CISA KEV Alert for Active Zero-Day Exploitation of Cisco FMC
July 30, 2026 CISA has added a newly disclosed Cisco Secure Firewall Management Center zero-day to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. The vulnerability, tracked as CVE-2026-20316, allows…
Critical Rails Active Storage Flaw Exposes Server Secrets
July 29, 2026 A critical vulnerability in Ruby on Rails Active Storage could let unauthenticated attackers read arbitrary files from application servers using crafted image uploads. Tracked as CVE-2026-66066 with a CVSS score of 9.5, the flaw exposes…
Server BMCs Leak Password Hashes via 20-Year-Old IPMI Flaw
July 28, 2026 More than 24,000 internet-exposed servers are leaking authentication password hashes through a 20-year-old vulnerability in their Baseboard Management Controller interfaces. Researchers at cybersecurity firm Lava discovered that…
Critical Pre-Auth RCE Flaw Enables Remote Code Execution
July 28, 2026 A critical pre-authentication remote code execution vulnerability in vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code on affected servers. The flaw, tracked as CVE-2026-61511, impacts versions 5.7.5…
Dysphoria IoT Botnet Hijacks Devices Worldwide
July 28, 2026 A rapidly evolving IoT botnet named Dysphoria has infected an estimated 200,000 devices worldwide. Consequently, defenders must understand its blockchain-based command-and-control architecture and aggressive DDoS capabilities. The botnet…
Browser Assembled Malware Targets Crypto Traders and Investors
July 27, 2026 A massive malvertising operation dubbed SourTrade is using fake cryptocurrency and trading websites to turn victims’ browsers into local malware assembly lines. Threat actors leverage JavaScript, service workers, and a clean copy of…
Hotel Wi-Fi DNS Hijack Campaign Steals Microsoft 365 Accounts
July 26, 2026 Threat actors are hijacking hotel and conference center Wi-Fi gateways to redirect business travelers to fake Microsoft 365 login pages. The campaign, active since at least June 2026, uses DNS manipulation and device-code authentication to…
Hermes AI Agent Automates Post-Exploitation Inside Thailand Ministry of Finance
July 24, 2026 A threat actor deployed the open-source Hermes AI agent in unattended “YOLO” mode to automate post-exploitation inside Thailand’s Ministry of Finance. The operation was uncovered after the attacker left 585 files and 470…
Critical Fastjson RCE Under Active Exploitation
July 25, 2026 Security researchers have uncovered a critical remote code execution flaw in Alibaba’s Fastjson 1.x library. Tracked as CVE-2026-16723, this vulnerability carries a CVSS score of 9.0 and is already under active exploitation in the…
RefluXFS CVE: Nine-Year-Old Linux Kernel Flaw Grants Root
July 23, 2026 A nine-year-old race condition in the Linux kernel’s XFS filesystem, tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on disk and gain persistent root access. The flaw, dubbed RefluXFS by Qualys,…