Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

20/07/2026 0 Comments 0 tags

F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

19/07/2026 0 Comments 0 tags

Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According to the Computer Emergency Response

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

19/07/2026 0 Comments 0 tags

A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

17/07/2026 0 Comments 0 tags

An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

17/07/2026 0 Comments 0 tags

Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

17/07/2026 0 Comments 0 tags

Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

17/07/2026 0 Comments 0 tags

A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator’s own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

17/07/2026 0 Comments 0 tags

Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as

Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images

17/07/2026 0 Comments 0 tags

North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake

E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants

17/07/2026 0 Comments 0 tags

The European Commission on Thursday ordered Google to give rival AI assistants the same reach into Android that Gemini already has: the camera, the microphone, whatever is on screen, a