable QPACK or HTTP/3 until a fix is available.
ResearchXQUIC - BleepingComputerZimbra urges customers to patch critical web client XSS flaw
Zimbra has issued an urgent update for a critical cross-site scripting (XSS) vulnerability impacting the Classic Web Client of its widely used Zimbra Collaboration Suite. The flaw, which allows attackers to inject malicious scripts via specially crafted emails, remains unassigned a CVE ID but is now patched in version 10.1.19. While there is no evidence of active exploitation at this time, the vulnerability was reported by Google’s Threat Analysis Group, known for uncovering sophisticated cyber threats. Zimbra strongly advises all users of the Classic Web Client to upgrade immediately to prevent potential theft of session data and mailbox information.
PatchZimbra Collaboration Suite - The Hacker NewsExposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
A cybercriminal group accidentally left a server exposed online for three weeks, revealing internal operations including tools, logs, and a list of over 1.4 million targeted websites. Researchers identified the campaign as WP-SHELLSTORM, where attackers exploit outdated plugins to plant webshells on vulnerable WordPress and Joomla sites. The most impactful flaws were in the Breeze caching plugin (CVE-2026-3844) and the Joomla JCE editor (CVE-2026-48907). These vulnerabilities allowed attackers to gain unauthorized access and control over compromised systems. Website owners using these platforms should prioritize patching affected components immediately.
Reported exploitedWordPress - The Hacker NewsStudy of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking
A new study analyzed 281 popular free Android VPN apps from the Google Play Store and uncovered significant privacy and security issues. Many failed to protect user data properly, with over 2.4 billion total installations across the problematic apps. Researchers identified leaks of encrypted traffic, unsecured data transmission, and tracking behaviors. Five apps were particularly vulnerable to 'tunnel hijacking,' allowing attackers to redirect connections to malicious servers. The findings highlight poor implementation practices and raise concerns about the reliability of free VPN services. The research team developed MVPNalyzer, a tool designed to systematically audit Android-based virtual private networks.
ResearchAndroidVPN Apps - The Hacker NewsAttackers Exploit 'Ill Bloom' Vulnerability to Drain $3.1 Million From Cryptocurrency Wallets
A critical vulnerability dubbed Ill Bloom has been actively exploited by attackers to steal over $3.1 million from cryptocurrency wallets. The flaw lies in how certain wallet applications generated recovery phrases—key components for accessing funds—with insufficient randomness, allowing malicious actors to predict and access them. Security firm Coinspect reported a coordinated theft on May 27, draining 431 wallets, with additional losses totaling more than $5 million since then. Older or less-known mobile wallets are particularly at risk. Coinspect advises users to use the free tool at illbloom.org to check if their wallet is affected and to move funds immediately if compromised. This issue mirrors past flaws such as CVE-2023-39910 and CVE-2023-31290, where predictable random number generators led to similar attacks.
Reported exploitedCryptocurrency Wallets - Help Net SecurityJuly 2026 Patch Tuesday forecast: Is CVE tracking still practical?
July 2026's Patch Tuesday is shaping up to be another busy round of security updates across major vendors like Microsoft, Adobe, Apple, Google, Mozilla, and Oracle. With over 200 CVEs addressed in June alone—many affecting Windows 10 and 11, along with critical applications like Office and SharePoint—the pace shows no sign of slowing down. A notable fix includes CVE-2026-50656, a privilege escalation flaw in Microsoft Defender, which was publicly disclosed with proof-of-concept code. Adobe has also doubled its monthly patch schedule due to the rising volume of vulnerabilities, while Google rolled out Chrome 150 with 433 security fixes. As AI accelerates vulnerability discovery, experts warn that traditional CVE tracking methods may become impractical, pushing organizations toward faster, more reactive patching strategies.
AdvisoryWindows - Palo Alto Unit 42No Manners Here: The Ruthless Rise of The Gentlemen Ransomware
Palo Alto Networks' Unit 42 reports that The Gentlemen, a Ransomware-as-a-Service (RaaS) group, has surpassed 580 claimed victims globally since its emergence in late 2025. Operating under the alias Storm-2697, the group uses custom tools and exploits several known vulnerabilities, including CVE-2024-55591 and CVE-2025-32433, to infiltrate networks. With a generous 90% affiliate payout model and partnerships with BreachForums, The Gentlemen has rapidly grown into one of the most active ransomware groups in 2026. Security experts recommend urgent patching and monitoring for signs of compromise.
Reported exploitedThe Gentlemen
Thursday, Jul 94 stories
- Ars Technica (Security)Patch for Windows Defender 0-day could allow attackers to fill hard disk
Microsoft has issued a patch for a critical zero-day vulnerability in its Windows Defender security engine, identified as CVE-2026-50656. The flaw was publicly disclosed in June by an anonymous researcher using the alias NightmareEclipse, who also shared proof-of-concept code for exploitation. This vulnerability enables remote attackers to gain administrative access on Windows 10 and 11 systems, even if real-time protection is turned off. According to the researcher, the latest update introduces changes that could allow malicious actors to fill up hard drives by generating large volumes of data. Microsoft claims the fix will be automatically applied through an update to the Malware Protection Engine.
PoC publicWindows Defender - Dark ReadingMicrosoft Reins in RoguePlanet Zero-Day Threat
Microsoft has released an urgent out-of-band patch for a high-severity zero-day vulnerability in Windows Defender, identified as CVE-2026-50656 and named RoguePlanet. The flaw allows attackers to escalate privileges from a regular user to SYSTEM-level access, granting full control over the device. The vulnerability was disclosed by an anonymous researcher known as Nightmare-Eclipse, who has been involved in a public dispute with Microsoft over several months. Despite the availability of a proof-of-concept exploit, there is currently no evidence that the flaw has been exploited in the wild. However, experts warn that the vulnerability poses significant risks, especially if used in conjunction with other initial access methods.
- Cisco TalosWolfSSL, GeoVision, VTK vulnerabilities
Cisco Talos has identified several critical security flaws across three major vendors: WolfSSL, GeoVision, and VTK-DICOM. These include improper input validation, buffer overflows, command injection, and other high-risk issues affecting a wide range of products. All reported vulnerabilities have been addressed by the respective vendors following responsible disclosure practices. Users are advised to update their software to mitigate potential risks.
AdvisoryWolfSSL - The Hacker NewsThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories
A critical security flaw in Esri ArcGIS Server 12.0 and earlier versions has been patched following reports of potential unauthenticated file access. The vulnerability, tracked as CVE-2026-9181 with a CVSS score of 9.8/7.5, allowed attackers to access sensitive files by sending specially crafted path parameters. This flaw resided in the REST Uploads resource due to insufficient validation of inputs, enabling directory traversal attacks. Horizon3.ai highlighted the risk, noting that no authentication was required to exploit it. Users are strongly advised to update to the latest version to mitigate exposure.
PatchArcGIS Server