The Hacker News
Cisco Talos says a China-aligned threat group tracked as UAT-7810 is continuing to build out an Operational Relay Box (ORB) network by compromising internet-facing networking gear and deploying update...
8 Jul 20262 min read
Read article →The Hacker News
Security researchers at Nebula Security have disclosed a long-standing Linux kernel vulnerability, tracked as CVE-2026-43499 and nicknamed GhostLock, that can let a local user gain full root privilege...
8 Jul 20262 min read
Read article →The Hacker News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after determining that they are being used in activ...
8 Jul 20262 min read
Read article →SecurityWeek
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned organizations about active exploitation of critical flaws in Adobe ColdFusion, Langflow, and two Joomla extensions, urging r...
8 Jul 20262 min read
Read article →SecurityWeek
Security researchers at Noma Labs have identified a critical prompt injection weakness in GitHub Agentic Workflows that could let an unauthenticated attacker expose data from private repositories. The...
8 Jul 20262 min read
Read article →Dark Reading
Estonia, long known for its advanced digital government services, may be considering a new step in online identity: giving AI agents a way to interact with public systems on behalf of people or organi...
8 Jul 20262 min read
Read article →BleepingComputer
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has directed federal civilian agencies to address an actively exploited authentication bypass flaw in Langflow, a visual development pl...
8 Jul 20262 min read
Read article →BleepingComputer
Ubiquiti has issued security updates for seven critical vulnerabilities affecting UniFi OS and related applications. The most serious issue, tracked as CVE-2026-50746, carries a maximum severity ratin...
8 Jul 20262 min read
Read article →BleepingComputer
The U.S. Cybersecurity and Infrastructure Security Agency has directed federal civilian agencies to patch a maximum-severity Adobe ColdFusion vulnerability by Friday after the flaw was added to its Kn...
8 Jul 20262 min read
Read article →The Hacker News
Security researchers say a phishing campaign observed from late June into early July 2026 abused Microsoft’s device-code authentication flow to target Microsoft 365 users. According to ZeroBEC, the op...
7 Jul 20262 min read
Read article →The Hacker News
Google has patched a serious security issue in Dialogflow CX that could have allowed an attacker with limited edit privileges to take over other chatbots in the same Google Cloud project, according to...
7 Jul 20262 min read
Read article →The Hacker News
A new Android fraud operation tracked as RedWing is being marketed on Telegram as a turnkey malware service, lowering the technical barrier for attackers looking to steal banking credentials and one-t...
7 Jul 20262 min read
Read article →