Injective SDK npm Supply Chain Attack: Crypto Wallet Keys Stolen via Compromised Package
July 9, 2026 Threat actors compromised a legitimate GitHub contributor account for the Injective Labs SDK project and published a malicious npm package that steals cryptocurrency wallet private keys and mnemonic seed phrases. The attack affected version…
Seven FatFs Vulnerabilities Expose Millions of Embedded Devices to Memory Corruption and Code Execution
July 4, 2026 Security researchers at runZero have disclosed seven vulnerabilities in FatFs, a small filesystem library used by millions of embedded devices worldwide. Consequently, any device that reads FAT or exFAT storage — including security cameras,…
Bad Epoll CVE-2026-46242: Linux Kernel Privilege Escalation Hits Android
July 3, 2026 A newly disclosed Linux kernel vulnerability dubbed “Bad Epoll” (CVE-2026-46242) allows an unprivileged user to escalate to root on Linux desktops, servers, and Android devices. The flaw is a use-after-free in the kernel’s…
Adobe ColdFusion Critical Patch: 6 CVSS 10.0 RCE Flaws Disclosed
July 2, 2026 Adobe has released urgent security patches for ColdFusion, resolving multiple critical vulnerabilities including six rated at the maximum CVSS score of 10.0. These flaws enable unauthenticated remote code execution on widely deployed…
SharePoint RCE CVE-2026-45659: CISA KEV Alert After Active Exploitation
July 2, 2026 CISA has confirmed active exploitation of a high-severity Microsoft SharePoint remote code execution vulnerability tracked as CVE-2026-45659 (CVSS: 8.8). Organizations running supported SharePoint Server versions should patch immediately to…
Cursor DuneSlide CVEs Enable Zero-Click Prompt Injection RCE on Developer Machines
July 01, 2026 Two critical vulnerabilities in the Cursor AI code editor enable zero-click prompt injection attacks that break out of the IDE’s security sandbox and run arbitrary commands on a developer’s machine. Discovered by Cato AI Labs…
Langflow CVE Critical RCE Deploys Monero Miner on AI Endpoints
June 30, 2026 On June 30, 2026, Trend Micro published a technical report confirming that threat actors are actively exploiting CVE-2026-33017, a critical unauthenticated remote code execution vulnerability in Langflow. The flaw carries a CVSS score of…
RustDuck Botnet Rebuilds Core in Rust for DDoS Attacks on Routers and Servers
June 30, 2026 A new two-stage malware family called RustDuck is hijacking home routers, IP cameras, Android boxes, and poorly secured servers to build a distributed denial-of-service (DDoS) botnet. Researchers at QiAnXin’s XLab have tracked it…
BlueHammer CVE: Ransomware Gangs Actively Exploit Microsoft Defender Privilege Escalation Flaw
June 30, 2026 CISA confirmed on Monday that ransomware gangs are now actively exploiting a high-severity Microsoft Defender privilege escalation vulnerability known as BlueHammer. The flaw, tracked as CVE-2026-33825, was originally leaked as a zero-day…
FBI Warns Russian Hackers Steal Signal Backup Recovery Keys
June 27, 2026 The FBI and CISA issued an updated public service advisory on June 26, 2026, warning that Russian Intelligence Services (RIS) have evolved their Signal phishing campaign to steal Backup Recovery Keys. Consequently, attackers who obtain…